You can enforce a signing policy by having an AI agent audit a whole folder of documents in one prompt, locally, and hand back a single table of exceptions. The agent runs in Claude Desktop, Claude Code, Cursor or GitHub Copilot, and the GroupDocs.Signature.Mcp server does the checking. The prompt that starts the sweep:
For every PDF in my documents folder, check whether it is digitally signed and still valid. Give me a table: file, signer, signed date, status.
The step-by-step version with config and troubleshooting is in the documentation: How to audit a folder of signed documents with an AI agent.
Why does a signing policy need an automated sweep?
A policy such as “every contract in the archive carries a valid digital signature” is only a policy if something tests it. Manual checks open files one at a time, so they happen rarely and cover a sample. The questions compliance asks are about the whole archive: which contracts are not signed, whose certificate expired, which files were changed after signing.
An AI agent alone cannot answer them, because a model reading a PDF cannot see its signature structure. The agent supplies the loop and the summary. The engine supplies the facts, per file.
The workflow, step by step
- Point the server at the folder. Set
GROUPDOCS_MCP_STORAGE_PATHto the documents folder. Files are resolved by name, so the agent passescontract-042.pdf, not a path from your machine. - Check the license mode. Ask the agent to call
get_license_status. In evaluation mode only the first 2 pages are processed, so a clean report can be wrong (see the limits below). - Run the sweep. Use the prompt above. For each file the agent calls
search_digital_signaturesand assembles the table. A file with no digital signature found is reported as unsigned. - Read the exceptions. Sort the table by status and handle the three groups described below.
- Re-run on a schedule. The same prompt works next month on the same folder, so the audit becomes a routine instead of a project.
What the agent decides and what the engine does
| Step | The agent decides | The engine does |
|---|---|---|
| Which files to check | Lists the PDFs in the folder from your prompt | Resolves each file by name from storage |
| Is it signed, valid, and by whom | Chooses the files | Returns signer, issuer, serial number, validity period, timestamp and isValid (search_digital_signatures) |
| The report | Builds the table and groups exceptions | Nothing; the engine does not summarise |
Example session (abridged)
You: For every PDF in my documents folder, check whether it is digitally
signed and still valid. Give me a table: file, signer, signed date, status.
Agent: [get_license_status] mode: licensed
[search_digital_signatures] x N
| file | signer | signed | status |
| contract-041.pdf | Dana Whitfield | 2026-09-14 | valid |
| contract-042.pdf | - | - | unsigned |
| contract-043.pdf | Omar Haddad | 2026-08-02 | invalid |
Exceptions: 1 unsigned, 1 invalid. Invalid usually means the file
changed after signing.
Illustrative output: file names and signer names are invented. The tool returns the fields described above.
The three exceptions that matter
- Unsigned files. This is the gap the audit exists to find.
- Invalid signatures. Almost always something changed after signing: a stamp added later, a re-save, an appended page. It is worth knowing which.
- Expired certificates. The signature was valid when it was made. Whether it still counts is your policy. The validity period is in the returned data, so ask the agent to list every certificate whose validity period ended before today; that comparison is what finds them.
How do you keep the sweep cheap and the report trustworthy?
- Run
search_digital_signatureson every file. Addverifyonly as an optional quick screen, and treat the detail record as the source of truth. - Skip
search_image_signaturesin bulk. It returns base64 images for every hit and inflates the run for nothing. - Leave
returnImageoff on code searches. - Under metered licensing each call is billed usage, so a targeted sweep costs less as well as running faster.
- Keep the per-file certificate details (signer, issuer, serial, timestamp) as your record. The agent’s prose summary is a report, not an attestation, and it is not a notarial act.
Then act on the exceptions
The same session can fix what the sweep finds, for example by applying a reference mark to the unsigned files:
Sign the three unsigned ones with our standard QR reference and list what you did.
Be precise about what that does. A QR code is a visual mark, not a certificate-based signature, so it does not replace a required digital signature. For files that need one, apply it last with sign and type: "digital".
Limits to state in your own process
Evaluation mode processes only the first 2 pages of each document and stamps a trial badge on every page. A signature on page 4 does not appear, so an unlicensed bulk audit can report “clean” for a file that is not. Check get_license_status first, every time. The server also reads signature data from the file; it does not know your policy, so the definition of an acceptable certificate stays with you.
FAQ
Which of my contracts are not signed?
Ask the agent to audit the folder and list files with no digital signature. Each file gets a search_digital_signatures call; a file where none is found is listed as unsigned. The result is one table.
Can AI do a bulk check of PDF signatures? Yes, in one prompt over a folder, locally. Without a license only the first 2 pages of each file are examined.
Can the report serve as compliance evidence? Keep the per-file certificate details returned by the engine as the evidence. The agent’s summary is a convenience, not an attestation.
Go deeper
- Documentation, canonical how-to: How to audit a folder of signed documents with an AI agent
- Documentation hub: GroupDocs.Signature MCP Server
- Start here: 3 Ways to Sign Documents with AI Agents and MCP: Text, QR Code, Certificate
- Related: Why an AI Agent Should Not Just Say a Document Is Verified
- Related: From Barcode to Record: Document Intake Automation with AI Agents
- On-premise and security model: 3 architectures for AI document processing, and the one that keeps files inside your network
- Questions: GroupDocs Signature forum
- Source: GroupDocs.Signature.Mcp on GitHub