You can enforce a signing policy by having an AI agent audit a whole folder of documents in one prompt, locally, and hand back a single table of exceptions. The agent runs in Claude Desktop, Claude Code, Cursor or GitHub Copilot, and the GroupDocs.Signature.Mcp server does the checking. The prompt that starts the sweep:

For every PDF in my documents folder, check whether it is digitally signed and still valid. Give me a table: file, signer, signed date, status.

The step-by-step version with config and troubleshooting is in the documentation: How to audit a folder of signed documents with an AI agent.

Why does a signing policy need an automated sweep?

A policy such as “every contract in the archive carries a valid digital signature” is only a policy if something tests it. Manual checks open files one at a time, so they happen rarely and cover a sample. The questions compliance asks are about the whole archive: which contracts are not signed, whose certificate expired, which files were changed after signing.

An AI agent alone cannot answer them, because a model reading a PDF cannot see its signature structure. The agent supplies the loop and the summary. The engine supplies the facts, per file.

The workflow, step by step

  1. Point the server at the folder. Set GROUPDOCS_MCP_STORAGE_PATH to the documents folder. Files are resolved by name, so the agent passes contract-042.pdf, not a path from your machine.
  2. Check the license mode. Ask the agent to call get_license_status. In evaluation mode only the first 2 pages are processed, so a clean report can be wrong (see the limits below).
  3. Run the sweep. Use the prompt above. For each file the agent calls search_digital_signatures and assembles the table. A file with no digital signature found is reported as unsigned.
  4. Read the exceptions. Sort the table by status and handle the three groups described below.
  5. Re-run on a schedule. The same prompt works next month on the same folder, so the audit becomes a routine instead of a project.

What the agent decides and what the engine does

Step The agent decides The engine does
Which files to check Lists the PDFs in the folder from your prompt Resolves each file by name from storage
Is it signed, valid, and by whom Chooses the files Returns signer, issuer, serial number, validity period, timestamp and isValid (search_digital_signatures)
The report Builds the table and groups exceptions Nothing; the engine does not summarise

Example session (abridged)

You:    For every PDF in my documents folder, check whether it is digitally
        signed and still valid. Give me a table: file, signer, signed date, status.

Agent:  [get_license_status]  mode: licensed
        [search_digital_signatures] x N
        | file             | signer      | signed     | status   |
        | contract-041.pdf | Dana Whitfield | 2026-09-14 | valid    |
        | contract-042.pdf | -              | -          | unsigned |
        | contract-043.pdf | Omar Haddad    | 2026-08-02 | invalid  |
        Exceptions: 1 unsigned, 1 invalid. Invalid usually means the file
        changed after signing.

Illustrative output: file names and signer names are invented. The tool returns the fields described above.

The three exceptions that matter

  • Unsigned files. This is the gap the audit exists to find.
  • Invalid signatures. Almost always something changed after signing: a stamp added later, a re-save, an appended page. It is worth knowing which.
  • Expired certificates. The signature was valid when it was made. Whether it still counts is your policy. The validity period is in the returned data, so ask the agent to list every certificate whose validity period ended before today; that comparison is what finds them.

How do you keep the sweep cheap and the report trustworthy?

  • Run search_digital_signatures on every file. Add verify only as an optional quick screen, and treat the detail record as the source of truth.
  • Skip search_image_signatures in bulk. It returns base64 images for every hit and inflates the run for nothing.
  • Leave returnImage off on code searches.
  • Under metered licensing each call is billed usage, so a targeted sweep costs less as well as running faster.
  • Keep the per-file certificate details (signer, issuer, serial, timestamp) as your record. The agent’s prose summary is a report, not an attestation, and it is not a notarial act.

Then act on the exceptions

The same session can fix what the sweep finds, for example by applying a reference mark to the unsigned files:

Sign the three unsigned ones with our standard QR reference and list what you did.

Be precise about what that does. A QR code is a visual mark, not a certificate-based signature, so it does not replace a required digital signature. For files that need one, apply it last with sign and type: "digital".

Limits to state in your own process

Evaluation mode processes only the first 2 pages of each document and stamps a trial badge on every page. A signature on page 4 does not appear, so an unlicensed bulk audit can report “clean” for a file that is not. Check get_license_status first, every time. The server also reads signature data from the file; it does not know your policy, so the definition of an acceptable certificate stays with you.

FAQ

Which of my contracts are not signed? Ask the agent to audit the folder and list files with no digital signature. Each file gets a search_digital_signatures call; a file where none is found is listed as unsigned. The result is one table.

Can AI do a bulk check of PDF signatures? Yes, in one prompt over a folder, locally. Without a license only the first 2 pages of each file are examined.

Can the report serve as compliance evidence? Keep the per-file certificate details returned by the engine as the evidence. The agent’s summary is a convenience, not an attestation.

Go deeper