While the document status automatically updates to "Completed" upon submission, why does this change fail to fire my standard Record-Triggered Flow, and how do we resolve it?

Published on October 3, 2026 DRTE


This behavior is caused by Salesforce native guest user security restrictions. When an external recipient completes an e-signature workflow, the submission executes under the Guest User context. Because Salesforce enforces strict security policies that prevent Guest Users from owning records or executing elevated administrative actions, any standard Record-Triggered Flow running in this context lacks the permissions required to update parent CRM records or execute system tasks.
To bypass these security restrictions and execute your automation under an elevated system context, you must decouple the process using Platform Events.
Why Standard Record-Triggered Flows Fail
  1. Guest User Security Model: External signers access the signing portal without logging into Salesforce. All portal actions execute under the site's Guest User Profile.
  2. Context Inheritance: A standard Record-Triggered Flow executing immediately upon document submission inherits the restricted permissions of the Guest User.
  3. Permission Denial: When the flow attempts to update restricted records (such as Opportunities, Contracts, or custom objects), Salesforce blocks the transaction due to insufficient guest user privileges.
The Solution: Context-Switching via Platform Events
To execute your post-signature logic with full administrative permissions, configure a two-step Platform Event architecture:
Step 1: Create a Record-Triggered Flow (Publishes the Event)
  1. Object: E Signature Request
  2. Trigger: Record is updated
  3. Entry Condition: isSigned Equals True (or Status Equals Completed)
  4. Execution Path: Move the logic to Async Processing (Scheduled Path) to ensure custom automation does not hinder native e-signature processing.
  5. Action: Add a Create Records element to publish a packaged Platform Event record (e.g., ESignatureDocumentRequest).
Step 2: Create a Platform Event-Triggered Flow (Executes System Logic)
  1. Triggering Event: ESignatureDocumentRequest (Platform Event)
  2. Running User Context: Platform Event-Triggered Flows automatically run under the Automated Process User (System Context), granting full administrative privileges.
  3. Actions: Perform your post-signature tasks, such as updating parent record fields, generating Certificates of Completion (CoC), or sending notification emails.



Knowledge Article Number: KA-00441

View more articles in the knowledge base