How to protect e-signature credentials when an agent uses official portals
In 60 seconds: An electronic signature, its private key, and tax credentials let a system act under the holder’s identity. Keep them in a vault, separate from documents, chats, and shared folders. Give the process temporary minimum access, use MFA where the portal supports it, log every use, and require human review. Define “read only” action by action: some portals create proof of notification when a pending document is opened. If the portal fails or changes, the agent preserves the last confirmed state, records the incident, and requests review. It never fills the gap with a probable answer.
A litigation firm wants to check case activity every morning. A company needs to download receipts and monitor monthly tax obligations. Both may look like browser automation projects until someone asks where the certificate, private key, and password will live.
If they are in a shared folder, the integration starts with a custody problem. The agent may automate one query, while the same credentials may authorize filings, signatures, or account access that the workflow never needed.
These field notes describe operational controls, not legal, tax, or cybersecurity advice for a specific matter. Each organization should confirm the effect of every portal action with the responsible professional and the rules of its jurisdiction.
The credential can act as the holder
Mexico provides a useful concrete example. For acts within its scope, the Advanced Electronic Signature Law says that electronic documents carrying an advanced electronic signature produce the same effects as documents bearing a handwritten signature and receive the evidentiary value granted by applicable law. The law excludes tax, customs, and financial matters, which follow their own rules. The Mexican Tax Administration Service (SAT) describes the e.firma as data that identifies the signer, is created under the signer’s exclusive control, and is linked to both the signer and the signed data.
The terms in the SAT e.firma application are even more direct: they attribute movements and documents signed with the private key to the holder and require the holder to protect the confidentiality of the .key file and its password. A copy available through a shared drive, email, or chat therefore expands the people and processes that could act under that identity.
Inventory each component separately:
- the public certificate, such as a
.cerfile; - the private key, such as a
.keyfile; - the private key password;
- the tax or account password used to enter the portal;
- authentication factors, active sessions, and recovery methods.
A portal may require several components without requiring the organization to store them together. The architecture should prevent one person, process, or leak from obtaining the complete set without additional controls.
Make the vault part of the workflow
Store private keys and passwords in a managed vault or secrets-management system. It should encrypt the material, authorize access by identity, record access, support revocation, and release a secret only to the process that needs it. Those requirements matter more than a vendor name.
NIST key-management guidance requires confidentiality protection for private keys outside a cryptographic module and calls for access controls, logging, and review. A folder with broad collaboration permissions can hold working documents. By itself, it does not provide the usage controls needed for a signing credential.
The agent does not need to see the secret either. Where the technology allows it, a controlled intermediary can perform the authorized authentication or signing operation and return only the result. The model receives a narrow capability for one task instead of a file and password in its prompt, browser state, or logs.
Apply MFA and least privilege per portal
Enable MFA wherever it is available, especially on accounts that hold sensitive information or administrative authority. CISA recommends MFA for remote and privileged access and advises using phishing-resistant methods when the service offers them.
MFA cannot repair excessive permissions. The agent’s account should reach only the entities, matters, and modules included in the assignment. If a portal cannot separate reading, signing, and filing, reduce scope elsewhere through a distinct account, a supervised session, a controlled workstation, or a manual step.
Document four boundaries before connecting the agent:
- which identity it uses;
- which portals, taxpayers, or matters it may query;
- which actions it may perform;
- when access expires or is revoked.
A shared credential erases attribution. When the portal requires one, the internal record must still identify the person who approved the run and the process that used it.
Temporary copies need an owner and an end
Some legacy portals only accept files loaded from the computer running the browser. A temporary copy may then be necessary. Treat it as a documented exception:
- approve the task and its access window;
- copy only the required components into an isolated, disposable environment;
- keep them out of prompts, screenshots, clipboards, shell history, and logs;
- run the authorized query;
- record the outcome and permitted evidence;
- remove the copy and destroy the environment when the task ends;
- verify that synchronization, download folders, caches, and unplanned backups kept no copy.
NIST treats distribution, storage, use, and destruction as auditable key-management events. “Temporary” describes a lifecycle, not a folder named tmp.
Do not use an environment for signing material when you cannot verify deletion or it retains browser profiles. Keep that step on a managed workstation under human control.
Define read-only access as specific actions
Entering a portal and reading a screen is not always neutral. Mexico’s Federal Judiciary Council explains that opening a resolution in its Online Services Portal automatically creates a record with the date and time of notification. In the SAT Tax Mailbox, the notification flow includes selecting the pending administrative act, entering the e.firma, and generating a receipt.
Translate the word “query” into an action matrix for each portal:
| Action | Agent | Responsible person |
|---|---|---|
| Check whether the portal is available | Allowed | Reviews exceptions |
| Query public data or authorized matters | Allowed and logged | Reviews samples |
| See that a pending item exists without opening it | Allowed only if the portal separates the actions | Chooses the next step |
| Open a pending resolution or administrative act | Blocked | Confirms the effect and authorizes it |
| Generate a receipt, accept, sign, or file | Blocked | Performs or approves the specific workflow |
This separation does not stop deadlines that law or the portal may trigger automatically. It prevents the automation from adding an unauthorized act and requires the team to maintain its own control over alerts and due dates.
When the portal fails, the status is unconfirmed
A timeout, new CAPTCHA, changed selector, or blank page does not mean “no activity.” The agent should return an explicit state such as query failed, ambiguous result, or human review required.
The minimum record includes the portal, technical identity, matter or taxpayer queried, time and time zone, attempted action, observed response, and last confirmed status. It never includes passwords, private keys, or tokens. Preserve permitted operational evidence and escalate according to the urgency of the matter.
The Federal Judiciary’s portal has an official technical-incident channel, and its portal guide explains how to file a report. That illustrates a useful rule: use the portal’s official channel and let the authority confirm the outage. An internal screenshot may support troubleshooting, but it does not replace any applicable formal requirement.
Stop the automation when the interface changes and revalidate the allowed actions. A selector that downloaded a document yesterday could point to “accept” or “submit” after a redesign.
Human review and an access ledger
Every run should answer who requested it, who approved it, which identity and portal it used, when it ran, what action it performed, which file it downloaded, and what happened. The ledger should also include failed access and the removal of temporary material.
Keep the ledger outside the environment that uses the credential and protect it against alteration. CISA recommends logging user activity, logins, and administrative actions, centralizing logs, and alerting on high-risk events.
Human review requires more than approving a summary. The reviewer needs to see the portal, identity, exact action, and expected effect. For a download, they verify the matter, source, and file. For a notice or filing, the decision and execution remain outside autonomous scope unless a separately approved procedure governs them.
The guide to a litigation second brain covers the next step: linking downloaded documents, observed states, owners, and next actions without delegating legal judgment.
Checklist before connecting the agent
- We inventoried certificates, private keys, passwords, MFA, sessions, and recovery paths.
- Private keys and credentials live in a vault, outside shared drives, chats, and documents.
- The agent receives a temporary, narrow capability, with no secrets in its prompt.
- We defined allowed and blocked actions for each portal.
- We confirmed which actions create a receipt, notification, signature, or filing.
- We enabled MFA and limited identities, matters, modules, and hours where possible.
- We document the creation and removal of every temporary copy.
- We log access, downloads, failures, approvals, and outcomes.
- A human exception queue handles interface changes, ambiguity, and outages.
- We tested revocation, rotation, and exposure response before the pilot.
Official sources were verified on October 11, 2026. Rules and portal features vary by jurisdiction and may change; verify the applicable version on the day of implementation.
Kiia can help design the permission map, custody controls, and query pilot before a real credential is connected. The first milestone is easy to test: the agent receives only the capability it needs, and every access leaves reviewable evidence.
Frequently asked questions
Can we keep e-signature files in Drive if the folder has restricted access?
A shared drive is not the right place for a private key and its password. Use a vault or secrets-management system with encryption, identity-based permissions, auditing, and revocation. A public certificate may be handled differently, but that does not justify storing every component together.
Can a read-only agent open official notices?
Not by default. In some portals, opening a document creates a notification record or is part of accepting service. Define which screens the agent may inspect in each portal and block any action that opens, accepts, signs, or acknowledges a pending notice.
What should the agent do when the portal fails or changes?
It should preserve the last confirmed state, record the time, portal, attempted action, and error, then send the exception to a person. It must not turn an empty page, changed selector, or timeout into 'no updates.'
From insight to action
Want to turn this into an agent that works for your team?
Tell us which process you want to improve. In a free call, we will identify the first workflow worth building.