REFRACT Notification

REFRACT Notification

REFRACT Notification is the shared notification layer for the REFRACT Platform. It routes email and SMS notifications for REFRACT Delivery, REFRACT eSign, and REFRACT Workflow through either REFRACT Shared Services ACS or your own Azure Communication Services instance.

REFRACT Notification is the cross-cutting notification infrastructure that powers outbound communications across the entire REFRACT Platform. It is not a standalone product - it is the shared layer underneath REFRACT Delivery recipient invitations, REFRACT eSign signing invitations and OTP codes, and REFRACT Workflow participant and approver notifications.

Scope

The EMAIL_PROVIDER environment variable controls all outbound notification emails sent by the REFRACT Platform - not just one product. Setting it on your Dispatcher and Processor affects REFRACT Delivery, REFRACT eSign, and REFRACT Workflow simultaneously.


Two Modes

Two notification routing modes are supported. The mode is set via the EMAIL_PROVIDER environment variable on both your Dispatcher and Processor Function Apps.

vault-shared (Default)

The Dispatcher queues notification messages to your Azure Service Bus. Your Processor picks them up and relays each message to the REFRACT PDF notification service (HMAC-signed, metadata only). REFRACT PDF's Azure Communication Services instance handles the actual email delivery.

Customer Azure Subscription                          REFRACT PDF Subscription
──────────────────────────────────────   ────────────────────────────────────
Dispatcher
  └─ enqueue (metadata-only message)
       └─ [Customer Service Bus]
             └─ Processor NotificationWorker
                  └─ POST /api/internal/email
                       (HMAC-SHA256 signed, metadata only:
                        recipient email, portal link, notification type)
                                                    └─ REFRACT PDF notification service
                                                          └─ ACS (email / SMS)

The HMAC-signed POST carries only: recipient email, portal link, notification type, and document name. Document content, file bytes, signatures, and form field data are never included.

customer-acs (Zero Transit Mode)

Your Processor sends all notification emails directly through your own Azure Communication Services instance. The REFRACT PDF notification service is never called - no notification metadata transits REFRACT PDF infrastructure under any REFRACT Platform feature.

Customer Azure Subscription
──────────────────────────────────────
Dispatcher
  └─ enqueue (metadata-only message)
       └─ [Customer Service Bus]
             └─ Processor NotificationWorker
                  └─ sendViaCustomerAcs()
                       └─ Your own ACS
                            (ACS_EMAIL_ENDPOINT + ACS_EMAIL_KEY)

customer-acs scope: REFRACT Delivery and REFRACT Workflow fully, REFRACT eSign partially

Setting EMAIL_PROVIDER=customer-acs on both your Dispatcher and Processor routes all notification queue emails through your own ACS - this covers REFRACT Delivery invitations and OTP codes, REFRACT eSign OTP codes and completion notifications, and REFRACT Workflow participant notifications.

REFRACT eSign invitation emails (initial and sequential) are currently also sent directly by the eSign Portal via REFRACT Shared Services ACS, independently of this setting. The notification queue path respects customer-acs, but the portal's direct send is not yet suppressed. If strict zero-transit of signer invitation emails is required, evaluate whether this meets your needs.


Environment Variable Reference

Settingvault-shared (default)customer-acs
EMAIL_PROVIDERvault-shared or blankcustomer-acs
VAULT_NOTIFICATION_API_URLrequirednot needed
VAULTNOTIF_SIGNING_KEYrequirednot needed
ACS_EMAIL_ENDPOINTblankcustomer's ACS URL
ACS_EMAIL_KEYblankcustomer's ACS key

Required variables for customer-acs mode:

VariableSet onDescription
EMAIL_PROVIDERDispatcher + ProcessorSet to customer-acs on both Function Apps
ACS_EMAIL_ENDPOINTDispatcher + ProcessorYour ACS endpoint URL
ACS_EMAIL_KEYDispatcher + ProcessorYour ACS access key
ACS_EMAIL_FROMDispatcher + ProcessorVerified sender address (e.g. noreply@contoso.com)

Choosing a Mode

vault-sharedcustomer-acs
Setup requiredNone (default)ACS resource in your tenant; set on both Function Apps
REFRACT PDF infrastructure in notification pathYes (metadata only - email address, portal link, notification type)No - REFRACT PDF infrastructure not involved
Document data crosses boundaryNeverNever
Applies toREFRACT Delivery, REFRACT eSign, REFRACT WorkflowREFRACT Delivery, REFRACT eSign, REFRACT Workflow
Use whenStandard deploymentsStrict zero-transit requirements for any notification metadata

What Each Product Sends

ProductNotificationRouted via EMAIL_PROVIDER
REFRACT DeliveryRecipient delivery invitationYes
REFRACT DeliveryOTP code (when requireOtp: true)Yes
REFRACT eSignOTP codeYes
REFRACT eSignCompletion notificationYes
REFRACT eSignSigner invitation (initial + sequential)No - sent directly by eSign Portal via REFRACT Shared Services ACS
REFRACT WorkflowParticipant portal linkYes
REFRACT WorkflowApprover notificationYes
REFRACT WorkflowChange-request and resubmission notificationsYes

Data Sovereignty

In both modes, document content, rendered PDF bytes, form field values, and file attachments are never included in any notification message. Notifications carry only the minimum metadata required to perform delivery: recipient email, portal access link, notification type, and document name.

On this page