Prerequisites
- A DocuSign organization with organization administration enabled (DocuSign Admin). One account can belong to only one organization; an organization can contain many accounts.
- An organization administrator who can register an integration key, grant admin consent, and identify the admin user Oleria will act as.
- An impersonated admin user - an existing DocuSign user whose permission profile grants account administration. Oleria acts as this user for both reads and remediation. A dedicated service user is recommended over an employee account.
Use a service account (not an employee account) for the integration to ensure continuity. The impersonated user’s permission profile must grant account administration for remediation actions to be available.
What Oleria collects
Set up the integration
DocuSign authentication uses JWT Grant with an RSA key pair. You register an app (integration key) in DocuSign, grant it consent to act on behalf of your admin user, and provide the credentials to Oleria.1
Create an integration key
- Log in to DocuSign and go to Settings → Apps and Keys (requires organization or account admin).
-
Select Add App and Integration Key, give the app a name (e.g.
Oleria), and select Create App. - Copy the Integration Key (the app’s client ID) - you will enter this in Oleria.
2
Generate an RSA key pair and add a redirect URI
- In the app, under Service Integration, select Generate RSA.
- Save the private key immediately and securely - DocuSign displays it only once. You will paste it into Oleria.
- Under Additional Settings → Redirect URLs, select Add URI and enter:
3
Grant admin consent
The integration key must be consented to impersonate users with the scopes Oleria needs. Before opening either URL below, replace Demo (developer sandbox):This is a one-time grant for the entire organization.
YOUR_INTEGRATION_KEY with the integration key from Step 1. Then open the consent URL in a browser, signed in as an organization administrator, and approve.Production:After approving, DocuSign redirects to
www.docusign.com - this is expected. Consent is recorded even if the redirect shows an error page.4
Identify the impersonated user
- In DocuSign Admin, go to Users and open the admin user Oleria should act as.
-
Copy the user’s API Username - a GUID in the format
bd75353b-52ed-44c6-b408-829fc56f4664. This is the Impersonated User GUID. - Confirm this user’s permission profile grants account administration (required for remediation actions - see Permissions for remediation below).
Connect DocuSign to Oleria
1
Open the integration
Log in to your Oleria workspace and navigate to Integrations → DocuSign → Connect.
2
Provide your credentials
Provide the following and select Authenticate:
3
Complete the connection
Oleria validates the connection, discovers your DocuSign accounts, and begins the first sync.
Verify the integration
Confirm DocuSign appears in your Oleria workspace connected integrations. After the first sync completes, you can review the discovered users, groups, permission profiles, and access in your Oleria workspace.Permissions for remediation (optional)
Read-only inventory requires only the read scopes granted in Step 3. To run remediation actions, the impersonated user’s permission profile must authorize the relevant writes.
Oleria checks these permissions before offering an action - an under-privileged connection shows the action as unavailable rather than failing mid-run.
Supported remediation actions
- Disable / Enable user - closes or reactivates the user’s membership across every account they belong to in the organization. Reactivation sends the user a DocuSign activation email, which they must click to become fully active.
- Add / Remove from group - targets the specific group you selected in its owning account. Does not affect same-named groups in other accounts.
- Assign / Remove role - changes the user’s permission profile in the account that owns that role.
Notes and limitations
- Multi-account: one connection manages the entire organization. Disable/enable is organization-wide by design - a user is closed in each account they belong to. Per-account-only disable is not currently supported.
- Activity requires the DocuSign Monitor add-on. Without it, activity data is empty; all other data remains unaffected.
- Resources: templates and folders are treated as durable, ACL-governed resources and are inventoried with their access grants. DocuSign envelopes are transactional documents and are not inventoried.

