Parties
Full legal names and contact information for the granting entity, the recipient, and any third-party administrators.
A concise, well-completed Business Use Tunnel reduces operational risk by defining scope, access limits, and accountability; it supports audits, incident response, and contractual compliance without replacing standalone service agreements or technical change controls.
The Business Use Tunnel is completed by administrators, project sponsors, or contract managers who control resource access and by third parties or internal users receiving permission.
Signatures usually come from an authorized representative of the granting party and an authorized recipient, with IT and security teams copied for operational handoff.
Full legal names and contact information for the granting entity, the recipient, and any third-party administrators.
Precise description of the tunnel's purpose, allowed activities, systems or networks accessible, and any excluded uses.
Effective date and expiration or review date, plus renewal or automatic-expiry conditions.
Authentication method, encryption requirements, permitted IP ranges, multi-factor needs, and monitoring or logging obligations.
Operational duties, incident reporting procedures, liability allocation, and who performs deprovisioning.
Signatory authority, date fields, and space for notarization or witness details when required.
| Field | Configuration |
|---|---|
| Required Fields | Grantor, Grantee, Scope, Effective/Expiration Dates |
| Review Order | Security → Legal/Procurement → IT Operations → Signatories |
| Signer Authentication | Email + optional SMS or two-factor for high-risk access |
| Audit Trail | Enable full timestamping, IP logging, and certificate-of-completion |
Ensure the selected service supports exportable audit reports, long-term storage formats (PDF/A), and, where required, HIPAA or 21 CFR Part 11 controls.
3–5 business days for security review
5–10 business days when third-party terms apply
1–3 business days after approvals
Immediate automated removal on expiration or within 24 hours
Retention measured from Effective Date
Requester completes template and assigns reviewers.
Technical team approves scope and required controls.
Legal or procurement confirms third-party obligations as needed.
IT implements tunnel and confirms connectivity.
A healthcare provider authorized a vendor to use a VPN for scheduled maintenance
A finance project required short-term access to billing systems by procurement
Signs to confirm technical feasibility and to accept responsibility for implementing security controls and deprovisioning at expiration. This party documents change tickets and operational handoff to IT operations.
Signs to confirm commercial and legal authority to grant access under existing agreements, ensuring indemnity, insurance, and liability terms are satisfied for third-party engagements.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |