I started at Conga in 2014 as an operations analyst and left in 2026 as a principal solutions engineer. Everything in between was the same job in escalating form: understand what a customer’s process actually is — not what the org chart says it is — and work out whether the software in front of us could carry it. Mostly that meant contract lifecycle management and document automation for Fortune 500 companies and financial institutions, the kind of buyer who sends a security architect to the second call and a procurement lawyer to the fourth.
After the Apttus/Conga merger I ended up training the enterprise solutions engineering organization — twenty-plus engineers, through workshops, coaching, and content I had to write from scratch. Teaching a thing is where you find out how much of your own understanding was pattern-matching. That period is probably the single biggest reason I stopped being satisfied with knowing a platform from the outside.
The legal floor is the same everywhere in US commerce: the ESIGN Act and state adoptions of UETA make an electronic signature enforceable, and eIDAS covers counterparties in the EU. That question is settled and nobody in an enterprise evaluation spends time on it. What differs by industry is the overlay — what the security architect, the compliance officer, and the procurement lead each need to see before the signature is allowed to happen at all. That overlay is what actually transfers between engagements, and it is rarely on the requirements list.
Multi-entity, multi-jurisdiction agreements where governing law and entity-specific templates change by region, and legal, procurement, and IT architecture each hold an independent veto. The technical evaluation is usually the easy half.
What the review asksA current SOC 2 Type II report, the period it covers, and whether there were material findings or corrective actions — not a badge, the actual report. US-only data residency as a mandate rather than a preference, and how tenant data is isolated in a multi-tenant environment. Tamper-evident access logging on designated sensitive agreements, so visibility itself is auditable. And a subprocessor question that catches most vendors flat: when contract text is run through a translation or AI feature, does it leave the vendor's environment, and through whom.
Protected health information (PHI) inside generated documents, and a set of questions that arrive before the first demo rather than after the technical fit is established.
What the review asksA business associate agreement (BAA) is a gate, not paperwork — it gets asked in the first call and the answer determines whether there is an evaluation at all. The distinction that actually changes the architecture: is PHI embedded in the generated document, or only used to populate it and then discarded? Those are different retention, storage, and audit stories. HIPAA audit-trail expectations attach to the signing process itself, not only to the repository the executed document lands in.
Legacy document-composition platforms with deep, IT-owned footprints. The migration path matters more than the feature comparison, because nobody is worried about whether the new tool works — they are worried about the templates already running.
What the review asksHealth and dental lines carry the same PHI and BAA questions as providers do, which surprises teams who assumed the payer side was lighter. Signing-process scoping starts with which regime actually applies — HIPAA audit trail, 21 CFR Part 11 where a life-sciences affiliate is in scope, or neither — because the answer sets whether the signature manifestation has to live on the record itself or can live in the audit log. Getting that wrong late is expensive; asking it in discovery is free.
Formal request-for-information and request-for-proposal procurement, security review as a gate rather than a step, and scope that turns out to be template migration off an incumbent rather than the greenfield build the requirements document described.
What the review asksState procurement codes set the contracting rules before any vendor is chosen — Hawaii's HRS Chapter 103D, for one, drives specific transparency and public-records obligations that become audit-trail requirements in the tool. FedRAMP authorization and CMMC certification get asked as status-and-roadmap questions, and 'not yet, here is the timeline' is a survivable answer where a vague one is not. The procurement path is often the real constraint: a cooperative vehicle like NASPO ValuePoint, or a government distributor such as Carahsoft, is frequently faster than a competitive RFP and changes who you are actually selling to.
Sell-side agreements — gift agreements, sponsored programs — running alongside procurement contracting that stays deliberately separate. Two contract lifecycles, one institution, and a strong preference for not merging them.
What the review asksClick-wrap exposure is the live risk: departments accept subscription terms nobody in legal ever saw, so the requirement is capturing them into the repository, not preventing them. Automated security review is increasingly a workflow step with a real integration behind it rather than an approval checkbox. Retention rules and linked-document hierarchies matter because the audit question is not 'do you have the NDA' but 'do you have the NDA, its amendments, and proof of which version was signed'.
Flow-down clauses to subcontractors, and post-execution obligations that are the actual pain even though the evaluation starts at document generation.
What the review asksCertificate of insurance issuance is its own record with its own approval and signature path, not an attachment to the master agreement — teams that model it as an attachment rebuild it later. Performance and payment bonds get triggered off a work order rather than the contract, which means the obligation engine has to watch a different object than the one being signed. FedRAMP and CMMC come up here too wherever defense or federal work is downstream in the supply chain.
Documents generated and signed at a site that may have no connectivity, which quietly converts an e-signature requirement into an offline-capability requirement and changes which architecture is even viable.
What the review asksEnforceability rests on the same ESIGN and state UETA foundation as anywhere else, but the evidence question is harder: intent to sign and attribution have to be captured on a device that cannot reach a server at the moment of signing, then reconciled afterward without breaking the chain. Vendors who only demo a browser signing flow have not answered it.
High-volume vendor, franchise, and client agreements across distributed operations, where the buyer is usually a legal-operations team trying to standardize on one signing vendor rather than adding another.
What the review asksVolume changes the problem from correctness to control: templates drifting into unmanaged Word copies at the location or franchisee level, and executed agreements that never make it back into a repository. The compliance ask is usually consolidation and retention — one signing platform, one audit trail, and a defensible answer to which version a given location actually signed.
Quoting logic trapped in spreadsheets, statements of work disconnected from the customer relationship management (CRM) system, and post-merger catalog consolidation where three product lines have to become one configurable one.
What the review asksSecurity and compliance shows up as a scored RFP category rather than a conversation: current SOC 2 Type II, GDPR and CCPA posture, role-based access control, audit logging, and — newly and increasingly — AI governance documentation as a named line item. The migration requirement gets the hardest scrutiny: proven methodology, tooling for products, price books, quotes, orders and approval rules, and a phased cutover. The honest answer about what has and hasn't been migrated before beats the confident one.
Quote-to-agreement flows across merged Salesforce orgs carrying two different sales processes, where the hard part is reconciling the processes rather than configuring the software.
What the review asksLease and lease-adjacent agreements are obligation-heavy after signature — renewal and notice windows, escalation dates, option exercises — so the requirement that decides the deal is post-execution tracking, not authoring. Migrating legacy agreements with enough version certainty to prove which one is operative is usually the unglamorous blocker.
Level$ began as a domestic argument, not a portfolio piece. Two people, one income that moves and one that doesn’t, a mortgage, daycare, and a recurring disagreement about the dining-out line. Every budgeting app we tried assumed one person was doing the budgeting, wanted everything categorized by hand, and had nothing to say when one of us just wanted to ask whether we could afford something without opening a laptop. So I built the version that answers the phone.
What I didn’t expect was how much of the work turned out to be the presales instinct in a different costume. A voice agent over real bank data is a weekend build. Convincing yourself it isn’t quietly wrong takes considerably longer — a shared calculation instead of two that can drift, a parity assertion that fails the build when they do, a check that traces every spoken figure back to a real tool return. That is the same question a bank’s security review asks, asked of my own work: not “does it work” but “how would you know if it didn’t.”
Solutions engineering, solutions architecture, or applied-AI work at a company building agent systems that have to hold up in production — voice, customer experience, trust and fraud, or AI infrastructure. I want a seat where the technical depth is the job rather than a bonus, and where I’m building the thing as well as explaining it. I bring an unusually specific stack of prior context with me: contract lifecycle management, document generation, e-signature, and Salesforce architecture at enterprise scale, which is exactly the surface most AI companies eventually have to sell into and rarely have anyone in-house who has lived in.
Denver-based, hybrid or remote. The fastest way to get a sense of how I work is the voice line case study — including the part where it says the results aren’t measured yet.