# Faldaro
This is llms-full.txt: every page of https://faldaro.com in one file. The index alone is at https://faldaro.com/llms.txt
> Faldaro is the intake platform: everything the outside world sends you becomes a record and is worked to a decision by your rules, your team and your AI agents. Every number is computed on the server, and the people who send it are never seats.
This site (https://faldaro.com) is the product guide and documentation; the product itself runs at https://faldaro.app. Faldaro also hosts a Model Context Protocol server — see the MCP pages below for connecting an AI client to an account. The full content of every page below, in one markdown file, is at https://faldaro.com/llms-full.txt
---
# Faldaro
Source: https://faldaro.com/
Forms with approvals by email, status links for submitters, generated PDFs and e-signatures. Faldaro is the intake platform — free to start.
## Form tools collect what the world sends you. Faldaro works it to a decision.
Faldaro is the intake platform. Claims, applications and requests arrive through a public link and become records — priced, routed, approved, signed and paid by your rules, your team and your AI agents. Nothing is computed in the browser, and nobody who submits is a seat.
[Start free](https://faldaro.app/auth/signup) Watch the 45-second run
Free forever — unlimited forms, ten thousand submissions a month, AI credits included. No card required.
CLM-2026-0147 Risk review
Claim intake v3 · published
Arrived 09:12 through the public link — nobody on your side typed a thing.
- Client: Acme Logistics
- Incident: 14 Jul 2026
- Vehicles: 3
- Rate band: B
Estimate computed $12,400
1. 09:12 Submitted through the public link a stranger · no account · no seat
2. 09:12 Estimate computed: 3 × $4,000 + $400 towing on the server
3. 09:12 Moved to Risk review by rule
4. 09:12 Deadline armed: 48 hours escalates itself
5. 09:13 Agent note: “Band B, no injuries. Towing receipt missing — flagged for the reviewer.” acting on this record only
6. 09:13 Claims lead notified, tracking link mailed to the claimant by the form’s rules
audit log · append-only every line a mechanism as shipped
1 Submitted 09:12
Claim intake
Public link · v3
- Client: Acme Logistics
- Incident: 14 Jul 2026
- Vehicles: 3
- Rate band: B
`CLM-2026-0147`
2 Priced 09:12
Estimate
$12,400
`3 × $4,000 + $400 towing`
Computed on the server
Recomputed on every read
3 Approved 12:26
1. Submitted
2. Risk review
3. Approved
Claims lead approved from their inbox — no login.
Inside the 48-hour deadline
4 Paid 12:41
Excess
$500.00
Visa ···· 4242
Succeeded
`payment_status` recorded
5 Filed 12:41
Settlement letter
Generated PDF
Signed
Certificate page attached
One claim, start to finish: priced by the server, approved from an inbox, paid, and filed with its signed letter. Nobody opened a spreadsheet.
### Somewhere in your company, the outside world lands in a spreadsheet
A claim arrives through a form, someone exports it, and the real work starts by hand. The spreadsheet becomes the system — and everything wrong with it happens after submit.
#### The total checked by hand
The server computes it from the answers, on every save and every read. There is no number to double-check, because there is no number a browser can send.
#### The approval chased by email
A workflow state with an owner and a deadline that escalates itself. Forty-eight hours in Review and the record moves — nobody has to remember to chase it.
#### The paperwork assembled by copy-paste
Documents generate from the submission the moment its state changes — and anything sold is priced by the rules and delivered on settlement, from the same record.
That spreadsheet — and the inbox around it — is the product Faldaro replaces.
### Folders group forms. Forms produce submissions. That's the whole model.
An insurer configures a Policies folder and a Claims folder. A support desk configures Tickets. Neither waits on a developer, because nothing in Faldaro is specific to a business domain — the platform takes the shape of whatever arrives.
Folders your nouns, not ours
[Policies Quote calculations, renewal workflows](https://faldaro.com/use-cases/insurance) [Claims Intake, estimates, approval chains](https://faldaro.com/use-cases/insurance) Claim intake v3 · published
CLM-2026-0147 Risk review $12,400
[Tickets Routing logic, states, notifications](https://faldaro.com/use-cases/support-desk)
folder form submission
What makes it an intake platform
### Three laws no form builder keeps
Each is a property of the architecture, not a feature on a list — and each is checkable in behaviour before you commit anything.
1. 1
#### The outside world is never a seat.
Submitters, brokers, approvers, signers and portal users cost nothing and are never metered. Submissions are never capped or billed by count on any plan — a fifty-person organization collects from fifty thousand. You pay for your team, never your audience.
[Pricing](https://faldaro.com/pricing) · [Records & sharing](https://faldaro.com/features/records) · [Partner organizations](https://faldaro.com/docs/sharing)
2. 2
#### The server owns the truth.
Every number is computed on the server on every save and every read — a browser cannot send a total, and a payment request has no field an amount could ride in. Published versions are immutable, every record keeps the version it was filled against, and the audit log is append-only because the database refuses to rewrite it.
[Builder, logic & calculations](https://faldaro.com/features/form-builder) · [Workflows](https://faldaro.com/features/workflows) · [Documents & payments](https://faldaro.com/features/documents-payments) · [Reports & datasets](https://faldaro.com/features/reports-data) · [Security](https://faldaro.com/security)
3. 3
#### AI works with a badge, not a master key.
The assistant, the standing agents and the MCP server act with exactly the permissions of the person or key behind them — bounded by the database, not by prompt engineering — with no delete tools and no credentials of their own. What a stranger typed arrives marked as data: the assistant cannot change anything in a turn that has read it, agents work inside fences of their own, and over MCP the marking reaches your client’s model intact.
[AI agent](https://faldaro.com/features/ai) · [MCP server](https://faldaro.com/features/mcp) · [Email-to-form](https://faldaro.com/features/inbound-email)
### An agent that works the queue, not a chatbox that describes it
Ask for a form and the assistant builds the draft, wires the logic and takes you there. Leave a standing agent on a form and it works what arrives — with exactly the permissions you granted, every step shown, and no delete tools, admin tools or credentials of its own. The agent proposes; you dispose.
[See everything the agent can do](https://faldaro.com/features/ai)
Assistant acting as you
Turn this PDF into our claims intake form.
- Read claim-intake.pdf
- Drafted 12 fields and 3 rules
- Wired estimate = vehicles × band_rate
- Opened the builder for your review
Draft ready — nothing is saved until you publish.
scope: your permissions no delete tools
#### Import a PDF as a fillable form
A working, editable draft — not a screenshot.
#### Prefill from a document
Matching fields fill themselves for your review.
#### Plain English to a filter
“Unpaid claims over $5,000” becomes the exact query.
#### Reports on demand
Describe the report; refine it in the builder it seeds.
### Records that travel
A submission isn’t filed to be forgotten. It becomes a card someone drags, a status a submitter tracks, an approval decided from an inbox, a chart on someone’s site — each behind its own revocable link that carries the projection and never the data.
#### A board you can drag
The same records as a table, a board, a calendar or cards. The board’s columns are your workflow’s own states — dragging a card takes the exact move the record page offers, every server-side rule intact, and a drop the rules withhold says why.
#### “Track your request”, per record
Mint a status link and the submitter watches their own record move — stage, reference number, last update, and nothing else. Drop {{status_link}} into a confirmation email and every record ships with the package-tracking experience.
#### Charts that leave the building
Share a grouped report as a live read-only page, embed the chart in any site, or schedule it as a daily or weekly email digest to people who never log in. Aggregates travel; individual records never do.
#### A portal from just an email
Submitters see all their records in one place with nothing but their address: a secure link, mailed to the mailbox itself, listing each record’s live status. You choose the one field that identifies them — nothing else ever matches.
#### Publish a form as a template
One link makes your form’s design cloneable by anyone — fields, rules and workflow travel; your data, datasets and integrations never do. The clone lands in their workspace, not yours.
#### Approvals from an inbox
A workflow action mails each approver their own approve/decline link — no account, no login. You choose which move each verdict takes and exactly which fields they see; the decision lands on the record with a name, comment and timestamp.
Boards, tracking links, approvals, shared reports, the portal and templates — all of it on every plan, spelled out on the [records page](https://faldaro.com/features/records).
### Built the other way round
Form builders are genuinely good at collecting answers. Work-management tools are genuinely good at work that stays inside the company. Faldaro is built for the work that arrives from outside it — the public form is the front door, and what walks through is worked, not exported.
| | Form builders | Work-management tools | In Faldaro |
| --- | --- | --- | --- |
| The person who submits | A metered response. | A seat, or a guest with a login someone had to create. | Never a seat and never metered — a tokenized link to fill, a tracking page to watch, an approval or signature taken from their own inbox. |
| The total | Computed in the browser; whatever arrives is stored. | A formula in a grid, editable by anyone with the sheet. | Recomputed by the server on every save and every read. A browser cannot fabricate a number. |
| The submission | A row you export. | A record, once someone with a seat has keyed it in. | A record from the first second — with a state machine, an owner, a deadline and an audit trail, minted by the stranger who submitted it. |
| The form itself | Edited in place, under responses already collected. | A view over the table. | Published as an immutable version. Every submission keeps the definition it was filled against. |
[Every difference, side by side](https://faldaro.com/why-faldaro) The first two columns describe how each category usually works, not any one product — check yours. Underneath Faldaro's: tenant isolation enforced by the database, immutable published versions, an append-only audit log. Each claim is checkable in behaviour, spelled out on the [security page](https://faldaro.com/security).
Built to be reviewed
### Security you can verify in the design
Every control here is a property of the architecture, not a setting — and each is spelled out where a reviewer can check it.
[Trust centre](https://faldaro.com/trust) [Security page](https://faldaro.com/security) [Enterprise](https://faldaro.com/enterprise)
- [Tenant isolation enforced by PostgreSQL Row-level security; the service refuses to start without it.](https://faldaro.com/security)
- [An append-only audit log Update and delete revoked from the application role.](https://faldaro.com/security)
- [Immutable published versions Every record keeps the definition it was filled against.](https://faldaro.com/docs/concepts)
- [Single sign-on with your provider OIDC on Enterprise; passkeys on every plan.](https://faldaro.com/docs/sso)
- [Retention you can prove Scheduled purges, each one recorded.](https://faldaro.com/docs/retention)
- [Public links that are opt-in and revocable Tokenized, throttled, every refusal an identical not-found.](https://faldaro.com/docs/public-forms)
Your first five minutes
### Leave with a door open, not a trial
No demo call, no sandbox tour, no imported sample data pretending to be yours. The first session ends with the outside world able to send you something — and the first thing it sends, worked.
#### 1 Say what arrives
Sign up — no card — and tell the agent what the outside world sends you: “claims from policyholders, with an estimate and a review step.” Or upload the PDF you make people send you today. Either way, a working, editable draft appears in the builder. 18 templates, if you would rather start from one.
#### 2 Make it yours
Adjust the fields on the canvas, watch the logic react in the preview, name the states work moves through. Publishing creates version one — immutable from that moment, like every version after it.
#### 3 Open the door
Issue the public link and send it to anyone. No account on their side, never a seat on yours — and the first thing that arrives is not a row but a record: values the server computed, a state to move it through, a tracking link for whoever sent it, an audit trail already started.
Try it on your own document
### Drop the form you make people send you
The intake sheet, the application, the claim form you still email as a PDF — drop it here and watch it come back as a working draft, no account required. Sign up and the agent builds the real thing from the whole document: computed totals, logic, workflow and a publishable link.
The converter also lives on its own page: [PDF to online form](https://faldaro.com/tools/pdf-to-form). Or start from a [free template](https://faldaro.com/templates) with the workflow already built.
Import a document no account required
Drop a PDF here — the form you make people print, the intake sheet, the application —
and watch it come back as a working draft. PDF or photo, up to 5 MB.
Reading your document…
Bigger documents take longer — this can run for a minute or two.
A draft, from your own document — fields and choices included. Signing up (free) lets the agent build the real thing from the whole document: it also reads a fillable PDF's own field definitions, drafts computed totals, logic and workflow, and hands you a publishable link — all editable in the builder.
[Build it for real — free](https://faldaro.app/auth/signup) Try another document
Try again [Or start free — the import runs inside too](https://faldaro.app/auth/signup)
Read once to draft this preview — nothing is stored, no account is created.
### Or watch the whole run
Forty-five seconds, no signup: a PDF becomes a form, a stranger submits, the server computes the total, and the record routes itself to review. Every scene is the product as shipped — nothing mocked, nothing sped past.
A looping demo of Faldaro. An agent reads a claim-intake PDF and turns it into a real, editable form; wires the estimate calculation and its conditional rules, validated against the form's own fields before saving; adds a workflow that routes any claim over $10,000 to risk review; a submitted claim is priced at $12,400 by the server and stamped with the reference CLM-2026-0147; and the phrase “unpaid claims from July over $5,000” compiles into an exact submissions filter. Throughout, the agent acts with your permissions, has no delete tools, and saves nothing until you publish.
faldaro.app /forms/new Assistant
Turn this PDF into our claims intake form, price the estimate, and send anything over $10,000 to risk.
claim-intake.pdf
- Read claim-intake.pdf — 3 pages, 12 questions
- Built Claim intake — 12 fields, 4 sections
- A working draft you can edit — not a picture of one
Calculations and conditional rules
estimate = vehicles × band_rate + excess
show excess when damage_type = "collision"
require adjuster_note when estimate > 10000
3 rules validated against this form's own fields
vehicle_count — not a field here. Dropped before it saved.
Workflow
Draft Submitted Risk review Approved
when estimate > 10,000 requires submission:transition
On entering risk review
- Notify the risk team · generate claim-summary.pdf
Routing is a property of the form, so nobody has to remember it
Claim intake Risk review
Client Acme Logistics
Vehicles 3
Damage type Collision
Estimate $12,400 computed on the server
CLM-2026-0147 v3 · published · audit entry written
unpaid claims from July over $5,000
payment_status = unpaid submitted ≥ 1 Jul estimate > 5000
CLM-2026-0147 Acme Logistics $12,400
CLM-2026-0151 Northbridge Ltd $8,900
CLM-2026-0158 Peak Freight $6,200
3 of 1,284 submissions — every field name checked against your form first
acting as you no delete tools nothing saved until you publish
import_pdf_as_form
You describe the outcome. The agent does the work.
### The next thing that walks in could be the first one you never export
Describe what arrives — or upload the PDF you use today — and open the door in the same sitting. Free forever: unlimited forms, ten thousand submissions a month, AI credits included.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Features: forms, workflows, approvals, AI
Source: https://faldaro.com/features
Everything around the form: a builder with server-evaluated logic, approval workflows, AI assistance, generated documents, payments and digital delivery.
## Everything around the form
A form is the start of a piece of work, not the end of it. These are the parts of Faldaro that carry the work the rest of the way — and every one of them ships on the Free plan's builder, so you can try before any of the limits matter.
[Form builder & logic Fields, conditional logic and calculations, evaluated on the server.](https://faldaro.com/features/form-builder) [Workflows Draw the states and moves that carry a submission from draft to done, with effects.](https://faldaro.com/features/workflows) [Records & sharing Boards, tracking links, shared reports, @mentions, a submitter portal — the life after submit.](https://faldaro.com/features/records) [AI agent An agent that builds, fills, files and filters — with exactly your permissions.](https://faldaro.com/features/ai) [MCP server Connect Claude to your account: your model, your key’s permissions, our tools.](https://faldaro.com/features/mcp) [Email-to-form Forward a message to a form’s own address and it becomes a submission, sender verified.](https://faldaro.com/features/inbound-email) [Documents & payments Generated PDFs, server-priced payments, e-signatures and digital delivery.](https://faldaro.com/features/documents-payments) [Reports & datasets Group, aggregate and search live submissions — no export required.](https://faldaro.com/features/reports-data) [Approval workflows Multi-step approvals decided from an email link — no approver account, deadlines that escalate.](https://faldaro.com/features/approvals) [Security & audit Tenant isolation, versioning and an append-only audit log — enforced by the database, not by promises.](https://faldaro.com/security)
Also worth a look: [submission management](https://faldaro.com/submission-management) for what happens after the form, [integrations](https://faldaro.com/integrations) for what Faldaro connects to today, the free [PDF to online form](https://faldaro.com/tools/pdf-to-form) converter, and the [guides](https://faldaro.com/guides) to approvals and intake.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Submission management software
Source: https://faldaro.com/submission-management
Submission management from form to decision: collect applications, claims and requests, approve by email, send documents and let submitters track status.
Submission management software
## Submission management, from the form to the decision
Applications, claims and requests from outside your organization — collected on a form, routed through review, approved from an inbox, answered with a document, and tracked by the submitter on a status link. One platform instead of a form tool, a spreadsheet and an email thread.
[Start free](https://faldaro.app/auth/signup) [Browse templates](https://faldaro.com/templates)
The whole lifecycle
### Six things a submission needs after it arrives
A form builder does the first. The rest is where the work — and the mistakes — used to live.
#### Collect
Public forms on an unguessable link, multi-page with conditional logic, file uploads, payments and 24 languages — or an email address per form, so forwarded mail becomes a submission too. Import the PDF you already use and it becomes the form.
#### Route
Every submission gets a state, an owner and, if you want one, a reference number. Rules assign it, a board shows the queue, and deadlines move what stalls. Datasets and indexed fields make the list filter fast.
#### Decide
Approval steps drawn as a diagram, approvers who decide from an email with no account, and conditions that gate each move. Totals and scores are computed on the server, so the figure a reviewer sees is one nobody typed in.
#### Respond
Each decision can send the email, generate the letter or certificate as a PDF, request an e-signature or a payment, and hand the submitter a status link that shows where their submission is.
#### Report
Group and total live submissions, share a report as a public page or a weekly digest, and — for the pattern-minded — ask for statistical insights and predictions over the history.
#### Keep the record
The submission keeps the exact form version it was filled against, its documents and an append-only audit log of every move. Settling a dispute is a read, not a reconstruction.
The details: [form builder](https://faldaro.com/features/form-builder), [approval workflows](https://faldaro.com/features/approvals), [records and status links](https://faldaro.com/features/records), [documents and payments](https://faldaro.com/features/documents-payments) and [reports](https://faldaro.com/features/reports-data).
What arrives
### Built for work that comes from outside
Nothing in Faldaro is specific to one industry — a folder of forms, a workflow and a few rules cover each of these.
#### Applications
Grants, memberships, vendors, jobs, event stalls — review, decide, notify.
#### Claims and requests
Insurance claims, certificate and loss run requests, maintenance and project requests.
#### Registrations and orders
Events and digital products, with payment priced on the server.
#### Reports and incidents
Inspections and incidents that need follow-through, not just a spreadsheet row.
See the [use cases](https://faldaro.com/use-cases) or start from a [template](https://faldaro.com/templates).
Questions
### Submission management, plainly
**What is submission management software?**
Software for everything that happens after someone outside your organization sends you something — an application, a claim, a request, a registration. A form builder stops at collecting it; submission management carries it through review, decisions, documents and follow-up, and keeps the record.
**Do the people submitting need an account?**
No. They fill a public link — or forward an email to the form’s own address — and can follow progress on a status link or in a no-account portal that lists their own submissions. Submitters are never seats on your bill.
**Can reviewers outside our team take part?**
Yes. Approvers decide from an email link with no account, and partner organizations can submit through your forms from their own workspace, their submissions isolated from each other by the database.
**How is it priced?**
There is a Free plan with the builder, workflows, approvals, status links and reports. Paid plans are a flat monthly price for your team with seats for the people who work the submissions — never per submitter. See the pricing page for the details.
**Can we move off it later?**
Yes. Reports export to CSV on plans that include exporting, submissions are reachable through the API, and generated documents are ordinary PDFs.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Convert PDF to online form — free, no signup
Source: https://faldaro.com/tools/pdf-to-form
Free PDF to online form converter: drop a PDF or a photo of a paper form and get a web form people fill on any device. No account; files are not stored.
Free tool · no signup
## Convert a PDF to an online form
Drop a PDF — or a photo of a paper form — and watch it come back as a web form people can fill on any device. Free, no account needed, and your file is not stored.
Import a document no account required
Drop a PDF here — the form you make people print, the intake sheet, the application —
and watch it come back as a working draft. PDF or photo, up to 5 MB.
Reading your document…
Bigger documents take longer — this can run for a minute or two.
A draft, from your own document — fields and choices included. Signing up (free) lets the agent build the real thing from the whole document: it also reads a fillable PDF's own field definitions, drafts computed totals, logic and workflow, and hands you a publishable link — all editable in the builder.
[Build it for real — free](https://faldaro.app/auth/signup) Try another document
Try again [Or start free — the import runs inside too](https://faldaro.app/auth/signup)
Read once to draft this preview — nothing is stored, no account is created.
How it works
### From paper to a working form in three steps
#### 1 Drop your PDF or a photo
The application, the intake sheet, the claim form you still email as an attachment — up to 5 MB.
#### 2 See it as a web form
The fields, their types and their choices come back as a draft you can read through, in a minute or two.
#### 3 Build it for real
Sign up free and the agent builds the whole form — logic, totals and a workflow — ready to publish on a link.
Questions
### Before you upload
**Is it free? Do I need an account?**
The converter above is free and needs no account. It drafts a preview of the form from your document. Signing up — also free — lets the agent build the full form from the whole document and gives you a link you can publish.
**Do I get a fillable PDF back?**
No — you get something better for collecting answers: a web form that works on any phone, validates what people type, and sends each response into a list you can review. If you need a PDF of each response, Faldaro can generate one from your own document’s layout, filled in with the answers.
**Does it work on scanned or photographed forms?**
Yes. Upload a PDF, or a PNG, JPEG or WebP photo of a paper form, up to 5 MB. The AI reads the page the way a person would, so a scan with no text layer still works; a very blurry photo gives a rougher draft.
**What happens to my file?**
It is read once to draft the preview and not stored anywhere. Nothing is saved until you sign up and choose to build the form.
**What can the finished form do that the PDF could not?**
Show and hide questions based on earlier answers, compute totals on the server, take file uploads and card payments, send each response through an approval workflow, request e-signatures, and give the person who filled it a link to check on its progress.
Starting from scratch instead? Browse free [form templates](https://faldaro.com/templates), or see what happens after someone submits on [submission management](https://faldaro.com/submission-management). Weighing a fillable PDF against a web form? Read the guide: [how to convert a PDF to a fillable online form](https://faldaro.com/guides/convert-pdf-to-online-form).
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Quote calculator form with private pricing
Source: https://faldaro.com/tools/quote-calculator
Build a quote calculator form priced on the server: applicants see their price as they type, never your formula. Free insurance quote template included.
Quote calculator form
## A quote calculator form that keeps your pricing private
Applicants answer a few questions and see their price as they type. The price is computed on the server, so the formula never reaches the page and nobody can submit a number of their own. Start from the free insurance quote template and change the rates to yours.
[Use the template free](https://faldaro.com/templates/insurance-quote) [Build your own](https://faldaro.app/auth/signup)
Insurance quote calculator — what the applicant answers
- Business name
- Email
- What the business does
- Years in business
- Annual revenue
- Employees
- Liability limit
- Deductible
- Estimated annual premium computed on the server
- Anything the underwriter should know
How it works
### A price from the answers, not from the browser
#### Priced as they type
With live evaluation on, the figure updates from the server on every answer — the same engine that prices the submission.
#### Your rates stay private
Visitors see the price, never the formula. Rating logic is not something a public form should hand out.
#### A quote becomes a record
Each request lands with its computed premium, moves through underwriting to quoted and bound, and keeps an audit trail.
More on how formulas work in the [formulas guide](https://faldaro.com/docs/formulas), and on the insurance side in [claims and quotes](https://faldaro.com/use-cases/insurance).
Questions
### Quote forms, plainly
**Can visitors see how the price is calculated?**
No. The formula runs on the server. The public form receives the computed figure and nothing else — the field is marked as computed and the expression behind it is withheld — so a competitor cannot lift your rating by opening the page source.
**Can someone change the price before submitting?**
No. The server recomputes every figure when the form is submitted and stores its own result alongside the answers, so a price edited in the browser is simply replaced by the real one.
**What can the formula do?**
Arithmetic, comparisons and a closed set of functions — MAX, MIN, ROUND, ABS, FLOOR, CEIL, plus functions for checkbox groups, tables and blank answers. It never executes code, and every formula is checked when you publish.
**Is this only for insurance?**
No — the same form prices cleaning jobs, event stalls, memberships, print runs or anything else priced from a few answers. Insurance is the template because it is the case where keeping the rating private matters most.
**Can the form take payment for the quoted amount?**
Yes. A payment rule collects a Stripe payment priced by the same server-side formula, so the amount charged is the amount computed, never a number the browser sent.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Integrations: Zapier, Slack, Stripe, webhooks, MCP
Source: https://faldaro.com/integrations
What Faldaro connects to today: Zapier, Slack and signed webhooks, Stripe payments, OIDC single sign-on and Google sign-in, the REST API and MCP, email and CSV.
## Integrations
What Faldaro connects to today. Records go out to the tools you already run, payments land in your own Stripe account, people sign in the way your organization already does, and your software and your AI models drive it with exactly the access you grant.
### Send records onward
Rules and workflow moves deliver to a connection by its name, never by URL. Every delivery is a queued row first, retried with backoff and visible in a log.
- [Z Zapier Automation Send created, updated and transitioned submissions to a Zapier catch hook, and from there to the thousands of apps Zapier reaches. Every delivery is signed.](https://faldaro.com/docs/integrations)
- [S Slack Messaging Post a card to a channel when a record arrives or moves: its name, stage and leading fields, with a button back to the record. Submitted text is escaped, so a stranger cannot ping the channel.](https://faldaro.com/docs/integrations)
- [W Webhooks Any HTTPS endpoint POST a JSON envelope to your own systems, signed with HMAC-SHA256 and a timestamp you can check for replays. Hosts are allow-listed by the operator; redirects are never followed.](https://faldaro.com/docs/integrations)
### Take payments
The price is computed on the server from the answers; the page never states it.
- [S Stripe Payments Collect payments into your own Stripe account through Connect, with splits across recipients, refunds, payment requests from a workflow, and file delivery released on settlement.](https://faldaro.com/docs/payments)
### Sign people in
Identity comes from where your people already are.
- [S Single sign-on (OIDC) Identity Sign in through your organization’s own OpenID Connect identity provider on Enterprise, with sessions scoped to your organization and the organizations beneath it.](https://faldaro.com/docs/sso)
- [G Google sign-in Identity Create an account or sign in with a Google account, on every plan.](https://faldaro.com/docs/getting-started)
- [P Passkeys Identity Sign in with the device’s own biometrics or security key, no password to leak.](https://faldaro.com/security)
### Let software and AI drive it
Machine access holds exactly the privileges you grant it — the same authorization every person passes through.
- [M MCP server AI clients Connect Claude Desktop, Claude Code or any Model Context Protocol client with an API key. The model builds forms, files submissions and runs reports with that key’s permissions and no more.](https://faldaro.com/features/mcp)
- [R REST API Developers A versioned API to evaluate a payload against a form’s rules without storing it, or file a submission, with keys scoped to explicit privileges.](https://faldaro.com/docs/api)
### Bring work in
Not everything arrives through a link.
- [E Email Inbound Give a form its own address. A forwarded message becomes a submission, attachments attached and the sender verified against the domain’s own SPF and DKIM.](https://faldaro.com/features/inbound-email)
- [Y Your website Embed Embed any public form or shared report chart in your own pages with a snippet from the share panel, or hand out a QR code for the paper world.](https://faldaro.com/docs/public-forms)
- [S Spreadsheets CSV Import history from any form tool as CSV — reference numbers and workflow states included — and export records or report results the same way.](https://faldaro.com/docs/submissions)
### Connect it to what you already run
Stripe payments, the API and Google sign-in are on every plan. Zapier, Slack, webhooks and the MCP server are part of Team; single sign-on is Enterprise.
[Start free](https://faldaro.app/auth/signup) [Read the integrations guide](https://faldaro.com/docs/integrations)
No card required.
---
# Use cases — what the outside world sends you
Source: https://faldaro.com/use-cases
Claims, tickets, applications, registrations, orders and vendor packets — everything the outside world sends you, shaped to the work with no code.
## What does the outside world send you?
Claims, tickets, applications, registrations, orders, vendor packets. Nothing in Faldaro is specific to a business domain: folders group forms, forms produce submissions, and workflows carry them — so the platform takes the shape of whatever arrives. Nine worked examples:
[Insurance claims intake Claims from policyholders and brokers, with calculated estimates, approvals and a trail that survives a dispute.](https://faldaro.com/use-cases/insurance) [Support ticket intake Tickets from users, routed by your rules into a desk shaped like your process.](https://faldaro.com/use-cases/support-desk) [Inspections Checklists that come back as a report, not a folder of photos.](https://faldaro.com/use-cases/inspections) [Grant application intake Applications in from the public, decisions out, with the reasoning kept.](https://faldaro.com/use-cases/grants) [Event registration Registrations from attendees that take the payment and send the confirmation.](https://faldaro.com/use-cases/event-registration) [Digital products Orders from the public: sell a file without standing up a storefront around it.](https://faldaro.com/use-cases/digital-products) [Client intake From inquiry to a signed letter with a retainer behind it.](https://faldaro.com/use-cases/client-intake) [Job application intake Applications from candidates, with a pipeline behind them and every candidate answered.](https://faldaro.com/use-cases/job-applications) [Vendor intake & onboarding Documents present, approvals earned, and a trail that survives an audit.](https://faldaro.com/use-cases/vendor-onboarding)
Yours isn't listed? That's rather the point — membership renewals, maintenance requests, course enrollments and volunteer sign-ups are all the same three nouns wearing different names. Start with the [form builder](https://faldaro.com/features/form-builder) and shape it yourself.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Faldaro vs form builders and work tools
Source: https://faldaro.com/why-faldaro
How Faldaro differs from form builders and work-management tools: server-owned totals, immutable versions, and no seat for the people who submit.
## Built for the work that walks in the door
Tally, Typeform, Jotform and Google Forms are genuinely good at collecting answers — if a survey is all you need, use one. Airtable, Quickbase and their kind are genuinely good at work that stays inside the company. Faldaro is built for the work that arrives from outside it: a claim, an application, a request or an order comes through a public form and becomes a record that gets worked — calculated, routed, approved, signed, paid — on a platform built so none of it can be quietly rewritten, and where the people who send it are never seats. Which means the honest comparison is rarely another form builder. It is the stack a team wires together when the form tool runs out: the e-sign tool, the payment page, the automation glue and the spreadsheet that quietly became the system of record.
Mechanisms, not adjectives
### Twelve things that work differently here
Not a feature checklist — those age badly and every vendor ticks every box. These are differences in where the truth lives, and each one is checkable in behaviour.
| | In most form tools | In Faldaro |
| --- | --- | --- |
| A calculated total | Computed in the browser by the form widget. Whatever number arrives with the submission is what gets stored. | Recomputed on the server on every save and every read. A browser cannot fabricate a total, because nothing it sends is trusted as one. |
| A submission | A row in a results table. Working it — triage, approval, payout — happens somewhere else, after an export or a Zap. | A record with a state machine. Moving it from state to state is a separate, permissioned act from editing it, and every transition can notify, generate documents, call your systems. |
| Editing a live form | The form changes underneath the responses already collected; old answers are reinterpreted by the new questions. | Publishing creates an immutable version. Every submission keeps the exact definition it was filled against, forever. |
| The audit trail | An activity feed the application maintains — and could, in principle, rewrite. | Append-only because the database refuses updates and deletes on it, not because the application promises to behave. |
| Taking a payment | An amount field wired to a processor. The price is whatever the page said it was. | The server prices the submitted answers itself; the payment request has no field an amount could even ride in. Delivery of anything sold is gated on settlement. |
| Teams, clients and partners | Workspaces sharing one account, separated by convention. | An organization tree with isolation enforced by row-level security in PostgreSQL. Share a form with a partner organization — their submissions stay theirs, yours stay yours. |
| Changing a form you rely on | Preview it, publish it, hope nothing broke. | Named regression cases re-run through the real engine before you publish, so a change that would move a number someone pinned down is caught first. |
| A record that stalls | Reminder emails, at best — and someone still has to notice nobody acted on them. | States carry deadlines that fire real transitions: forty-eight hours in Review and Escalate happens by itself, with the same guards and notifications a person’s click would carry, audited as the deadline’s doing. |
| A form in another language | Duplicate the form per language and keep the copies in step by hand — two forms, two links, two piles of submissions to reconcile. | One form, one submission stream, a translation table per language substituted on the server. Choice values are never translated, so a French submission and an English one record the same data — and AI can draft the whole table for you to approve. |
| Form analytics | A tracker script in the embed, a cookie on the visitor, and a consent banner on you. | Views, starts and completions counted server-side — no cookie, no IP stored, no per-visitor row. Conversion numbers with nothing to disclose, because nothing is collected. |
| AI | A chatbot that drafts questions into the editor. | An agent acting inside the product with exactly your permissions — it builds forms, imports PDFs, wires logic and routes work, with no delete tools, no credentials of its own, and every step shown. |
| Who you pay for | Responses are the meter: growth in submissions is growth in your bill, and the tools that work them charge for every person who touches the system. | You pay for your team, never your audience. Submissions are never capped and never billed by count, and the people filling your forms are not seats — a fifty-person organization can collect from fifty thousand. |
The left column describes how form tools usually work, not any one product — check yours. The right column is spelled out mechanism by mechanism on the [security page](https://faldaro.com/security).
An honest sorting
### Which tool actually fits
Recommending a competitor when they fit is cheaper than a churned customer who was sold the wrong thing.
#### A form builder
Surveys, polls, waitlists, one-off feedback. The answers are the product, nobody works them afterwards, and time-to-published is the only metric that matters.
#### A work-management tool
Work that stays inside the company: a shared grid, a project board, a database every participant logs into. Strong tools, priced per person who touches them — right when everyone involved is an employee.
#### A vertical intake suite
One industry’s whole practice in one product — matter management for a law firm, a practice system for a clinic. Right when the suite is the job and intake is one feature of it.
#### Faldaro
Intake from outside the company: claims, tickets, applications, registrations that take money, orders. The submission has a lifecycle, someone is accountable for it, and the person who sent it is never a seat.
Weighing a specific tool? There is an honest page each for [Typeform](https://faldaro.com/alternatives/typeform), [Jotform](https://faldaro.com/alternatives/jotform), [Google Forms](https://faldaro.com/alternatives/google-forms), [Microsoft Forms](https://faldaro.com/alternatives/microsoft-forms), [SurveyMonkey](https://faldaro.com/alternatives/surveymonkey), [Formstack](https://faldaro.com/alternatives/formstack), [Fillout](https://faldaro.com/alternatives/fillout), [Anvil](https://faldaro.com/alternatives/anvil), [Cognito Forms](https://faldaro.com/alternatives/cognito-forms), [Tally](https://faldaro.com/alternatives/tally), [Pipefy](https://faldaro.com/alternatives/pipefy), [DocuSign PowerForms](https://faldaro.com/alternatives/docusign-powerforms) and [Formstack Documents](https://faldaro.com/alternatives/formstack-documents).
### Fair questions
**Is Faldaro an alternative to Tally or Typeform?**
For a survey, a poll or a waitlist — honestly, not the best one. Those tools are excellent at collecting answers quickly and Faldaro will not out-simple them. Faldaro is the alternative when the form starts a process: a claim to adjudicate, a ticket to route, an application to score, a registration to charge. If your responses end up in a spreadsheet that someone then works through, that spreadsheet is the part Faldaro replaces.
**Jotform has approvals, PDFs and payments too. What is actually different?**
Where the truth lives. In Faldaro, calculations run on the server so a browser cannot fabricate a total; payment amounts are priced server-side from the answers, never sent by the page; published versions are immutable and every submission keeps the definition it was filled against; and the audit log is append-only because the database refuses changes to it. Those are properties of the architecture, not features on a list — and they are what an auditor, a regulator or a dispute actually turns on.
**We already have forms elsewhere. How hard is moving?**
Forms rebuild quickly: upload the PDF and the agent turns it into a working, editable draft, or describe the form and it builds one. Your response history comes too — export it as CSV and import it: columns map to your fields by header, reference numbers survive the trip, workflow states come across, and every imported record is marked as imported in the audit log. History arrives as records, not attachments — and none of it replays: no notifications, no integrations, no freshly minted numbers.
**We would be replacing more than a form tool — e-sign, payments, the tracking sheet. Is that the idea?**
Yes, and it is the honest way to weigh the price. The loop a submission travels — collected, calculated, routed, approved, signed, paid, documented, delivered — is one record here, so the form tool, the e-sign requests, the payment page, the tracking spreadsheet and the automation glue between them are exactly what consolidates. Keep the tools that do work no form ever starts: general contract signing with no submission behind it, accounting, your CRM. The test is simple — if the work begins with something submitted, it belongs on the record.
**Our process involves outside partners — brokers, franchisees, client firms. Can they work in it?**
Yes, as organizations of their own rather than seats on your account. Share a form or a whole folder with a partner organization: they see exactly what you shared and submit through it if you allow that, their submissions stay theirs, and only you can change the form — the database blocks cross-organization edits outright. Privileges inherit down your own organization tree, never up or sideways, so subsidiaries and chapters run the same way.
**Why not Airtable, Quickbase or a work-management platform?**
Those are strong tools for work that stays inside your company — and they price accordingly: per person who touches the system, with the public form as an afterthought. Faldaro is built the other way round: the public form is the front door, hardened for strangers — tokenized links, throttles, captcha, payments — and the people filling it are never seats you pay for. If your process starts with the outside world submitting something, that inversion is the whole difference; if everyone involved is an employee in a shared grid, they may fit better.
**Is Faldaro overkill for a simple contact form?**
No — the free plan has unlimited forms and ten thousand submissions a month, and a simple form is just a form. The difference only shows up when you need what surrounds it. Plenty of teams start with a contact form and discover the workflow, documents and payments when the process arrives.
**When should we not use Faldaro?**
When the form is the whole job and speed is everything, a lightweight builder is genuinely the better tool. And when your process needs deeply bespoke software — a custom underwriting engine, say — Faldaro is the intake and routing in front of it, not a replacement for building it.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Security: tenant isolation & append-only audit
Source: https://faldaro.com/security
Security you can verify in the design: tenant isolation enforced by PostgreSQL row-level security, an append-only audit log and server-side evaluation.
## Security you can verify in the design
This page makes no claims a badge could carry. It describes how Faldaro is built — mechanisms you can check in the product's behaviour, not adjectives.
### Tenant isolation, enforced by the database
Every tenant-scoped table carries row-level security policies in PostgreSQL, matched against the organization bound from your verified token. The application cannot forget to filter — the database does it, and a query that loses its tenant context returns nothing rather than everything.
### An append-only audit log
The audit table accepts inserts and refuses updates and deletes at the database-permission level. What happened is what the log says happened; there is no code path that can quietly rewrite history.
### Versions are immutable once published
Publishing a form, dataset or template creates a new version and freezes the old one. A submission keeps the exact definition it was filled against — change your pricing tomorrow and yesterday’s records still mean what they meant.
### The server owns every derived value
Submitted data and computed data are stored separately, and the engine recomputes on every write. A tampered request cannot fabricate a total, skip a validation or set its own payment amount — the server’s answer is the only one recorded.
### Formulas and templates cannot run code
Form logic runs on a closed expression evaluator — a fixed set of operators and functions, no script engine. Document templates are structured data with every merged value escaped. Author-supplied patterns and templates run under hard resource budgets.
### The public surface is opt-in and tokenized
A form is reachable anonymously only when you publish a link for it. Links carry unguessable tokens, revoke by rotation, and answer every refusal identically — a withdrawn link is indistinguishable from one that never existed. Formulas and workflow are never exposed.
Access control
### Privileges flow down, never up
Roles grant privileges on an organization and its descendants — a parent administrator can run the whole subtree, and nothing flows upward or sideways. You cannot grant a privilege you do not hold, which is what stops anyone minting a role above their own access.
Sign-in
### Passkeys, Google, or email and password
Accounts support passkeys for phishing-resistant sign-in alongside Google and password authentication. Sessions are refresh-token based and organization switches re-check membership on every reissue.
Questions about how something specific is handled? Ask us at [sales@faldaro.com](mailto:sales@faldaro.com) and we will answer in the same register as this page: with the mechanism. Running an enterprise evaluation? [The Enterprise page](https://faldaro.com/enterprise) describes the plan and the buying process.
### Built so the safe thing is the default
Start on the Free plan and check every claim on this page against the product itself.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Enterprise intake: SSO, org trees, custom plans
Source: https://faldaro.com/enterprise
For organizations beyond Business limits: OIDC single sign-on, custom plans, annual invoicing and security reviews answered directly — priced by conversation.
## Built to fit, priced by conversation
Enterprise is the same platform on a plan shaped to your organization. This page describes only what Enterprise customers get today — no badge-shaped claims, no line an evaluation could not verify.
[Email sales](mailto:sales@faldaro.com) [See all plans](https://faldaro.com/pricing)
Who it's for
### Three reasons this conversation starts
Enterprise exists for organizations the published grid cannot describe — by size, by shape, or by the review that precedes the purchase.
#### Organizations beyond the Business plan
Seats, storage or audit history past what the published plans carry. An Enterprise plan is configured for your organization rather than picked off a grid.
- [Organizations made of organizations Programs, agencies, branches or partners as child organizations under one tree — with sharing across organizations and privileges that flow down the tree, never up.](https://faldaro.com/use-cases/insurance)
- [Buyers who review before they buy If your procurement runs a security review, this is the tier where it is answered directly — in writing, with the mechanism.](https://faldaro.com/security)
The offer
### What Enterprise adds over Business
The pricing page carries the summary; this is what each line means in practice.
#### Everything in Business
The whole platform: the builder and logic engine, workflows, documents and e-signatures, payments, integrations and webhooks, AI agents and the MCP server, email-to-form, child organizations and cross-org sharing.
- [Single sign-on with your identity provider OIDC against the provider you already operate, configured with you during onboarding. Sessions your provider opens are scoped to your organization and its descendants.](https://faldaro.com/docs/sso)
#### Custom limits, seats and plans
Your plan is configured directly — seats, storage, email and AI allowances, audit retention set to your policy. And as on every plan, submissions are never metered or capped: the people filling your forms are never the number you buy.
#### Annual invoicing
Priced in conversation, agreed in writing, invoiced annually. No card form.
#### Priority support and onboarding help
A direct line to the people who built the platform, and help shaping your folders, forms and workflows when you arrive.
- [Security reviews answered directly Send the questionnaire. Answers come back in writing, in the same register as the security page: the mechanism, not an adjective.](https://faldaro.com/security)
Architecture
### The security case is already public
Nothing on this page is claimed for Enterprise alone — the mechanisms below hold on every plan, are stated publicly, and are what your security review's answers will cite.
- [Tenant isolation, enforced by the database Row-level security in PostgreSQL, matched against the organization on your verified token. A query that loses tenant context returns nothing rather than everything.](https://faldaro.com/security)
- [An append-only audit log The audit table refuses updates and deletes at the database-permission level, and every change a person can trigger writes an entry.](https://faldaro.com/docs/admin)
- [Retention on a schedule, provable in the log Set a form’s retention and its records are deleted on schedule — and every deletion writes an audit entry, so deletion-on-schedule is a checkable claim, not a policy statement.](https://faldaro.com/docs/retention)
- [Every claim on this site is checkable The mechanisms behind the platform — server-owned computation, immutable versions, closed evaluators — are stated publicly so you can verify them in the product’s behaviour.](https://faldaro.com/why-faldaro)
Single sign-on
### Your identity provider opens the door
Single sign-on is the Enterprise capability, and it is deliberately conservative: deny-by-default configuration, sessions bounded to your own tree, and membership that stays invitation-governed.
- [Your identity provider, by OIDC Sign-in runs against the provider you already operate. Your side lives in your settings; Faldaro’s side — a deny-by-default allow-list of identity-provider hosts — is configured for you during onboarding.](https://faldaro.com/docs/sso)
#### Sessions scoped to your organization
A session your provider opens reaches your organization and its descendants, and nothing sideways — another organization’s provider can never open yours.
#### Membership stays yours to grant
Signing in through your provider never creates an account by itself. People join by invitation, so your member list is a decision, not a side effect of your directory.
How buying works
### Priced by conversation, in practice
No card form and no quote widget — a short, honest process that ends in a plan configured for you.
#### 1 Write to us
Email sales@faldaro.com with what you run and roughly who is involved — the process, the entities, the identity provider if there is one.
#### 2 A conversation, not a card form
We talk through limits, seats and entities and recommend honestly — including a smaller plan, or a different tool, when that is the right answer.
#### 3 Your security review, answered
Send the questionnaire whenever you are ready. Written answers, each naming the mechanism.
#### 4 A plan shaped to you
Your plan is configured, single sign-on is set up with your identity provider, and an annual invoice closes it out.
The first step is just an email: [sales@faldaro.com](mailto:sales@faldaro.com). We reply in the same register as this page.
Questions
### Enterprise, plainly
What the conversation usually covers, answered before it starts.
**How is Enterprise priced?**
By conversation, after we understand your scope — seats, entities, storage and history. The agreement is annual and invoiced; there is no self-serve Enterprise checkout.
**Can we start on Business and move up later?**
Yes. Plans change in place — your folders, forms, submissions and history stay exactly where they are. Many Enterprise conversations start as a Business organization reaching its limits.
**What does “custom limits” actually mean?**
Your plan’s seats and allowances are configured for your organization rather than picked from the published grid. One thing never changes: submissions are never metered or capped on any plan, so the people filling your forms are never the number you buy.
**How does single sign-on onboarding work?**
You tell us your identity provider; we allow its host on our side and hand you the callback URL to register with it. You finish in your settings with your provider’s details, and from then on sign-in runs through your provider, scoped to your organization.
**What do we get for our security review?**
Written answers, directly from the people who built the platform, in the same register as our security page: the mechanism rather than the adjective. The architecture — database-enforced tenant isolation, an append-only audit log, server-owned computation — is public and checkable before you ever send a questionnaire.
### Start the conversation
Tell us what you run and who is involved — we will answer with mechanisms, a recommendation, and a plan shaped to fit.
[Email sales](mailto:sales@faldaro.com) [See all plans](https://faldaro.com/pricing)
---
# Pricing: free plan, submitters never seats
Source: https://faldaro.com/pricing
You pay for your team, never your audience: submitters are not seats and submissions are never capped. Start free with no card; paid plans from $29 a month.
## You pay for your team, never your audience
The people filling your forms are not seats, and submissions are never capped or billed by count — on any plan, ever. Every plan includes the form builder, logic engine, workflows and public links; higher plans raise the limits and add integrations, multi-entity sharing and longer audit history. Start free, with no card.
### Free
$0 forever
Build a form, share it, collect real answers.
- Users: 1
- Forms: Unlimited
- Submissions: 10,000 / month
- Storage: 250 MB
- Emails: 100 / month
- AI credits: 100 / month
- Max upload: 5 MB
- Form builder & logic
- Public links
- PDF documents
- Email notifications
- Collect payments (3% platform fee)
Not included
- Removing the Faldaro line — public pages say “Powered by Faldaro”, emails “Sent via Faldaro”
- Report export
- Integrations
- MCP server
- Email-to-form
- E-signature requests
- Audit log
[Get started](https://faldaro.app/auth/signup)
### Starter
$29 per month
$290 / year — two months free
For a small team running real work through Faldaro.
- Users: 3
- Forms: Unlimited
- Submissions: Unlimited
- Storage: 10 GB
- Emails: 1,000 / month
- AI credits: 300 / month
- Max upload: 25 MB
- Everything in Free
- Extra seats — $15 / seat / month (up to 7)
- Your branding only — no Faldaro line
- Payments with no platform fee
- Report CSV export
- Digital product delivery
- Reference numbers
- Audit history (30 days visible)
Not included
- Integrations
- AI agents
- MCP server
- Email-to-form
- E-signature requests
- Form test cases
[Start with Starter](https://faldaro.app/auth/signup)
Most popular
### Team
$199 per month
$1,990 / year — two months free
Integrations, AI agents and regression tests for a growing operation.
- Users: 10
- Forms: Unlimited
- Submissions: Unlimited
- Storage: 100 GB
- Emails: 10,000 / month
- AI credits: 1,200 / month
- Max upload: 25 MB
- Everything in Starter
- Extra seats — $15 / seat / month (up to 15)
- AI agents — jobs that run on your forms
- MCP server — connect Claude to your account
- Email a form — forward a message to its own address and it becomes a submission
- E-signature requests — signing links with an evidence trail and certificate
- Zapier integrations
- Outbound webhooks
- Form test cases
- Audit history (1 year visible)
Not included
- Child organizations
- Cross-organization sharing
[Start with Team](https://faldaro.app/auth/signup)
### Business
$599 per month
$5,990 / year — two months free
Child organizations and cross-organization sharing for multi-entity groups.
- Users: 25
- Forms: Unlimited
- Submissions: Unlimited
- Storage: 500 GB
- Emails: 25,000 / month
- AI credits: 3,500 / month
- Max upload: 100 MB
- Everything in Team
- Child organizations
- Cross-organization sharing
- Audit history (3 years visible)
[Start with Business](https://faldaro.app/auth/signup)
### Enterprise
For organizations beyond Business limits, or with requirements of their own. Custom plans are built to fit — priced by conversation, not a card form.
- Everything in Business
- Single sign-on with your identity provider (OIDC)
- Custom limits, seats and plans
- Annual invoicing
- Priority support and onboarding help
- Security reviews answered directly
[About Enterprise](https://faldaro.com/enterprise)
Questions
### Pricing, plainly
What the numbers above mean in practice — allowances, overage and leaving.
**What is an AI credit?**
One unit of assistant, AI-builder or agent work. Translating a form into a language costs about four, as does analyzing a form’s submissions into an insight report; filling a form from a document costs about five, as does turning a typical page into a template — a dense multi-page reproduction spends more, at what it measurably cost; generating a whole form from a description costs about fifty; an AI agent run spends credits as it works. Training a predictive model costs no credits at all — credits meter model reasoning, not compute. Credits reset monthly.
**What happens if I go over a monthly allowance?**
Submissions never stop — imported history included — and there is no automatic overage charge, ever. Storage and email degrade gently instead of billing you: when storage is full, new uploads pause until you free space or upgrade, and emails over the monthly allowance wait in the queue — never lost — until the month rolls over. AI credits stop at the allowance — unless you have bought a prepaid credit pack, which is drawn only after the allowance is used. Nothing is ever charged automatically.
**Can I buy more AI credits?**
Yes — on any paid plan, as prepaid packs: $10 for 300 credits, $30 for 1,000. A pack is a one-time purchase, never a subscription and never overage: you choose to buy it, it never renews, and unused pack credits never expire. Packs are drawn only after your monthly allowance is used, and one balance is shared across your whole billed group of organizations.
**How generous is the Free plan really?**
Unlimited forms, yes — a form is just a definition, so we do not count them on any plan. Free includes 10,000 submissions a month, which is more than an evaluating team will use, and it is bounded by the things that genuinely cost us money: one user, 250 MB of file storage and 100 emails a month. What you upgrade for is removing our branding and the 3% payment fee, plus integrations, exports and audit history — not permission to keep collecting.
**What is the 3% on the Free plan?**
If you collect money through a Faldaro form on the Free plan, we keep 3% of it. Collect nothing and you pay nothing — that is how Free pays for itself instead of charging you a subscription. Every paid plan is 0%, so once you are taking more than about $1,000 a month you are better off on Starter.
**Is the API included on every plan?**
Yes. API keys, the versioned /v1 endpoints and the app’s own API are on every plan, Free included — machine access is not a paywall here. What Team adds is the MCP server: the model-ready toolbox that lets Claude and other AI clients operate your account as tool calls. MCP itself never consumes AI credits, because the model doing the thinking is yours; the only exception is a tool that asks Faldaro’s own AI to do something — generating a form, running an insight analysis — which spends the same credits it spends from the app or the raw API.
**Do I need a card to start?**
No. The Free plan is free forever, needs no card, and includes the same form builder, logic engine and workflows as every paid plan.
**Can I cancel at any time?**
Yes. Cancelling stops renewal at the end of the current billing period and nothing is deleted — your forms and submissions stay exactly where they are.
### Try the Free plan today
Build a form, share a link and collect real submissions in the next ten minutes — upgrade only when the work outgrows the limits.
[Start free](https://faldaro.app/auth/signup) [Explore features](https://faldaro.com/features)
No card required.
---
# About Faldaro — the intake platform
Source: https://faldaro.com/company
What Faldaro is, what it believes and where it came from: the intake platform for work that arrives from outside, built on claims you can check.
About
## Where the outside world’s paperwork becomes your decisions
Faldaro is the intake platform. Everything an organization receives from outside itself — claims, applications, requests, registrations, orders — arrives through a public link and becomes a record, worked to a decision by the organization’s own rules, its people and its AI agents.
### What we build
A front door built for strangers, and a system of record behind it.
Form tools collect answers. Work-management tools are built for employees and price every participant as a seat. Faldaro is built the other way round: the public form is the front door, hardened for people who have no account and never will, and what walks through it is worked rather than exported — priced, routed, approved, signed, paid and documented on one record with an audit trail already started.
Nothing in the platform is specific to an industry. Folders group forms, forms produce submissions, and workflows carry them, so an insurer configures Policies and Claims, a program office configures Applications, and a support desk configures Tickets — each in a morning, none waiting on a developer.
### What we believe
Four principles, each visible in the product rather than asserted about it.
#### The outside world is never a seat
The people who send you work — submitters, brokers, approvers, signers — are not licences. Pricing counts your team and never your audience, and that promise is enforced in code rather than in copy.
#### The server owns the truth
Every number is computed where the submitter cannot reach it. Published versions are immutable, and the audit log is append-only because the database refuses to rewrite it. What arrives can never quietly become what you decided.
#### AI works with a badge, not a master key
The assistant, the standing agents and the MCP server hold exactly the permissions of the person or key behind them. They have no delete tools and no credentials of their own. What a stranger typed arrives marked as data: the assistant cannot change anything in a turn that has read it, the agents work inside fences of their own, and over MCP the marking reaches your client’s own model intact.
#### Claims you can check
Every claim on this site names a mechanism that can be verified in behaviour. Named competitors get credit for what they are good at, and nothing here describes what the product does not do.
### Where it came from
Faldaro grew out of years spent building and running insurance intake systems, where one lesson kept repeating: the moment a form’s total is computed in the browser, someone eventually sends a different one. Everything downstream — the approval, the payment, the letter — then rests on a number nobody can vouch for.
The platform was rebuilt from that lesson as a general intake platform: the server owns every derived value, every published version is immutable, formulas run in a closed evaluator rather than a code interpreter, and tenant isolation is enforced by the database rather than by the application promising to behave. Insurance remains the purest example of the work it is for, and the vocabulary still runs through the demos.
### How we work with customers
Three ways in, and the same platform behind each.
- [Self-serve, from a free plan that stays free Unlimited forms, ten thousand submissions a month and the same engine as every paid plan, with no card. The first session ends with your own process taking real submissions.](https://faldaro.com/pricing)
- [Enterprise, by conversation Organizations beyond the published plans — programs, agencies, branches and partners under one tree — are configured rather than picked off a grid, with single sign-on and security reviews answered directly.](https://faldaro.com/enterprise)
- [Reviewed before it is trusted Security questionnaires are answered in writing, mechanism by mechanism. Vulnerability reports are acknowledged within two working days. The trust centre says how your data is handled.](https://faldaro.com/trust)
### Contact
Three addresses, each read by a person.
- [Sales Plans, Enterprise and partnerships. sales@faldaro.com](mailto:sales@faldaro.com)
- [Support Help with your account and your forms. support@faldaro.com](mailto:support@faldaro.com)
- [Security Responsible disclosure. security@faldaro.com](mailto:security@faldaro.com)
### See the platform for yourself
Describe what arrives — or upload the PDF you use today — and open a door in the same sitting. Free forever, no card.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Trust centre
Source: https://faldaro.com/trust
How Faldaro handles your data, as mechanisms: tenant isolation in PostgreSQL, append-only audit, provable retention, the AI data path and subprocessors.
## Trust centre
How Faldaro handles your data, stated as mechanisms you can verify — never as adjectives. Each item names a behaviour, and most link to the page that spells it out. All traffic to faldaro.app and faldaro.com is served over TLS.
Isolation and access
### Who can reach what
- [Tenant isolation enforced by the database Row-level security policies in PostgreSQL match every query against the organization bound from a verified token. The application connects as a non-superuser and refuses to start if the policies would not apply. A query that loses its tenant context returns nothing, never everything.](https://faldaro.com/security)
- [Privileges from one place Privileges are seeded once and served by the API. A role granted on an organization applies down its tree and never up or sideways, and nobody can grant a privilege they do not hold.](https://faldaro.com/docs/admin)
- [Single sign-on, passkeys and rotated sessions OIDC against your own identity provider on Enterprise, with sessions scoped to your organization and its descendants. Passkeys and Google sign-in on every plan. Refresh tokens are rotated on every use.](https://faldaro.com/docs/sso)
- [Machine access with explicit grants An API key carries a stated set of privileges and nothing more. The MCP server forwards your key verbatim to the same authorization stack every request passes through, and judges no credential itself.](https://faldaro.com/docs/api-keys)
Integrity
### What cannot be quietly changed
- [Immutable published versions Publishing a form, dataset or template creates a version that never changes. Every submission keeps the exact definition it was filled against, for as long as it exists.](https://faldaro.com/docs/concepts)
- [An append-only audit log Update and delete are revoked from the application role, so the log cannot be rewritten by the application. Every write a person can trigger lands in it under the real actor: a user, an API key, an agent, or the anonymous public surface.](https://faldaro.com/security)
- [Values the server owns Calculated fields are recomputed on the server on every save and every read. Payment amounts are priced from the submitted answers and never accepted from a request. Formulas run in a closed evaluator with an operation budget, never in a code interpreter.](https://faldaro.com/docs/formulas)
- [Budgets on untrusted input Author-supplied patterns, report queries, document renders, uploads and public submissions each run under a bound the server enforces, so no single tenant can pin the service.](https://faldaro.com/security)
Data lifecycle
### How data arrives, leaves and ends
- [Retention you can prove Each form can carry a retention period. Submissions past it are deleted permanently on schedule, and each purge is recorded so you can show what was removed and when.](https://faldaro.com/docs/retention)
- [Export and import Your submissions leave as CSV and come back as records with their reference numbers and workflow states. An import replays nothing: no notifications, no integrations, no freshly minted numbers.](https://faldaro.com/docs/submissions)
- [Public surfaces are opt-in A form is never reachable anonymously because it exists — only because someone with the privilege issued a tokenized link. Links are revoked by rotation, every refusal is an identical not-found, and archiving a form takes its public pages down with it.](https://faldaro.com/docs/public-forms)
- [Outward links carry projections, never data Tracking pages, shared reports, the submitter portal and approval links each serve a curated projection behind a revocable token. Individual records never leave the tenant this way.](https://faldaro.com/docs/records-sharing)
AI
### The AI data path
- [Your permissions, never more The assistant and the standing agents act inside the same authorization boundary as the person or key behind them. They have no delete tools, no administrative tools and no credentials of their own.](https://faldaro.com/docs/ai)
- [Per request, for the action you invoked Content reaches the language-model provider only for the action you asked for, in that request. What someone outside your organization submits — through a public link, by email or over the API — is wrapped as data, never presented as instructions, before a model sees it.](https://faldaro.com/features/ai)
- [Nothing of yours trains a model Faldaro’s language-model features use your content for the request and nothing else. The predictive models built by Form Insights are trained only on your own organization’s records, at your request, and serve only your organization.](https://faldaro.com/docs/ai)
- [Over MCP, the model is yours A connected model calls tools with your API key and no other credential. Faldaro meters no AI credits for the transport, because the model in the loop is the client’s.](https://faldaro.com/docs/mcp)
Where it runs
### Subprocessors
The services the hosted platform relies on, and what each is used for.
| Provider | Purpose |
| --- | --- |
| Google Cloud | Application hosting, the PostgreSQL database and object storage for uploaded files. |
| Hetzner | Web front-end hosting. |
| Anthropic | Language-model features — the assistant, inline AI, agents and insight narration — called per request. |
| Stripe | Payments collected through your forms, and subscription billing. |
| Google | Google sign-in, for people who choose it. |
| Cloudflare | Turnstile captcha on public forms, where the operator enables it. |
| Transactional email provider | Outbound notifications and account mail, as configured for the deployment. |
Integrations you connect yourself — Zapier, Slack, your own webhook endpoints — receive only what the rule or workflow action you authored sends, with every delivery signed.
Disclosure and reviews
### Talking to us about security
- [Report a vulnerability Email security@faldaro.com with a description, the steps to reproduce and what you were able to reach. Expect an acknowledgement within two working days and an assessment within five. Credit in the fix is offered; not being named is the default.](mailto:security@faldaro.com)
- [Security reviews Questionnaires are answered in writing by the team, mechanism by mechanism, in the same register as this page. Write to sales@faldaro.com with what your review requires.](mailto:sales@faldaro.com)
### Bring your security review
Every answer is a mechanism, and every mechanism is checkable in behaviour before you commit anything.
[Email sales](mailto:sales@faldaro.com) [Read the security page](https://faldaro.com/security)
---
# Changelog
Source: https://faldaro.com/changelog
What shipped in Faldaro and when: the records release, approvals by email, e-signatures, email-to-form, predictive insights and the MCP server.
## Changelog
What shipped, dated. Everything here is in the product today and described in the documentation. The engine, workflows, payments and documents that the entries build on shipped through the summer.
### September 2026
1. 22 Sep
#### [Faldaro is the intake platform](https://faldaro.com/why-faldaro)
The site now says what the product is for: work that arrives from outside the organization. The homepage shows a record being worked rather than a form being built, and three new comparison pages cover Formstack, Fillout and Anvil.
2. 20 Sep
#### [Plans repriced](https://faldaro.com/pricing)
Team and Business moved to their new prices; extra seats on Starter and Team were repriced with them. Free and Starter are unchanged, and nothing is ever billed as overage.
3. 17 Sep
#### [Import a PDF on the homepage](https://faldaro.com/)
Drop a PDF or a photo of a form and it comes back as a draft, with no account. Nothing is stored; the document is read once to draft the preview.
4. 16 Sep
#### [Approvals by email](https://faldaro.com/features/records)
A workflow action mails each approver their own approve or decline link. The verdict lands on the record with a name, a comment and a timestamp, and fires the transition you chose.
5. 16 Sep
#### [Community template gallery](https://faldaro.com/templates)
Publish a form as a template and ask for it to be listed. A public link can now offer “clone this design” and show its response count as social proof — both opt-in per link.
6. 15 Sep
#### [The records release](https://faldaro.com/features/records)
Submissions as a table, a board, a calendar or cards. Per-record tracking links, shared report pages and badges, scheduled report digests, @mentions, linked-record fields, publish-as-template and a submitter portal reached by a mailed link.
7. 15 Sep
#### [Hosted MCP server](https://faldaro.com/features/mcp)
Point Claude or any MCP client at your account with an API key. Your model builds forms, files submissions and runs reports with exactly that key’s permissions. A stdio bridge, @faldaro/mcp, ships on npm.
8. 14 Sep
#### [Form insights and predictive models](https://faldaro.com/docs/ai)
Analyze a form’s submissions into a narrated report with executed drill-downs, and train models on your own records to predict workflow outcomes, flag unusual records and explain their drivers.
9. 10 Sep
#### [E-signatures](https://faldaro.com/docs/esignatures)
Request signatures from a workflow: per-signer links, a frozen and fingerprinted document, an evidence trail, and a certificate page appended to the signed PDF.
10. 10 Sep
#### [Email-to-form](https://faldaro.com/docs/inbound-email)
Every form can have its own address. Forward a message and it becomes a submission with attachments attached, the sender verified and the workflow started. Comments and attachments on submissions shipped alongside.
### August 2026
1. Aug
#### [The field library](https://faldaro.com/docs/field-library)
Save reusable groups of fields and insert them into any form. Insertion copies, so published forms stay immutable.
2. Aug
#### [The facsimile document engine](https://faldaro.com/features/documents-payments)
Upload the PDF you already send and its exact layout becomes the document template, filled from the record when its state changes.
3. Aug
#### [Single sign-on, branding and retention](https://faldaro.com/docs/sso)
OIDC single sign-on for Enterprise organizations, organization branding on public pages, and per-form retention schedules with provable purges.
4. Aug
#### [Standing agents and AI credit packs](https://faldaro.com/docs/ai)
Agents that work a form’s submissions on a trigger or a schedule with an explicit privilege grant, metered in credits, with prepaid packs as the one way to buy more.
5. Aug
#### [API keys, Slack and webhooks](https://faldaro.com/docs/integrations)
Machine credentials with a stated privilege set, a versioned evaluate-and-submit API, Slack cards on notifications, and signed webhook deliveries to any allow-listed endpoint.
6. Aug
#### [Plans, payments and refunds](https://faldaro.com/docs/payments)
Self-serve plans with entitlements, Stripe payments priced on the server with split payouts, digital product delivery on settlement, and operator-initiated refunds.
### Start with the version that exists today
Every entry above is live on the free plan or the plan the pricing page names. No card required.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Brand assets
Source: https://faldaro.com/brand
The Faldaro mark and wordmark, the colours, the tagline, and how to use them — with downloadable assets for press and partners.
## Brand
The Faldaro mark, wordmark and colours, with the rules that keep them consistent. Use them to refer to Faldaro; do not alter them. Press and partners are welcome to the files below.
The mark
### A pleat
“Falda” is a pleat. The mark is an accordion fold — three panels of one strip, dimmer where the middle panel turns away from the light — the same strip a record travels along on the homepage.
- [Mark, SVG Any size. Preferred.](https://faldaro.com/favicon.svg)
- [Mark, PNG 512 px For places that cannot take SVG.](https://faldaro.com/icon-512.png)
- [Mark, PNG 192 px Small placements.](https://faldaro.com/icon-192.png)
The wordmark
### Faldaro, set in Space Grotesk
The wordmark is type, not lettering: “Faldaro” in Space Grotesk semibold with tight tracking, usually beside the mark. The tagline may sit under it.
Faldaro Intake, not forms
Faldaro Intake, not forms
Colour
### Wine, dusk and the horizon
One primary, one dark sky and the light along its horizon. The gradient appears on emphasis only — a numeral, a rule, a button — never as a wash.
Wine
#9c4064
The primary. Buttons, links, the mark’s ground.
Dusk
#180b19
The zenith of the dark sky product panes sit on.
Horizon
#e56c80
The light along the dusk horizon; accents on dark.
Brand gradient
#af6aaf → #c76069
The one gradient, from violet to rose, on emphasis only.
Usage
### Six rules
#### Keep the mark whole
Three panels of one strip. Do not recolour, rotate, outline, add effects to, or separate the panels of the mark. On dark grounds use it as supplied; it carries its own ground.
#### Give it room
Clear space around the mark of at least half its width on every side. Never smaller than 16 px on screen.
#### Set the wordmark in its own face
The wordmark is “Faldaro” in Space Grotesk, semibold, tightly tracked. Do not re-set it in another face, and do not spell the name in capitals or lowercase in prose — it is a word, capitalized as one.
#### Pair the tagline, or leave it off
The short tagline is “Intake, not forms.” It may sit under the wordmark or beside it, in the body face. No other line may.
#### Attribution on public pages
Forms on the free plan carry a “Powered by Faldaro” line. That lockup is the only one third parties use; partners describing an integration say “works with Faldaro”.
#### Say what the product is
Faldaro is the intake platform. Describe it that way — not as a form builder, a survey tool or a workflow product — and every claim you make about it should be one this site makes.
### Writing about Faldaro?
Sales answers press and partner questions, and every claim on this site is one you can quote.
[Contact us](https://faldaro.com/contact) [About Faldaro](https://faldaro.com/company)
---
# Contact
Source: https://faldaro.com/contact
Reach Faldaro: sales for plans and Enterprise, support for help with your account, and security for responsible disclosure.
## Contact
Three addresses, each read by a person. Say which one you need and what you would like to happen next.
### Sales
Plans, Enterprise and partnerships.
[sales@faldaro.com](mailto:sales@faldaro.com) Write with what you run and roughly who is involved — the process, the organizations, the identity provider if there is one. Security questionnaires come here too, and are answered in writing.
[Enterprise](https://faldaro.com/enterprise) [Pricing](https://faldaro.com/pricing)
### Support
Help with your account and your forms.
[support@faldaro.com](mailto:support@faldaro.com) Include the organization name and, where it applies, the form or record. The documentation answers most questions the same day; write when it does not.
[Documentation](https://faldaro.com/docs) [Getting started](https://faldaro.com/docs/getting-started)
### Security
Responsible disclosure.
[security@faldaro.com](mailto:security@faldaro.com) A description, the steps to reproduce and what you were able to reach. Acknowledged within two working days, assessed within five. Please do not open a public issue for anything exploitable.
[Trust centre](https://faldaro.com/trust) [Security](https://faldaro.com/security)
### Prefer to see it first?
The free plan is free forever, and the homepage imports a PDF with no account at all.
### Open a door today
Describe what arrives — or upload the PDF you use today — and share a live link in the same sitting.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Form builder with logic and calculations
Source: https://faldaro.com/features/form-builder
Build forms with conditional logic and calculations evaluated on the server — totals a client cannot fabricate, versioned, tested before you publish.
## A form builder with logic that runs on the server
Start from a template — support requests, registrations, applications — or a blank canvas. Build fields, conditions and calculations in the browser; Faldaro evaluates them on the server on every save, which is the difference between a form that displays a total and a form whose total can be trusted.
[Start building free](https://faldaro.app/auth/signup)
Calculations
### Totals a browser cannot fabricate
A claims form multiplies vehicles by rate bands and shows the estimate as the submitter types. When the form is saved, the server runs the same formulas over the submitted values and stores its own result — the client's arithmetic is a preview, never the record.
vehicles 3
rate_band Commercial
estimate = vehicles × band_rate $12,400
Recomputed server-side on every save · client value discarded
Field types
### Over two dozen field types, and the awkward ones included
Signatures drawn on the page and stored with the submission. Addresses with optional Google Places autocomplete. Tables and structured lists for line items. Input masks, computed summary panels, uploads served safely — the fields real processes need, not just text boxes wearing hats.
Text & long text Email · phone · URL Numbers & currency Percentages Dropdowns & combo boxes Radio & checkbox groups Dates, times & ranges Address (Places autocomplete) Signature Tables & lists Contacts Linked records File & image upload Input masks Computed summary panels Headings & layout
#### Conditional logic
Show, hide and require fields from other answers. A hidden field contributes nothing to a calculation — it is removed from the maths, not just the page.
#### Versioned by default
Editing a live form clones a new draft. Publish when ready; every submission keeps the definition it was filled against.
#### Reference numbers
Sequences allocate once, at submission — a record keeps its number through every edit, and two concurrent saves can never draw the same one.
#### Test cases
Pin inputs to expected outputs and re-run them through the real engine before publishing a change. A pricing tweak that moves a pinned value fails loudly, not in production.
#### Public links
Opt a form into anonymous submission with a revocable tokenized link — throttled by default, behind a captcha where the operator has configured one, and without exposing your formulas. Half-filled answers survive on the submitter’s own device, so a closed tab is not a lost submission.
#### Cross-organization sharing
Share a form or folder with a partner organization at view or submit level. They use it; only you can change it.
#### A field library
Save the blocks you keep rebuilding — an address section, a signature block, a standard disclosure — and insert them into any form. Inserting copies the fields (references rewritten, collisions renamed), so editing the group later never changes a form it was already placed in.
#### AI-styled fields
Describe a look — “dark, rounded, ticket-stub feel” — and the AI styles the field on the canvas for you to keep or tune. Styled fields saved to the library become reusable styles you can copy onto any field, and every style passes the same validation fence as your own CSS.
#### A canvas that cannot drift
The builder previews every field with the same component a submitter sees — dataset options, input masks, date pickers and all — so what you arrange is what they get, by construction rather than by imitation.
Questions
### Form builder, plainly
**Where does form logic run?**
On the server. The browser shows a live preview, but every calculation, visibility rule and validation is re-evaluated server-side on save — so a tampered request cannot fabricate a total or skip a required field.
**Can I change a live form without breaking old submissions?**
Yes. Editing a published form creates a new draft version; existing submissions keep the exact definition they were filled against, forever. Publishing the draft affects only what happens next.
**How do I know a change won’t break my pricing?**
Form test cases pin named inputs to expected outputs and re-run through the real engine. Run them against a draft before publishing and you know whether the change moves any value someone has pinned down.
**Can people outside my organization fill a form?**
Only if you publish a public link for it. Links carry an unguessable token rather than the form’s id, can be revoked by rotating them, and never expose your formulas or workflow to the person filling the form.
### Build your first form in minutes
Unlimited forms, public links and the full logic engine are free forever — no card, no trial clock.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Workflow automation for form submissions
Source: https://faldaro.com/features/workflows
Form workflow automation, drawn as a diagram: states and moves from draft to done that notify people, generate documents and request e-signatures.
## Workflows that carry a submission from draft to done
Draw the states your work moves through and who may move it. Each transition can notify people, generate documents, call your systems and create related records — and every record shows where it is, what can happen next, and why the rest cannot.
[Start free](https://faldaro.app/auth/signup)
Draft In review Approved Each arrow is privilege-gated, notified and audited
The builder
### Drawn, not listed
A workflow is a picture of where a record can go. The builder shows it as one — and says, under the picture, what would stop it working before the server has to.
#### A picture, not a list
States are boxes laid out by how many moves it takes to reach them; moves are arrows carrying their button text. Select either and the rail beside the picture edits it.
#### Four quick starts
Review and approve, Ticket, Application, To do — complete workflows you rename, not blank pages. Type a state’s name and its id is derived; nothing to misspell.
#### Guards on the arrow
Who may take a move, the condition it needs, the fields that must be filled first — each edited with pickers and marked on the arrow with a lock, a funnel or a checklist.
#### Actions on the state
What happens on entering and leaving, with the control each kind deserves: a field and a value or formula, a person by name, a template by name, recipients as chips.
#### Checked before you publish
Dead ends, states nothing leads to, two identical buttons, a deadline with nowhere to go — listed under the picture in plain words, one click from the spot.
#### A colour per state
Six colours, chosen once, shown everywhere the state appears: the diagram, the record’s title, the submissions table and the counted state filters above it. Rejected reads as red before anyone reads the word.
Effects
### What a transition can do
Moving a record is rarely the whole job. Attach effects to a state and the rest happens with the move — reliably ordered, never able to undo the move that triggered them.
#### Send a notification
Templated email to the assignee, the owner, the creator, any email field on the form or a list field of addresses — ticked, not typed.
#### Generate a document
A PDF from your template, merged with the submission’s values.
#### Request a signature
Each signer gets their own link to a frozen, fingerprinted document; the signed copy carries a certificate, and a later move can require everyone to have signed.
#### Call a webhook
Notify your own systems — restricted to hosts an operator has allow-listed.
#### Send to Zapier
Hand the submission to thousands of other tools without writing an integration.
#### Create a linked submission
Spawn a related record in another form, with the relationship kept.
#### Assign and set fields
Route the work to a person — it appears in their My Work queue, one list of everything assigned to them across every form — and stamp values the next step depends on.
Default deny
### Safe is the default, not an option
A transition that names no required privilege still requires one — the platform's default. The easiest thing a workflow author can do is also the safe thing, which is exactly how permission systems should be built.
On the record
### Where it is, and why the rest is withheld
A record shows its state in the author's colour, a strip of every state with the current one lit, and the moves the reader may take as buttons. Moves that exist but were withheld are listed with the reason — the privilege, the fields to complete, or that the condition does not hold — without ever showing the condition. A move into a final state asks first, because nothing moves out of one afterwards.
Deadlines
### States carry a clock, and the clock takes the transition
Give Review a 48-hour deadline firing Escalate, and a record that stalls stops being invisible: the platform takes the transition a person would have clicked — same conditions, same notifications, same generated documents — and the audit entry says the deadline did it. The one check it does not make is the caller's privilege, because a deadline has no caller: authorization happened when someone with form:write published that one named transition. Chained deadlines compose: escalation can arm the next state's clock.
Honest by construction
### Attempted once, and written down either way
A deadline fires once per stay in a state. If its transition's own condition refuses — the record changed under it — the refusal is recorded in the audit log rather than retried forever, and a person moving the record first simply disarms the clock. Deadlines apply to records created after you publish them; existing records keep the definition they were filled against.
Audited
### Every move leaves a record
Who moved what, when, from which state to which — appended to an audit log that neither users nor the application can rewrite. When a decision is questioned months later, the trail is simply there.
Questions
### Workflows, plainly
**Who can move a submission between states?**
Only someone holding the privilege the transition requires. A transition that names no privilege still requires the default transition privilege — leaving the field out is the safe choice, not an open door.
**Why is a button missing from a record?**
The record says. Moves that exist from its state but were withheld are listed under the state strip with the reason — the privilege needed, the fields to complete first, or that the move’s condition does not hold. The condition itself is never shown, so a record is not an oracle for the rule behind it.
**What happens if an effect fails — say, the mail server is down?**
The move stands and the failed effect is logged and retried where it can be. Effects that leave the platform run after the transition commits, so an unreachable webhook can never announce a move that then rolled back.
**Can a workflow create other records?**
Yes. A transition can create a linked submission in another form — a claim spawning a payout request, a ticket spawning a task — and the link between them is kept.
**Can a transition depend on payment?**
Yes. Payment status is recorded on the submission, so a transition can require payment to have succeeded before it can be taken.
**Can a workflow collect an e-signature?**
Yes. A “Request a signature” action emails each signer their own link to review and sign a frozen copy of the document, records the evidence — who, when, from where, over which exact bytes — and appends a certificate page to the signed PDF. A later transition can require everyone asked to have signed.
### Model your process, not a compromise
States, transitions and effects are configuration — draw them in the browser and change them as your process changes.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Submission tracking with status links
Source: https://faldaro.com/features/records
Everything a submission becomes after it lands: a board you drag, a status link submitters track, shared reports and digests, @mentions and a submitter portal.
Records
## The form is the doorway. The record is the point.
Everything a submission becomes after it lands: a card on a board, a status a submitter can track, a number on a shared chart, a conversation with your team, a reference another record points at. This is what “all the things you can do with data records” looks like in practice.
[Try it free](https://faldaro.app/auth/signup)
### One pipeline, four views
The same records as a table, a board, a calendar, or cards. The board’s columns are your workflow’s own states; dragging a card takes the exact move the record page offers, with every server-side guard intact — and a drop the rules withhold says why, right in the column.
### A tracking link for every record
“Track your request” — a per-record status page showing the stage, reference number and last update, and nothing else. Put {{status_link}} in a confirmation email and every submitter gets the package-tracking experience for whatever they filed.
### Reports that travel
Share a grouped report as a live read-only page, embed its chart in any site, or schedule it as a daily or weekly email digest to people who never log in. Aggregates only — individual records never leave this way.
### @mentions that reach people
Type @ in a record’s comments to bring a colleague in: they get the comment by email with a link to the record, and a “Mentioned you” card on their dashboard. Server-checked against membership, capped, and audited like every other write.
### Records that reference records
A linked-record field holds a reference to a record of another form — orders to customers, inspections to assets. Every link is validated on write: it must exist, be live, and belong to exactly the form the field declares.
### A portal for the people who filled it in
Submitters track all their records in one place with nothing but their email — a magic link, mailed to the address itself, listing each record’s live status. You choose which field identifies them; everything else stays yours.
### Forms you can hand to the world
Publish any form’s design as a cloneable template page. Fields, logic and workflow travel; your data, datasets and integrations never do. Anyone who opens the link can make it theirs in one click.
### Slack cards, not log lines
The Slack integration posts a proper card per event — the record’s name, stage and leading fields, with an “Open record” button back into Faldaro — so a shared channel becomes a live feed of the pipeline.
### Approvals decided from an inbox
A workflow action mails each approver their own approve/decline link — no account, no login. You choose which move each verdict takes and exactly which fields they see; the decision lands on the record with a name, a comment and a timestamp.
### A live badge for your README
Any shared count-or-sum report serves a one-number SVG badge off the same link — paste the markdown into a README, a wiki, a docs page, and the number updates with the report.
### Every share lands harder
Pasted links unfurl as real preview cards (a form’s name, a template’s shape — never a record’s contents), every share dialog offers a printable QR code, a public form can show its response count as social proof, and good templates can be listed — after review — in the community gallery.
Built on the same rules
### Public means curated, never exposed
Every outward-facing link here follows the discipline the public form already lives by.
Every shared URL is a 256-bit token — unguessable, revocable by rotating it, and the whole of the link’s authority. Every payload is a curated projection: a status page carries a stage and a timestamp, never answers; a shared report carries aggregates, never rows; a template carries a design, never data. And every refusal looks identical, so probing a link tells you nothing about whether it ever existed.
Questions
### Fair questions, straight answers
**What exactly does a status link show?**
The record’s current stage in your workflow — the label and colour you gave it — its reference number, and when it last moved. Never the answers, never who is working on it, never the rules behind it. You mint the link per record, and revoking it is one click: the old URL stops working everywhere at once.
**Can a shared report leak individual submissions?**
No. Only grouped reports — counts, sums, averages per category — can be shared or mailed as a digest. A report that lists individual records is refused at sharing time, and if a shared report is later edited into a listing, its public link goes dark rather than serving rows.
**Who can be @mentioned?**
Members of your organization. Every mention is checked server-side against membership before anything is stored or sent — an id that merely exists proves nothing about whose it is. The mentioned person gets an email with the comment and a link to the record, and a “Mentioned you” card on their dashboard.
**How does the submitter portal identify people?**
By the one email field you choose, and only that field. A visitor types their address on the public form page; if any submissions match, a secure link is mailed to that address — possession of the mailbox is the credential. An address that merely appears somewhere inside a record never unlocks it, and the page answers identically whether anything matched.
**What travels with a shared template?**
The design: fields, calculations, show/hide rules, outcomes, and the workflow’s states and moves. Nothing org-local ever leaves — no dataset bindings, no notification templates, no integrations, no records. It is sanitized when you publish, not when someone reads it, so the published copy never held anything private to begin with.
**What can an approval link actually do?**
Exactly what its author delegated: take the one workflow move named for an approval, optionally another for a decline, and nothing else. The page shows only the fields the author chose, every data-dependent guard still applies at decision time, and a link opened after the record moved on records the verdict without moving anything. The decision — who, when, from where, with what comment — lands on the record’s Approvals tab.
**Which plans include all this?**
All of it ships on every plan, the Free plan included — sharing a board screenshot, a status link, an approval, a report page or a template must never hit a paywall. Paid plans remove the “Powered by Faldaro” line from public pages and notification emails; the features themselves are not what’s sold.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# AI form builder and agent
Source: https://faldaro.com/features/ai
An agentic AI assistant inside the intake platform: it builds forms, imports PDFs as fillable forms, translates them, and acts with exactly your permissions.
Agentic AI
## An AI agent woven through the whole platform
Not a chatbot bolted on the side: an agent that plans multi-step work and carries it out — building forms, wiring logic, filing and finding submissions, navigating you to the result — inside the same product you use, with your permissions, showing every step it takes.
[Try it free](https://faldaro.app/auth/signup)
Assistant acting as you
Turn this PDF into our claims intake form.
- Read claim-intake.pdf
- Drafted 12 fields and 3 rules
- Wired estimate = vehicles × band_rate
- Opened the builder for your review
Draft ready — nothing is saved until you publish.
scope: your permissions no delete tools
### An agent in the app, not a chatbox
Ask for an outcome — “set up an intake form for equipment loans, with an approval step” — and the agent plans the steps, builds the draft, wires the logic and navigates you to the result. Every tool call it makes is visible in the conversation, so you watch the work happen rather than take its word for it. On a wide screen the panel docks beside the page, so what it is changing stays in view; it opens with three suggestions about the page you are on, and a file dropped anywhere on it is attached.
### Import a PDF as a fillable form
Attach the paper form you use today; the agent reads it and produces a working, editable Faldaro draft — fields, types and structure — rather than a picture of one.
### Prefill from a document
Upload a report, invoice or ID against a form and the matching fields fill themselves for your review. Only fields the form actually has; only values you approve.
### Turn your paperwork into templates
Hand the document template editor the letter or certificate you send today and it comes back as a template — layout mirrored, logos extracted and placed, every fill-in area already a merge field for the form you picked. When it must match the original exactly, reproduce the PDF page for page instead and let one prompt bind your fields onto it. The notification editor does the same for email, subject line included. Or skip the upload and just describe the template you need.
### Plain English to a filter
“Unpaid claims from July over $5,000” compiles into the exact filter — field keys, operators and workflow states all checked against the form before anything runs.
### Translate a form for its submitters
Pick a language and the whole public form comes back translated — labels, help text, choices, the submit button — into the builder for you to read before you save. It fills gaps only: anything you worded yourself is never sent to the model and never overwritten, so running it again after you add a field translates the new strings and leaves your wording alone.
### Style a field from a description
Tell the builder how a field should look and the model proposes the styling — theme colours, radius, scoped CSS — straight onto the canvas, validated by the same fence as hand-written styles, applied only when you save.
### Reports and dashboard reads
Describe the report you need and refine the result in the report builder it seeds; ask the dashboard what changed this week and get an answer grounded in your own data.
### Insight reports on any form
One click — or a weekly schedule — analyzes a form’s submissions: trends, outliers, correlations, where work sits too long in the workflow. The statistics are computed by the server and the AI narrates them into ranked, actionable findings — and every count on a finding is the result of a real query, with “view affected submissions” opening exactly that list. Not a number the model made up: a number the database returned.
### Predict outcomes from your own history
Train a model on past submissions — free-text answers included — to predict a field or the workflow outcome for the ones still open, with accuracy measured on held-out data and the driving fields named. Then it is held to account: as records close, live accuracy is measured against what actually happened, drift is said in words, and retraining is one click or a weekly schedule. Predictions appear as clearly labelled estimates beside a record with a what-if to test a change, never among its real values, and training costs no AI credits at all.
### Flag the unusual ones
An anomaly model learns what a normal submission looks like and marks the ones that don’t fit — an “Unusual record” flag with the fields that made it odd — scored automatically as records arrive and change. Quiet by design: a flag on the record, not a siren in your inbox.
### Standing agents that work a form’s submissions
Beyond the conversation: define an agent with a job in your own words — “triage new tickets and assign them” — against one form, with only the permissions you explicitly grant it (never more than your own). Run it on demand, on every new submission, or on a real schedule — every Monday at 9am in your timezone, not “roughly weekly, drifting later each run”. Every run is shown live, and a run that touches anything beyond its one form is refused.
### Ask for a review
One click in the builder hands your draft to the agent, which walks the form, its logic and its workflow and reports what it finds — gaps, dead rules, unreachable states — as a visible investigation, not a verdict from a black box.
Annotation, not the record
### AI output is checked before it touches anything
Every extraction, filter and generated definition is validated against your form's real fields before it is used — unknown fields are dropped, values are coerced to their declared types, and the server recomputes every calculation regardless of what was suggested.
Bounded by design
### The agent is exactly as privileged as you
It signs its requests with your own session, so the platform's access control bounds everything it does. It has no delete tools, no admin tools and no credentials of its own — there is no 'AI user' with special powers to compromise.
Questions
### AI, plainly
**What makes the assistant agentic?**
It runs a plan-and-act loop rather than generating text about your ask: it chooses from a set of tools — the same platform operations you use — executes them in sequence, checks the results and carries on until the job is done, reporting each step in the conversation as it goes.
**What can the agent see and do?**
Exactly what you can. It acts with your own permissions — every read and write it performs is bounded by the same access control as your own clicks, and it cannot delete or archive anything. Destructive actions stay in the UI, with you.
**Does AI change my data without asking?**
No. AI proposes and the human disposes: an extraction lands in the form for your review, a compiled filter is applied to your view, a generated report seeds the builder. Nothing persists until you take the normal save path.
**What is an AI credit?**
One unit of assistant or AI-builder work. Analyzing a form’s submissions into an insight report costs about four; filling a form from a document costs about five, as does turning a typical page into a template — a dense multi-page reproduction spends more, at what it measurably cost; generating a whole form from a description costs about fifty. Training a predictive model costs no credits — credits meter model reasoning, not compute. Credits reset monthly, and stop at the allowance — a runaway loop cannot run up a bill. Paid plans can add prepaid credit packs that never expire; nothing is ever charged automatically.
### Put the agent to work
Every plan includes monthly AI credits — the Free plan too. See pricing for allowances.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# MCP form builder for Claude and AI agents
Source: https://faldaro.com/features/mcp
An MCP form builder for Claude and any MCP client: your model builds forms, files submissions and runs reports with exactly your API key’s permissions.
MCP server
## Connect Claude to your forms
Faldaro hosts a Model Context Protocol server. Point Claude — or any MCP client — at it with one of your API keys, and your model can build forms, file submissions, run reports and work your data as tool calls, with exactly the permissions that key holds and not one more.
[Try it free](https://faldaro.app/auth/signup)
### The whole platform as a toolbox
Nearly sixty tools, the same catalogue the in-app agent uses: folders and forms, drafts and publishing, logic and workflow editing, submissions, transitions, reports, datasets, document and notification templates, test cases. If your key may do it, your model may do it.
### Your key is the whole permission model
The server adds no account of its own and holds no credential of its own. Each tool call is authorized as the API key that made it — the same privilege checks and the same tenant isolation as the raw API, enforced in the database.
### Honest tool annotations
Every tool declares what it is: read-only tools say so, and tools that can overwrite a draft carry a destructive hint, so a well-behaved client knows when to stop and ask you. Reading is safe by construction — evaluation and previews persist nothing.
### Build and test forms from your editor
Ask Claude Code to draft a form, wire its logic, add regression test cases and run them — then open the builder to see the result. The validation that guards the app guards these writes too: a broken logic document is refused before it is saved, not stored and ignored.
Two minutes to connected
### One endpoint, one header
Create an API key under Settings → API keys, then hand it to your client. That is the whole setup.
Claude Code
```
claude mcp add --transport http faldaro https://faldaro.app/api/mcp \
--header "Authorization: Bearer ffk_your_key_here"
```
Then ask for the work, not the clicks: “find last week's unassigned submissions and assign them to me”, “add a test case pinning the premium for a $2M building”. The [MCP guide](https://faldaro.com/docs/mcp) has the full tool list, other clients, and what to know before connecting a model to real data.
Questions
### Fair questions, straight answers
**What is MCP?**
The Model Context Protocol is an open standard that lets AI applications call tools on other systems. Faldaro hosts an MCP server, so Claude — and any other MCP client — can operate your Faldaro account: list folders, build and publish forms, file and search submissions, run reports, all as tool calls you can watch.
**Is this different from the in-app AI agent?**
Same tools, different driver. The in-app agent runs inside Faldaro on our models and is metered in AI credits. Over MCP, the model is the one you already use — your Claude, in your editor or terminal — calling Faldaro as one of its tools. Faldaro meters those calls like ordinary API traffic, not AI credits — except where a tool itself runs Faldaro’s AI (generating a form, running an insight analysis), which spends the same credits it spends from the app.
**What can a connected model do to my account?**
Exactly what the API key you connect with can do, and nothing more. A key carries an explicit grant of privileges chosen when it was made; every tool call is checked against that grant and walled into your organization by the database itself. There are no delete or archive tools at all — destructive actions stay in the app, with a person.
**Which plans include it?**
Team and Business. API keys and the raw API stay on every plan, Free included — what Team adds is the model-ready toolbox. And MCP itself never consumes AI credits — the model doing the thinking is yours. Only the few tools that ask Faldaro’s own AI to work, like generating a form or running an insight analysis, spend credits, exactly as they do from the app or the raw API.
**Which clients work?**
Any MCP client that speaks the Streamable HTTP transport and can send an Authorization header — Claude Code and the Claude API among them, and stdio-only clients through a local bridge. Connectors that require OAuth sign-in (such as claude.ai on the web) are not supported yet.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Email to form: emails become submissions
Source: https://faldaro.com/features/inbound-email
Forward an email to a form’s own address and it becomes a submission: fields filled from the message, attachments attached, sender verified, workflow started.
Email-to-form
## Every form gets an email address
Half the work that belongs on a form arrives as an email instead. Give the form its own address, and forwarding that email files it: fields filled from the message, attachments attached, the sender verified against SPF and DKIM, and the workflow already moving.
[Try it free](https://faldaro.app/auth/signup)
### Forward it, and it’s filed
A message to a form’s address becomes a submission like any other: validation runs, formulas are computed on the server, the workflow starts, notifications and integrations fire, and an on-submission agent can triage it. Work that used to sit in an inbox lands as a record with a state.
### Only senders you named
An allowlist per address — a mailbox, or a whole domain — checked against what the sender’s mail cryptographically proved, never against the From line alone. New addresses start with an empty list that refuses everyone, because an address nobody vouched for should accept nothing.
### AI reads the message into your fields
“New claim for the Henderson job, $4,200, needs doing by the 14th” lands on client, amount and due date. The model may only fill fields the form declares, values are coerced to each field’s type, and your explicit mappings always win — an extraction is a guess, configuration is intent.
### Attachments ride along
Files on the message become files on the submission, mapped onto a file field of your choosing. The forwarded invoice is attached to the record it created, not stranded in whoever’s mailbox it arrived in.
### Nothing vanishes into a spam folder
Every message is a row in the Inbound mail queue: filed ones link to their submission, held ones say why in plain words — with the sender’s SPF and DKIM verdict beside them — and a held message is retried in one click once the cause is fixed. The original.eml stays downloadable.
Two minutes to receiving
### Mint, allowlist, forward
From the builder’s Share tab, beside the public link — the other way into a form without an account.
The form’s own address
```
s-k3v9m2xq7c4p8trw5ndj6bhs2f@in.faldaro.com
```
Create the address, add the senders you trust, map where the subject, body and attachments should land — then forward something to it and watch it appear as a submission. The [Email-to-form guide](https://faldaro.com/docs/inbound-email) covers sender verification, the review queue, and what your domain needs to publish for its mail to prove itself.
Questions
### Fair questions, straight answers
**Who can send to a form’s address?**
Only senders you named. Every address carries an allowlist — a mailbox, or a whole domain — and an empty allowlist refuses everyone, deliberately: an address that accepted mail the moment it existed would be an open relay into your forms. The address itself is an unguessable token, rotated in one click if it spreads too far.
**What stops someone faking the sender?**
The From line on an email is text anyone can type, so Faldaro never trusts it on its own. A message counts as being from a domain only when that domain proved it — an SPF pass or a DKIM signature that aligns with the From address, the same standard the big mail providers hold each other to. A sender whose domain proves nothing is held for review, with the reason spelled out.
**What happens to attachments?**
They become real files on the submission, on whichever file field you mapped — same as if someone had uploaded them on the form. With AI extraction on they are read too: the claim form a broker attaches, scanned or not, fills the fields it answers.
**What if a message can’t be filed?**
It is held, never dropped. The Inbound mail queue shows every message with what its sender proved and, for held ones, the reason in plain words — sender not on the allowlist, nothing authenticated the domain, the data failed the form’s own validation. Fix the cause and press Retry; a retry can never file the same message twice.
**Can I just forward things from my own inbox?**
Yes — that is the everyday use. Forward the broker’s email, the supplier’s invoice, the enquiry that arrived in the wrong place, and it is filed on the right form with you as a verified sender. Your own provider signs your forward, which is exactly the identity your allowlist names.
**Which plans include it?**
Team and Business. The configured mappings — subject here, body there, attachments on that field — cost nothing per message; having AI read the rest of the message into your fields is metered in AI credits like every other AI feature, and can be switched off per address.
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Generate PDFs from form submissions, with e-sign
Source: https://faldaro.com/features/documents-payments
Generate a PDF from every form submission — in your own document’s layout — request e-signatures, collect Stripe payments priced on the server, deliver files.
## Documents, payments and delivery from one submission
The same submission that captured the answers can produce the PDF, take the payment and hand over the goods — without a script, a stitched-together toolchain or a human copying values between systems.
[Start free](https://faldaro.app/auth/signup)
### PDF documents
Design templates from structured blocks — headings, tables, merge fields, conditional sections, images — or reproduce an existing PDF exactly, its own pages becoming the template with the type matched onto open faces and your fields bound on top. Certificates, decision letters, confirmations: merged, not mail-merged.
### Payments, server-priced
A logic rule prices the payment from the submitted answers; Stripe collects it. Deposits, tiered fees, add-ons — whatever your formulas say, and only what they say. A workflow step can require payment before it proceeds.
### E-signatures
A workflow step emails each signer their own link to a frozen, fingerprinted copy of the document. They draw or type a signature; the platform records who, when and from where, appends a certificate page to the signed PDF, and a later step can require everyone to have signed.
### Digital delivery
Attach files from your library to a form’s rules and submitters get a stable download link when their submission — and, if priced, their payment — completes. Sell documents, deliver purchased files, hand out program packs.
Comparing approaches first? The guide to [generating a PDF from every form submission](https://faldaro.com/guides/generate-pdf-from-form-submission) covers built-in exports, document services, plugins and code, and the [membership approval guide](https://faldaro.com/guides/membership-application-approval) shows payment requested only after approval.
Reliability
### Money moves like data: recorded first
Every payment and payout is written down before any request leaves for Stripe, and confirmations come from Stripe's signed webhooks — never from a browser's success page. A closed tab cannot lose a payment, and a retried webhook cannot double one.
Templates are data
### A template cannot run code
Document templates are structured data rendered by the platform, not scripts. Merged values are escaped, conditions run through the same closed expression engine as form logic, and rendering has a budget — a malformed template degrades, it never takes the service with it.
Questions
### Documents and payments, plainly
**Who decides how much a payment is?**
Your form’s rules, evaluated on the server. The amount is computed from the submitted answers by the same engine that computes every other value — a browser has no way to send its own price, because the request has no field an amount could ride in.
**How do payments reach my bank account?**
Through Stripe. You connect your Stripe account once; Faldaro creates the payment against it and Stripe handles cards, receipts and payouts. Card details never touch Faldaro.
**When is a digital product released?**
When the submission’s recorded payment status says it has been paid — checked at download time, every time. A free tier priced at zero releases immediately; a paid one releases when Stripe confirms settlement.
**Can a workflow send someone their documents?**
Yes. A transition can generate a document from a template and email it — the approval that finishes a claim can be the same step that sends the decision letter.
### Close the loop on your process
Collect the answers, price the work, produce the paper and deliver the goods — one platform, one submission.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Form reports, dashboards and datasets
Source: https://faldaro.com/features/reports-data
Group, aggregate and search live submissions on the server — dashboard reports, plain-English filters, CSV export and versioned datasets behind your dropdowns.
## Ask questions where the answers live
With most form tools, analysis begins by leaving: export, spreadsheet, pivot table, repeat next week. Faldaro runs the grouping, the aggregates and the search on the server, over the live submissions — and keeps the reference data behind your forms on the platform too.
[Start free](https://faldaro.app/auth/signup)
### A report builder over live submissions
Pick columns, filter, group and aggregate — sums, averages, counts, distinct counts, minimums and maximums, with date grouping by day, week, month, quarter or year. The queries run on the server against current data; nothing is copied out to be counted.
### Pinned to the dashboard
Any saved report pins to the organization’s dashboard and renders there as a live card, beside submission trends, workflow-state counts and top forms. The morning glance and the deep dive are the same definition.
### Plain English to a filter
“Unpaid claims from July over $5,000” compiles into the exact filter — field keys, operators and workflow states checked against the form before anything runs. The interpretation is shown, so you can see what the words became.
### A form’s list is its pipeline
Above every form’s submissions, its workflow states are counted filters in the order they flow — one glance for where work is piling up, one click to see only those records. The name column stays pinned while a wide table scrolls, columns you hide are remembered per form, and ticking rows brings a bar that assigns or archives them together.
### Describe a report, refine it in the builder
Say what you want measured and a full definition — columns, filters, groupings, aggregates — lands in the report builder for you to adjust and save. AI proposes; you dispose.
### Insight reports, on demand or on a schedule
Every form’s Insights page analyzes its submissions — trends, outliers, correlations, workflow bottlenecks — with the statistics computed by the server and AI narrating them into ranked findings. Every count on a finding is an executed query, and one click opens exactly those submissions. See the AI page for the full story, including outcome prediction from your own history.
### Shared pages, embeds, badges and email digests
A grouped report becomes a live read-only page at a revocable link, an iframe embed for your own site, a one-number SVG badge for a README or wiki, or a daily or weekly email digest to people who never log in. Aggregates only — a report that lists individual records is refused at sharing time, and stays refused if it is ever edited into one.
### CSV export, without the booby traps
Reports and raw submissions export to CSV. Any cell that could execute as a spreadsheet formula is neutralized on the way out, so a hostile submission cannot attack whoever opens the file.
### A funnel on every share link, with nothing to consent to
Every public link counts views, starts and completions — per link, per day, shown beside the link and as a dashboard funnel. No cookies, no IP addresses, no fingerprinting: the server increments a counter and stores nothing about the person. There is nothing to put in a consent banner, because nothing is collected.
### Datasets: your reference data, versioned
Rate tables, product catalogues, region lists — edited in the browser or imported from CSV, versioned like forms, and bound to dropdowns and combo boxes. One dataset, every form that uses it, no options drifting out of step.
Mechanism
### A report definition is data, never SQL
Field names are validated against the form's live schema and bound as parameters; operators, aggregates and date buckets are looked up in closed maps. Nothing a report author types is ever concatenated into a query — and every report runs under a server-enforced time budget, so an expensive one is cut off rather than taking the service with it.
Isolation
### The engine has no special access
Reports execute under the same row-level security as every other query in the platform. However a definition is written — by hand, by AI, by mistake — it can only aggregate submissions its own organization could already read.
Questions
### Reports and datasets, plainly
**Do I have to export to analyze anything?**
No — that is rather the point. Group, aggregate and filter run against the live submissions, on the server, whenever the report is opened. Export exists for when you want the file, not because the answers live anywhere else.
**Is a report live, or a snapshot?**
Live. A report is a saved definition, not saved results: every run — on the report page or as a pinned dashboard card — executes against the submissions as they are now.
**Where do my dropdown options come from?**
A dataset: a versioned reference table you edit in the browser or import from CSV. Bind a field to a column and the options stay in one place — update the dataset, publish, and every form using it offers the new list. A second field can cascade from the first, region narrowing to district.
**Can the AI invent a report over fields that do not exist?**
No. A described report is validated field by field against the form’s real schema before it reaches the builder — unknown fields are dropped, operators are checked against each field’s type, and nothing is saved until you save it.
**Can a report see another organization’s submissions?**
No. Reports run under the same row-level security as every other query — the report engine holds no special access, so a definition, however written, can only ever aggregate what its organization could read anyway.
### Retire the Tuesday export
Build the report once, pin it to the dashboard, and let the spreadsheet be something you choose to make — not the place the answers live.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Form approval workflows, approved by email
Source: https://faldaro.com/features/approvals
Build approval forms with multi-step workflows: approvers decide from an email link with no account, deadlines escalate, and every decision lands on the record.
Approval workflows
## Form approval workflows, approved from the inbox
Build the form, draw the approval steps, and name who approves each one. Approvers decide from an email link with no account; deadlines escalate what stalls; every decision lands on the record with a name and a timestamp. Free to start, on every plan.
[Build an approval form free](https://faldaro.app/auth/signup) [See a template](https://faldaro.com/templates/expense-claim)
### Approve from the inbox, no login
The approver gets an email with their own link, sees only the fields you picked — the amount and the reason, not the whole application — and approves or declines with a comment. Managers, clients, landlords and partners outside your organization approve the same way.
### Multi-step, drawn as a diagram
Submitted → Manager review → Finance review → Approved. Each step is a state with its own moves, and each move names who may take it. Returned-with-questions and resubmit are moves too, so a request is never stuck in an email thread.
### Deadlines that escalate
A step can carry a deadline and the move to take when it passes. Stalled approvals stop being invisible: the record escalates on its own, and the audit log records that the deadline did it.
### Every decision on the record
Who approved, when, from where, with what comment — on the record’s Approvals tab and in an append-only audit log. When someone asks "who signed this off?", the answer is a read, not a hunt through email.
### What happens next is automatic
An approval can send the notification, generate the PDF, request the e-signature, ask for payment or create the next form’s record. You configure it once; every approval keeps the same promise.
### The requester can see where it is
Give the submitter a status link and they can check progress themselves — the current step and its reference number, never the answers or your internal notes. Fewer "any update?" emails.
Where it fits
### Approval forms people actually build
Each of these is a form, a few states and an approval request — configured in the browser, changed the day the process changes.
#### Purchase requests
Line items with a total the server computes, manager then finance approval over a threshold, a purchase order PDF on approval.
#### Expense claims
Receipts attached, the total added up on the server, approve or return with questions, then marked paid.
#### Time-off and change requests
A short form, one approver by email, the decision mailed back to the requester automatically.
#### Vendor and membership applications
Review the application, approve before you charge, and send the welcome pack on the approving move.
Start from a template — [expense claim](https://faldaro.com/templates/expense-claim), [project request](https://faldaro.com/templates/project-request), [vendor onboarding](https://faldaro.com/templates/vendor-onboarding) or [membership application](https://faldaro.com/templates/membership-application) — or read how [workflows](https://faldaro.com/features/workflows) work underneath. Designing the process first? Read [how to set up a form approval workflow](https://faldaro.com/guides/form-approval-workflow), or the guides for adding approvals to [Microsoft Forms](https://faldaro.com/guides/microsoft-forms-approval-workflow) and [Google Forms](https://faldaro.com/guides/google-forms-approval-workflow).
Questions
### Approvals, plainly
**Do approvers need an account?**
No. A workflow action emails each approver their own approve/decline link. They open it, see the fields you chose to show them, and decide — no login, no seat, no password to forget. The decision lands on the record with their name, a comment and a timestamp.
**Can a form need more than one approval?**
Yes, in two ways. Name several approvers on one request and the move fires once everyone has said yes; any no reads as declined. Or chain steps in the workflow — manager, then finance — so each approval is its own state with its own approvers, deadline and notifications.
**What if nobody approves?**
Give the waiting state a deadline — 48 hours, say — and name the move it takes when time runs out, such as Escalate. The platform takes that move itself, with the same conditions and notifications a person’s click would have, and the audit log says the deadline did it. An approval request can also expire; an expired request never counts as a yes.
**What can an approval link actually do?**
Exactly what you delegated and nothing more: take the one move you named for approve, and optionally another for decline. If the record has moved on by the time the link is opened, the verdict is recorded and nothing moves. Only people who can edit submissions can see the links in the app; people who can only read them see the verdicts.
**Can the next step depend on the approval?**
Yes. The verdict is recorded on the submission as approval_status, so any later move can require approval_status to be "approved" as its condition — and because the server records it, a submitter cannot type it in.
**Which plans include approvals?**
Every plan, the Free plan included. Paid plans add seats, volume and features like e-signatures and email-to-form; the approval step itself is never behind a paywall.
### Put your approval process on a form this week
A form, the steps, the approvers — built by the team that owns the process, on the Free plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Claims intake forms & FNOL workflow for insurers
Source: https://faldaro.com/use-cases/insurance
Claims intake and first notice of loss without a software project: FNOL forms, calculated estimates, approval workflows, status links and an audit trail.
## Claims intake without a software project
A Policies folder, a Claims folder, and workflows between them — configured in the browser by the people who run the process, changed the day the process changes.
[Start free](https://faldaro.app/auth/signup)
Claim intake Draft Submitted Approved
Client Acme Logistics
Incident date 14 Jul 2026
Vehicles 3
Estimate computed $12,400
CLM-2026-0147 v3 · published
A claim, end to end
### From incident to decision letter
The demo above is not a mock-up of someone else's product — it is the claim form this page describes, doing what claims do.
#### 1 Intake
A public claim form collects the incident. Conditional fields keep it short; the engine computes an estimate from your rate bands as the server sees the answers.
#### 2 Review
The claim lands in the Claims folder as Submitted, gets a reference number, and routing rules assign it. Reviewers see the computed estimate beside the submitted answers — two different things, stored separately.
#### 3 Approval
Moving to Approved is a privilege-gated transition. The move generates the decision letter from your template, emails the policyholder, and can spawn a linked payout submission.
#### 4 The record
Months later, the submission still carries the form version it was filled against, its audit trail, its documents and its figures. Disputes are settled by reading, not reconstructing.
The moving parts: the [form builder](https://faldaro.com/features/form-builder), [workflows](https://faldaro.com/features/workflows) and [documents](https://faldaro.com/features/documents-payments) — each doing the same job it does for every other use case. Start from a free template: [first notice of loss (FNOL)](https://faldaro.com/templates/first-notice-of-loss), [certificate of insurance request](https://faldaro.com/templates/certificate-of-insurance-request) or [loss run request](https://faldaro.com/templates/loss-run-request).
The broker channel
### Partners raise business on your forms
A brokerage is not a login you hand out — it is an organization of its own. Share the intake folder with each one and the whole channel works from the same forms, isolated by the database rather than by convention.
#### One intake, every brokerage
Publish a change once and every partner is on the new version at once — no emailed copies drifting out of date, no per-broker variants to reconcile.
#### Their book stays theirs
A brokerage submits through your form at submit level and its submissions belong to it; isolation is enforced by row-level security in PostgreSQL, and only you can change the form — cross-organization edits are blocked by the database itself.
The full rules — access levels, what a recipient can and cannot do — are in the [partner-sharing guide](https://faldaro.com/docs/sharing).
Job by job
### Insurance intake, one desk at a time
The same platform, shaped to the three streams of work insurance teams ask about most.
- [MGA submission intake Broker submissions in, referral rules and a server-computed indication applied, and a quote-or-decline workflow behind them.](https://faldaro.com/use-cases/insurance/mga-submission-intake)
- [Broker submission portal Brokers submit, track status and see their own submissions without a login on your account.](https://faldaro.com/use-cases/insurance/broker-submission-portal)
- [Claims email intake Forward a claim email to a form’s address and it becomes a claim record, attachments and all.](https://faldaro.com/use-cases/insurance/claims-email-intake)
Questions
### Insurance on Faldaro, plainly
**Can policyholders submit claims without an account?**
Yes — publish a public link for the claim form. The link is tokenized and revocable, throttled against runaway scripts, and never exposes your rating formulas or workflow to the person filling it in.
**Can brokers or partner agencies use our forms?**
Yes. Share a form or a whole folder with a partner organization at submit level: they raise business through your forms, their submissions stay theirs, and only you can change the form.
**What happens when a claim is disputed?**
The record answers for itself: the submission keeps the exact form version it was filled against, every workflow move is in an append-only audit log, and every computed figure was produced by the server, not typed in.
### Configure your claims process this week
No integration project, no vendor onboarding — a folder, a form and a workflow, built by the team that owns the process.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Support ticket intake forms
Source: https://faldaro.com/use-cases/support-desk
A ticket desk shaped like your process: intake forms with routing logic, your own workflow states, notifications and Zapier handoffs to the rest of your stack.
## A ticket desk shaped like your process
Helpdesk products make you adopt their vocabulary. On Faldaro a Tickets folder holds forms you designed, moving through states you named, routed by rules you wrote — and all of it changes the day your process does.
[Start free](https://faldaro.app/auth/signup)
### Intake that asks the right questions
Conditional fields mean a billing question and an outage report ask different things — one form, no irrelevant boxes, no “see attached” tickets missing the one detail you needed.
### States your team already uses
New, Triaged, Waiting on customer, Resolved — whatever your desk actually says. Rename a state or add one in the browser; the workflow is configuration, not code.
### Notifications that close the loop
Acknowledgement on submission, updates on transition, a resolution note from a template when the ticket closes — each one a workflow effect you configure once.
### A desk you can answer for
Every ticket keeps its history: who triaged it, when it moved, what was said in the record. The audit log is append-only, so the answer to “what happened here?” is always the truth.
### Requesters who never ask “any update?”
Every ticket can carry a “track your request” link — merged into the acknowledgement email — showing its current stage and reference number. Switch on the portal and requesters see all their tickets from just their email address, no account, no seat.
### Triage on a board
The queue as a board whose columns are your own states: drag a ticket from New to Triaged and the workflow move fires, guards intact. The same records, as a table, calendar or cards when the board is the wrong lens.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder), [workflows](https://faldaro.com/features/workflows) and [the assistant](https://faldaro.com/features/ai) for the “show me unresolved tickets from last week” moments.
Start from a free template: [Contact us](https://faldaro.com/templates/contact), [Support request](https://faldaro.com/templates/support-request) or [Maintenance request](https://faldaro.com/templates/maintenance-request). Each opens as an editable draft in your own account.
Questions
### Support on Faldaro, plainly
**Can customers raise tickets without logging in?**
Yes — publish a public link for the intake form. Anonymous submission is throttled by default, and where your operator has configured a captcha it sits in front of every public form. Attachments work, and the customer sees only the form: never your routing rules, states or internal fields.
**How does a ticket reach the right person?**
Workflow rules assign from the submission’s own answers — product area, severity, region — and notify the assignee. Reassignment is a transition like any other, gated and audited.
**Does it talk to the rest of our stack?**
Transitions can call your webhooks (against operator-allow-listed hosts) and send tickets to Zapier, which reaches the rest. Slack messages, CRM records and sheets are a rule, not an integration project.
### Stand up your desk today
An intake form, four states and two notification rules make a working desk — the Free plan covers all of it.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Inspection checklist forms
Source: https://faldaro.com/use-cases/inspections
Inspection checklists that produce the report: conditional questions, photo uploads, server-calculated pass-fail scores and a generated PDF for every visit.
## Checklists that come back as a report
Most inspection tooling stops at collecting the answers, leaving somebody to assemble the findings into something a client will read. On Faldaro the same submission that captured the visit produces the score, the PDF and the paper trail.
[Start free](https://faldaro.app/auth/signup)
### Checklists that branch
A roof inspection and a kitchen inspection ask different questions. Conditional logic shows only the section that applies, so an inspector answers what matters and nothing else — one form, not eleven near-identical PDFs.
### Scores the field cannot fudge
Weighted items, defect counts, a pass threshold — all calculated on the server from the submitted answers. The device shows the result; it does not decide it, and it has no way to send one of its own.
### A report, generated
A document template turns the finished inspection into a PDF: findings, photos, the score and the sign-off, laid out the same way every time. Generate it on the closing transition and email it in the same step.
### Evidence that holds up later
Photos stay attached to the submission that captured them, and the audit log is append-only — so when a finding is challenged six months on, who inspected what and when is a matter of record, not recollection.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder) for the checklist, [documents](https://faldaro.com/features/documents-payments) for the report and [workflows](https://faldaro.com/features/workflows) for what happens when something fails.
Start from a free template: [Incident report](https://faldaro.com/templates/incident-report) or [Inspection checklist](https://faldaro.com/templates/inspection-checklist). Each opens as an editable draft in your own account.
Questions
### Inspections on Faldaro, plainly
**Can an inspector attach photos from a phone?**
Yes. Add a file field and the form accepts photos — including on a public link, where the file field is itself the opt-in. Uploads are stored against the submission and served as attachments only, never rendered back into the page.
**How is a pass or fail decided?**
By your formulas, evaluated on the server on every save. A score derived from the answers cannot be edited in the browser, because the engine recomputes it from the submitted data rather than trusting a number the page sent.
**What if the checklist changes next quarter?**
Edit the form and publish a new version. Every inspection already filed keeps the version it was filled against, so last quarter’s reports still say exactly what they said — and you can run test cases before publishing to see what the change would move.
### Put your checklist in a browser
Build the form, add the scoring rule, design the report once — and every visit after that files itself.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Grant application intake and scoring
Source: https://faldaro.com/use-cases/grants
Run a grant round on one platform: public application links, server-side eligibility scoring, a gated review workflow and reference numbers that never change.
## Applications in, decisions out, reasoning kept
A grant round run on a mailbox and a spreadsheet can rarely answer the one question that matters afterwards: why this application and not that one. Faldaro keeps the criteria, the scores and the decisions in the same place as the applications.
[Start free](https://faldaro.app/auth/signup)
### One link, however many applicants
A tokenized public link takes applications from people who will never have a login — supporting documents attached, submission throttled against runaway scripts, and nothing on the page that reveals your internal fields.
### Scoring that is written down
Eligibility checks and weighted scores are formulas evaluated on the server, so every application is assessed by the same rule rather than by whoever opened it first. Change the rule and the change is versioned.
### A round that moves in steps
Received, Eligible, Shortlisted, Awarded, Declined — each transition gated by a privilege, so shortlisting and awarding are different powers held by different people. A rule can notify the applicant as it moves.
### Reference numbers and a record
Each application is allocated its reference once and keeps it through every edit — the number on the acknowledgement email is still the number a year later, and the append-only log says who decided what.
### Committee members who never log in
A workflow action mails each committee member their own approve/decline link showing exactly the fields you chose. The award fires only when everyone has said yes, any decline reads declined, and each verdict lands with a name, comment and timestamp.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder) for the criteria, [workflows](https://faldaro.com/features/workflows) for the review chain, and [the assistant](https://faldaro.com/features/ai) for “show me every eligible application above 70”.
Questions
### Grant rounds on Faldaro, plainly
**Can applicants apply without an account?**
Yes. Publish a link for the application form and anyone holding it can apply, attachments included. The link carries an unguessable token rather than the form’s id, so the range cannot be walked, and revoking an over-shared link is a rotation.
**Can applicants see their score?**
No, and not by accident — the public response deliberately carries no formula text, no rules and no calculated values. Scoring happens on the server, is visible to your reviewers, and never turns the application form into an oracle for the criteria behind it.
**Can an outside review panel see the applications?**
Invite reviewers into your organization by email with a narrow role — read and move applications, change nothing else. Submissions are never shared across organizations, deliberately: cross-organization sharing lets a partner submit through your form, not read what others submitted.
### Open your next round here
An application form, a scoring rule and four states are a working round — build it in an afternoon and publish the link.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Event registration forms with payment
Source: https://faldaro.com/use-cases/event-registration
Event registration forms that price the ticket on the server, collect it through Stripe, send the confirmation and keep a door list you can trust.
## Registrations that take the payment and send the confirmation
Event tooling usually gives you a ticket page and leaves the rest — the pricing rules, the dietary requirements, the confirmation emails, the door list — to a spreadsheet. Faldaro runs the whole registration as one submission.
[Start free](https://faldaro.app/auth/signup)
### One form, every ticket type
Member or guest, one day or three, dinner or not — conditional fields ask each attendee only what applies to them, and the questions you need for badges and catering come back filled in rather than chased later.
### The price is the form’s, not the page’s
A logic rule prices the registration from the answers and Stripe collects it. Change the early-bird cut-off in the browser and the next registration is priced the new way; card details never touch Faldaro.
### Confirmations that send themselves
Submission sends the acknowledgement and the joining instructions go out on the transition that confirms a place — each one a template you write once and a rule you configure once. The card receipt is Stripe’s to send, from the account the money landed in.
### A door list that is current
Registrations move through the states you named — Registered, Paid, Confirmed, Checked in — so on the day the list reflects who actually turned up, and every change to it is recorded.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder) for the questions, [payments](https://faldaro.com/features/documents-payments) for the money and [workflows](https://faldaro.com/features/workflows) for everything the confirmation should trigger.
Start from a free template: [Event registration](https://faldaro.com/templates/event-registration) or [Event vendor application](https://faldaro.com/templates/event-vendor-application). Each opens as an editable draft in your own account.
Questions
### Registration on Faldaro, plainly
**Who works out what a registration costs?**
Your form’s rules, on the server. Early-bird dates, member rates, workshop add-ons and group discounts are formulas over the submitted answers — and a browser cannot send a price of its own, because the request has no field one could ride in.
**What happens if someone closes the tab mid-payment?**
Nothing is lost. The payment is written down before any request leaves for Stripe, and completion is recorded from Stripe’s signed webhook rather than from a success page — so a closed tab cannot lose a registration, and a retried webhook cannot double one.
**How do we get the attendee list?**
Build a report over the registration form — counts by ticket type, dietary requirements, workshop numbers — and export it as CSV on plans that include export. Text cells that start with an equals sign are neutralized, so nobody’s answer executes in your spreadsheet.
### Open registration for your next event
Build and share the form on the Free plan; add Stripe payments from Starter when you are ready to charge for a place.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Sell digital products from a form
Source: https://faldaro.com/use-cases/digital-products
Sell a report, template pack or workbook straight from a form: server-priced payment, then a download link released once Stripe confirms the money arrived.
## Sell a file without standing up a storefront
Selling a report, a template pack or a course workbook usually means an e-commerce platform you did not want for the sake of one file. A Faldaro form can ask the questions, price the order, take the payment and hand over the goods.
[Start free](https://faldaro.app/auth/signup)
### The form is the storefront
Ask what you need to know — licence tier, seat count, VAT number — price it from those answers, and take the payment on the same submission. No storefront to configure alongside the questions you actually wanted.
### Delivery is a rule, not an errand
Upload the file to your library once and point a rule at it. Every qualifying submission mints its own claim, so nobody is emailing attachments at eleven at night when an order comes in from another timezone.
### Paid means paid
The claim is created when the submission commits, but it only releases against the payment status Stripe confirmed. Rows are written before any request leaves for Stripe, so a closed tab loses neither the order nor the money.
### One link, held for the buyer
The download link is minted once and stays stable across later edits, so it can be reissued in an email without changing. Revoke the product’s sharing later and claims already handed out still work.
Built from the same parts as everything else: [payments and delivery](https://faldaro.com/features/documents-payments) do the selling, [the builder](https://faldaro.com/features/form-builder) does the pricing, and [workflows](https://faldaro.com/features/workflows) carry whatever handling follows. The refund that occasionally follows is its own act, taken from the payment record — full amount, reversing any split with it, and safe to run twice.
Questions
### Selling files on Faldaro, plainly
**When exactly does the buyer get the file?**
When the submission’s recorded payment status says it has been paid — checked afresh every time the link is opened, not written down once at checkout. There is no release flag to get stuck, and nothing for a retried webhook to knock out of step.
**Can the download link be passed around?**
It carries an unguessable token, and the file ids behind it are inert without it. The link is rate-limited per token rather than per visitor, so one over-shared link is bounded — and a link that never opted in is a plain 404, the same answer a made-up token gets.
**What if I give something away free?**
Then it is released immediately. The gate is frozen per submission from what that submission’s own rules priced — so a conditional rule that charged nothing this time does not leave the buyer waiting on a payment that was never asked for.
### Put your file behind a form
Payments and digital delivery start on the Starter plan — build and shape the form itself for nothing first.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Client intake forms with e-sign & payments
Source: https://faldaro.com/use-cases/client-intake
Client intake for firms and agencies as one record: the questionnaire, documents, a generated engagement letter, the e-signature and a server-priced retainer.
## Client intake that ends signed and paid
For firms and agencies, intake is not a form — it is the stretch between “we should work together” and a signed letter with a retainer behind it. On Faldaro that stretch is one record: the questionnaire, the documents, the generated letter, the e-signature and the payment, moving through states your practice named.
[Start free](https://faldaro.app/auth/signup)
### One form instead of an email thread
Conditional fields mean a new engagement and a returning client answer different questions — and required documents are uploaded into the record, not attached to message four of nine.
### From inquiry to engaged, as states
Inquiry, Conflicts check, Proposal sent, Engaged — whatever your intake actually says. Moving a matter is a separate, permissioned act from editing it, and each move can notify, generate the letter, or request the signature.
### The letter writes itself
A document template merges the client’s answers into your engagement letter or proposal as a PDF — generated by a workflow move, not assembled by hand from the last one.
### A record you can answer for
Who opened the matter, who cleared conflicts, when the letter went out, what was signed and when the retainer landed — an append-only audit log keeps the history a professional practice has to be able to produce.
### Clients who can see where things stand
Each matter can carry a status link — stage, reference number, last movement — and the portal lists every matter a client has open, reached with nothing but their email. Fewer “just checking in” calls; never a peek at the file itself.
### Intake you can hand to a partner firm
Publish the intake form’s design as a template and a partner clones it into their own workspace in one click — fields, rules and workflow travel; your matters and datasets never do.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder), [workflows](https://faldaro.com/features/workflows) and [documents & payments](https://faldaro.com/features/documents-payments) for the letter and the retainer.
Start from a free template: [Project request](https://faldaro.com/templates/project-request). Each opens as an editable draft in your own account.
Questions
### Intake on Faldaro, plainly
**Do clients need an account to fill in the intake form?**
No. Publish a public link — an unguessable token you can rotate — and the client sees only the form: never your review states, internal fields or the pricing logic behind a computed fee. File uploads work without a sign-in, so the documents arrive attached to the record instead of in a separate email.
**Can the engagement letter be signed in the same flow?**
Yes, on the Team plan and above. A workflow move requests the signature: the client gets their own tokenized signing link, the document is frozen and fingerprinted before anyone signs, and the evidence — what was shown, what happened, when, from where — lands in rows the application role cannot delete. A transition can then gate on the signature, so nothing proceeds unsigned.
**Can I take a retainer or deposit at intake?**
Yes. A rule prices the payment from the client’s own answers — matter type, scope, urgency — and the server computes that amount itself, so the page cannot be tampered into a discount. Anything gated on payment waits until Stripe confirms the money actually arrived.
**What happens to intake that still arrives by email?**
Give the form its own address and forward the message: it becomes a submission with the attachments attached, the sender verified, and the workflow fired — same queue, same states, no retyping. Inbound email is a Team-plan feature, and only senders you allow-list are accepted.
### Retire the intake email thread
A questionnaire, four states and a document template make a working intake — the Free plan covers the form, the documents and the payment.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Job application intake with a hiring pipeline
Source: https://faldaro.com/use-cases/job-applications
Collect job applications with resumes attached, route them to reviewers by rule, move candidates through your hiring states and answer every applicant.
## Job applications with a pipeline behind them
A hiring form is easy; hiring is what happens after — screening, routing, interviews, and candidates hearing back. On Faldaro each application is a record moving through states you named, with resumes attached, reviewers assigned by rule, and every candidate answered by the workflow instead of by whoever remembered.
[Start free](https://faldaro.app/auth/signup)
### An application, not an attachment
Structured questions plus the resume upload, in one record — screening reads answers side by side instead of opening thirty PDFs, and conditional fields ask engineers and designers different things.
### Your pipeline, as states
Applied, Screening, Interview, Offer, Hired — or whatever your process actually says. Moving a candidate is a separate, permissioned act from editing the record, and every move is audited.
### Silence is a choice, not a default
Acknowledgement on apply, updates on transition, a real answer either way at the end — each one a workflow effect configured once, sent to the address the candidate gave.
### Hiring you can report on
Applications by role, by source, by state, over time — reports run on the live records with grouping and aggregation, so the Monday pipeline review is a saved report, not a spreadsheet rebuilt by hand.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder), [workflows](https://faldaro.com/features/workflows) and [reports](https://faldaro.com/features/reports-data) for the pipeline review.
Start from a free template: [Job application](https://faldaro.com/templates/job-application). Each opens as an editable draft in your own account.
Questions
### Hiring on Faldaro, plainly
**Can candidates apply without creating an account?**
Yes — the application is a public link, and nobody signs up for anything. Resume and portfolio uploads work anonymously too; the files arrive attached to the application record, not in a shared inbox. Anonymous submission is throttled by default, and a captcha can sit in front of it where your operator has configured one.
**How do applications reach the right reviewer?**
Workflow rules assign from the application’s own answers — role, team, location — and notify the assignee. Reassignment is a transition like any other, gated and audited, so “who is sitting on this?” always has an answer.
**Do candidates hear back automatically?**
Each transition can send a templated email to the address the candidate gave — received, moving forward, or a considerate no. You write the templates once; the workflow keeps the promise on every application, not just the ones someone remembered.
**Can applications sit unreviewed for weeks?**
Only if you let them. A state can carry a deadline — “in Screening more than ten days” — that fires a transition by itself: escalate it, flag it, notify someone. The deadline is part of the published form, so it holds even when everyone is busy, which is exactly when it matters.
### Open the role today
An application form, five states and two notification rules make a working pipeline — the Free plan covers all of it.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Vendor intake & onboarding with approvals
Source: https://faldaro.com/use-cases/vendor-onboarding
Vendor onboarding with the compliance kept: documents on the record, approval gated on the answers, signed agreements and an append-only audit trail.
## Vendor onboarding that would survive an audit
Onboarding a vendor is a compliance exercise wearing a form’s clothes: documents that must be present, approvals that must be earned, and a history someone will one day ask for. On Faldaro the vendor fills a public link, the documents attach to the record, approval is gated on what was actually answered, and the whole trail is append-only.
[Start free](https://faldaro.app/auth/signup)
### One request instead of an email checklist
Company details, tax status, banking, certificates — one form with conditional sections, so a sole trader and a corporation answer different questions and nothing arrives as “see attached”.
### Review as a workflow, not a spreadsheet
Submitted, In review, Approved, Rejected — with moves permissioned, conditions gating approval on the answers, and deadlines escalating a vendor nobody has looked at.
### Vendor numbers that behave
A reference number is allocated once, when the record commits, and never changes — edits never renumber a vendor, and two simultaneous registrations can never draw the same number.
### A file that would survive an audit
The exact form version answered, every document uploaded, every state change and who made it, the signed agreement and its evidence — kept in an append-only log, not a shared drive.
### Sign-off from finance, by email
The final approval often belongs to someone who will never open another tool. Mail them an approve/decline link showing just the fields that matter — their verdict takes the move you delegated, with a name, comment and timestamp on the record.
Built from the same parts as everything else: [the builder](https://faldaro.com/features/form-builder), [workflows](https://faldaro.com/features/workflows) and [e-signatures](https://faldaro.com/docs/esignatures) for the agreement itself.
Start from a free template: [Vendor onboarding](https://faldaro.com/templates/vendor-onboarding). Each opens as an editable draft in your own account.
Questions
### Onboarding on Faldaro, plainly
**Do vendors need an account on our system?**
No. The vendor gets a public link — an unguessable token you can rotate — and sees only the form: never your review states, risk fields or internal notes. Tax forms, certificates and bank letters upload without a sign-in and arrive attached to the record.
**Can approval require the documents to actually be there?**
Yes. A transition can require fields to be filled before it is offered, and a condition can gate on any answer — so “Approve” is simply not available while the insurance certificate is missing or the risk rating says review. Moving a vendor and editing a vendor are separate, permissioned acts.
**Where do the signed agreements happen?**
In the same record, on the Team plan and above: a workflow move requests the signature, the vendor signs on their own tokenized link, the document is frozen and fingerprinted first, and the evidence is kept in rows the application role cannot delete. A later transition can gate on the signature having happened.
**What does procurement get out of this beyond a tidy queue?**
A defensible history. Every submission keeps the exact form version it was filled against, every move records who took it and when, and the audit log is append-only because the database refuses updates and deletes on it — the answer to “who approved this vendor, on what information?” is always producible.
### Put procurement on rails
A registration form, four states and a required-documents gate make a working onboarding — start free, no card.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# MGA submission intake with referral rules
Source: https://faldaro.com/use-cases/insurance/mga-submission-intake
MGA submission intake for broker business: referral rules, a server-computed indication, email approvals and a quote-or-decline workflow on every submission.
## MGA submission intake, triaged by your own rules
An MGA or program administrator lives on broker submissions: a steady stream of risks, most of them incomplete, some outside appetite, a few that need someone with authority to look. Faldaro turns that stream into records — each submission checked against your referral rules, priced by the server, and moved from Received to Quoted or Declined by the people allowed to move it.
[Start free](https://faldaro.app/auth/signup)
A submission, end to end
### From broker email to quote or decline
The same four steps whether the risk came in through the form or through the inbox.
#### 1 The submission arrives
A broker fills in your submission form through a public link — no account, no seat — or forwards it by email. Class codes, territories and other long lists come from datasets you maintain, so the broker picks from your list, not free text.
#### 2 Your rules read it
Referral rules raise named outcomes — “Refer to underwriting”, “Outside appetite” — with a message saying why. The indication is computed by the server from the broker’s answers and stored apart from what the broker typed, so nobody can submit a premium of their own.
#### 3 Someone owns it
The submission gets a reference number, lands as Received and can be assigned. Moving it to Quoted, Declined or Referred is a separate, permissioned act from editing it, and a move can require fields to be filled or a condition on the values to hold.
#### 4 A decision goes out
The move to Quoted can generate the quote letter from your template and email the broker. Referrals can wait on an email approval from whoever holds the authority, and a deadline can move a quote that nobody answered to Lapsed on its own.
The parts doing the work: [workflows](https://faldaro.com/features/workflows) for the states and moves, [email approvals](https://faldaro.com/features/approvals) for referrals, and [records](https://faldaro.com/features/records) for the reference number, history and status link. This page is one part of [claims and submission intake for insurance](https://faldaro.com/use-cases/insurance).
Referral rules
### Appetite, written down once
The rules underwriters apply in their heads, stated where every submission meets them.
A referral rule is a condition and an outcome: when the total insured value is over your line, when the class is on the referral list, when the loss history says more than two claims — raise “Refer to underwriting” with a message naming the reason. Rules can also show or hide questions, so a broker quoting a warehouse is asked about sprinklers and a broker quoting an office is not. A hidden question contributes nothing to the calculation, so an answer the broker can no longer see cannot inflate the indication.
The indication itself is a formula over the broker’s answers — rate times exposure, adjusted by the factors you choose — and the server works it out on every save. What the broker typed and what the server computed are stored separately, which is what lets a referral rule, a transition or a quote letter rely on the number.
Keep in mind what a formula here is: arithmetic and a small set of functions, not a rating engine with its own tables. If your rating needs a large rate table, keep it where it lives and bring the result into the record; if it fits in a handful of factors, it fits in the form.
Control
### Built for rules that change every quarter
Appetite moves. The platform is shaped so that changing it is routine rather than risky.
#### Rating you can change safely
Every published version is immutable. Change a rate, publish, and new submissions use the new version while old ones keep theirs — the indication on a bound risk never shifts under it.
#### Changes tested before they ship
Form test cases pin named inputs to expected outputs. Run them against a draft and you know whether this week’s rating change moves a figure somebody relied on.
#### Formulas that cannot run code
Expressions run through a closed evaluator with a fixed set of operators and functions — no scripting engine behind the rating, and a budget on every evaluation.
#### A trail that answers for itself
Every create, move and publish is written to an append-only audit log. When a broker asks why a risk was declined, the record says who moved it, when, and against which version of the rules.
Where brokers come in
### Brokers are never seats
Submission intake is work from outside your organization, so the people sending it are not users you pay for.
Brokers reach you through a public link or a form’s email address — neither needs an account. Each submission can carry a status link the broker keeps, and with the submitter portal switched on a broker can list every submission filed under their email address. The [broker submission portal](https://faldaro.com/use-cases/insurance/broker-submission-portal) page covers that side in detail, and [claims email intake](https://faldaro.com/use-cases/insurance/claims-email-intake) explains how emailed submissions are verified and filed.
On the servicing side, the same account can run the smaller requests brokers send all day. Start from the free [certificate of insurance request](https://faldaro.com/templates/certificate-of-insurance-request), [loss run request](https://faldaro.com/templates/loss-run-request) or [first notice of loss](https://faldaro.com/templates/first-notice-of-loss) templates — each opens as an editable draft with its workflow included.
Questions
### MGA submission intake, plainly
**Can brokers see our referral criteria or rating from the submission form?**
No. The public form carries no logic document, no formula text and no calculated values — computed fields are marked as computed with the expression withheld. Referral outcomes and their messages appear only to your own staff inside the app, so the form never becomes an oracle for your appetite or your rating.
**What happens to submissions already in flight when we change the rating?**
Nothing. Publishing creates a new immutable version, and every submission keeps the version it was filled against. Before you publish, form test cases re-run pinned inputs through the real engine against the draft, so you see which indications would change before any broker does.
**Can an underwriter with referral authority approve from their inbox?**
Yes. A workflow move can request an approval by email: each approver gets a private link to a decision page showing only the fields you chose, and their verdict fires the move you configured. Every approver must agree for an approval to pass, any decline reads as declined, and an expired request never counts as a yes.
**Can brokers email submissions instead of filling in a form?**
On the Team plan and above, yes. Give the form its own address and allow-list your brokers’ domains; each message becomes a submission with its attachments, a verified sender and fields read out of the email. See the claims email intake page for how the checks work — the same mechanism serves new business.
### Put your submission desk on one queue
A submission form, your referral rules and four states make a working intake — built by the underwriting team, changed the day appetite changes.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Broker submission portal, no logins needed
Source: https://faldaro.com/use-cases/insurance/broker-submission-portal
A broker submission portal without seats: brokers submit through a link, track each risk on a status page and list their own submissions by email.
## A broker submission portal with no logins to hand out
Most broker portals are a user list: every producer at every agency gets a login, a password to forget and a seat somebody pays for. Faldaro starts from the other end. Brokers are outside your organization, so they submit through a link, follow each risk on its own status page and list their submissions with nothing but their email address.
[Start free](https://faldaro.app/auth/signup)
What the broker gets
### Submit, track, look back
Three things a broker wants from a portal, each without an account.
#### Submit without a login
Each form gets a public link carrying an unguessable token instead of the form’s id. Brokers fill it in, upload the documents the form asks for and are done — no account, no password reset, no seat on your plan.
#### A status page for every risk
Each submission can carry its own status link: form name, current state, reference number and when it last moved. Send it in the acknowledgement email and the “any update?” calls have somewhere to go.
#### All my submissions, by email
Switch on the submitter portal for a form by naming the email field that identifies the broker. The broker enters that address and gets a link listing every submission filed under it — matched on that one field only, never on an address that merely appears somewhere in a record.
#### Nothing leaks through the portal
The public form carries no logic, no formula text and no computed values, and the status and portal pages show only the curated projection. Refused tokens all get the same “not found”, so a withdrawn link cannot be told apart from one that never existed.
The status page and the portal are covered in the [records and sharing links guide](https://faldaro.com/docs/records-sharing); the record behind them is described on [records](https://faldaro.com/features/records).
Two shapes
### Decide where the submission should live
Faldaro supports two ways of working with brokers, and they answer different questions.
#### Submissions come to you
Public links, the form’s email address, status links and the portal. Every submission lands in your account and your workflow; brokers need nothing but a browser and an inbox. This is the broker portal most MGAs and wholesalers mean.
#### Brokerages keep their own book
Share a folder or a form with a brokerage’s own organization at submit level. They work from your current forms — publish a change once and every partner has it — but their submissions belong to them. Only you can change the form; a partner cannot share it onward or open a public link on it.
The difference is deliberate. Forms and folders can be shared between organizations; submissions never are. A partner organization can read your form — it has to, to fill it in — but only you can write it, and what a partner submits stays in the partner’s account. The full rules are in the [partner-sharing guide](https://faldaro.com/docs/sharing).
Behind the portal
### What your team sees
The broker’s side is deliberately small. Yours is the full record.
Each submission arrives as a record with a reference number, a state and an owner. Underwriters work it through [workflow](https://faldaro.com/features/workflows) states you name — Received, Referred, Quoted, Declined — and every move is a permissioned act written to an append-only audit log. When the state changes, the broker’s status page changes with it; there is nothing to sync and nothing to email by hand unless you want to.
Referrals can go to whoever holds the authority as an [email approval](https://faldaro.com/features/approvals): a private link to a decision page showing only the fields you picked. The rating and referral side is covered on [MGA submission intake](https://faldaro.com/use-cases/insurance/mga-submission-intake), and brokers who would rather forward an email than fill in a form are covered on [claims email intake](https://faldaro.com/use-cases/insurance/claims-email-intake) — the same address mechanism serves new business.
The portal is not only for new business. Service requests use the same links and the same status pages: start from the free [certificate of insurance request](https://faldaro.com/templates/certificate-of-insurance-request), [loss run request](https://faldaro.com/templates/loss-run-request) or [first notice of loss](https://faldaro.com/templates/first-notice-of-loss) template. More on the vertical as a whole is on the [insurance overview](https://faldaro.com/use-cases/insurance).
Questions
### The broker portal, plainly
**Do brokers need an account to use the portal?**
No. A broker submits through a public link and signs in to nothing. To see their submissions later they type their email address on your form’s page and receive a sign-in link at that address — owning the mailbox is the credential. The page answers the same way whether or not anything matched, so it cannot be used to check who has submitted to you.
**What can a broker see about a submission they sent?**
The status page shows the form’s name, the current state with the label you gave it, whether it is finished, the reference number and when it last moved. It never shows field values, your workflow, your referral rules or any computed figure — a broker learns where the risk stands, not how you rate it.
**Can a brokerage get its own copy of our forms instead?**
Yes — share the folder or a single form with the brokerage’s own Faldaro organization at submit level. Be clear about the trade-off: submissions made that way belong to the brokerage and stay in its account, isolated by the database. If the submission needs to land in your queue, use the public link or the form’s email address.
**Can we revoke a broker’s access?**
Every link is a token you can rotate. Rotating a public link stops it working at once, and a status link can be rotated or removed even while the record is archived. Access for a partner organization is removed by withdrawing the share.
### Give brokers a portal, not a password
Public links, status pages and the submitter portal are on every plan — start with one submission form and add the rest as brokers ask.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Claims email intake: email claims to a form
Source: https://faldaro.com/use-cases/insurance/claims-email-intake
Email claims to a form: each forwarded claim becomes a record with its attachments, a verified sender, fields filled from the message and the workflow started.
## Claims email intake: forward the email, get a claim record
However good your claim form is, a share of first notices will still arrive as email — from brokers, from adjusters, from a policyholder who replied to the last message you sent. Give the claim form its own address and those emails stop being a second queue: each one is checked, filed as a claim with its attachments, and put into the same workflow as everything else.
[Start free](https://faldaro.app/auth/signup)
Email claims to a form
### Four steps from inbox to claim
Set up once per form; after that, forwarding is the whole job.
#### 1 Give the claim form an address
In the builder’s Share tab, mint an address of the shape s-…@in.faldaro.com. The part before the @ is an unguessable token, not the form’s name, and an address that has spread too far is retired by rotating it.
#### 2 Say who may send
Allow-list the brokers, adjusters and partner domains that report claims to you. Each message is checked against what its sending domain proved — SPF or DKIM, aligned with the From address the way DMARC aligns it.
#### 3 Forward the claim
The subject, body, sender and received date map onto fields you choose; attachments land on a file field as real files on the record. With AI switched on, the rest of the form — policy number, date of loss, type of loss — is read out of the message itself.
#### 4 Work it like any claim
The message becomes a submission: validation runs, formulas are computed on the server, the workflow starts at Reported, and notifications and integrations fire exactly as they would for a claim filed through the form.
The feature is described on [email to form](https://faldaro.com/features/inbound-email), and every setting is explained in the [inbound email guide](https://faldaro.com/docs/inbound-email).
Trust the sender, not the header
### Why an emailed claim can be believed
An inbox is the easiest place in the world to impersonate someone. The checks are built for that.
The allowlist is matched against the domain the message proved, never the From line on its own. A message qualifies when its sending domain passes SPF or carries a DKIM signature and that domain matches the From address. A broker on Google Workspace or Microsoft 365 needs their domain’s SPF record published — one DNS entry — and ideally DKIM switched on; until then their mail authenticates the provider rather than the brokerage, and the review queue says exactly that instead of accepting a claim nothing backed.
Each claim filed by email is recorded with the verified sender as its author in the audit log, and the submission is anonymous by construction — no person inside your organization is recorded as having filed it. Any automation you run on new claims treats it with the same caution as a claim from a public link.
Fields read out of the message are held to the form’s own rules: the model may only fill fields the form declares, every value is coerced to that field’s type, a choice field accepts only its published options, and anything it could not place is noted on the message. The mappings you configure always win over the extraction — configuration is a statement of intent, an extraction is a guess.
Honest limits
### What it deliberately will not do
Stated up front, so nobody finds out from a claim that never arrived.
#### Automated mail is ignored
Auto-replies, out-of-office notices and bulk mail are never processed, so a claim system and an auto-responder cannot mail each other in a loop.
#### No payment by email
A form whose rules price a payment cannot be filed by email — nobody is present to pay — so the message is held and says so rather than filed half-done.
#### The attachments, not just the note
Extraction reads the subject, the body and the attachments: text PDFs and text files as text, scanned forms and photos as images — up to five scans or images a message, each within a size limit. A scan or image left unread is named on the record; other formats, such as Word documents, are kept on the record but not read.
#### Size limits
Messages are capped at 25 MB with up to twenty attachments. Anything larger belongs on the form’s own upload field.
Start here
### A claim form that already has a workflow
Email intake is an address on a form. Start from one that already works.
The free [first notice of loss template](https://faldaro.com/templates/first-notice-of-loss) has the policy, policyholder and loss questions, a photo and document upload, and a workflow from Reported through Acknowledged and With an adjuster to Approved or Declined. Add an email address to it and claims from the form and the inbox land in the same queue. The same works for the [certificate of insurance request](https://faldaro.com/templates/certificate-of-insurance-request) and [loss run request](https://faldaro.com/templates/loss-run-request) templates.
Once a claim is a record, the rest of the platform applies. The claimant or broker can follow it on a status link — see the [broker submission portal](https://faldaro.com/use-cases/insurance/broker-submission-portal) — and the same address mechanism serves new business, covered on [MGA submission intake](https://faldaro.com/use-cases/insurance/mga-submission-intake). Decisions can go out as [email approvals](https://faldaro.com/features/approvals), and the whole vertical is summarized on the [insurance overview](https://faldaro.com/use-cases/insurance).
Questions
### Claims by email, plainly
**Who can email claims to the form?**
Only senders on the address’s allowlist, and a new address starts with an empty one that refuses everyone. An entry with an @ admits one mailbox; an entry without admits a whole domain, but only for mail whose SPF or DKIM actually proved that domain. The From header on its own is never enough — it is text anyone can type.
**What happens to an email that cannot be filed?**
It is held in the review queue with the reason in plain words — sender not allowed, authentication failed, the data failed the form’s validation, the organization ran out of AI credits. Fix the cause and press Retry: the message is still there, and retrying can never file it twice.
**Can it read a claim form attached as a PDF?**
Yes. With AI extraction on, the attachments are read along with the message: a PDF’s text, and — for a scanned form or a photo of the damage — the page itself, read as an image. Where the covering note and the attached form disagree, the AI is told to prefer the form and to say so in the notes on the record. The files are also kept on the record, and a message that yields nothing the form can accept is held for review rather than guessed at.
**Which plan includes claims email intake?**
Email-to-form is included in the Team plan and above. Reading fields out of the message uses AI credits per message; the fixed mappings — subject, body, sender, date and attachments — cost nothing.
### Close the second claims queue
One address on your claim form, an allowlist of the people who report claims, and the inbox feeds the same workflow as the form.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free form templates with workflows
Source: https://faldaro.com/templates
Free form templates that open in the builder as editable drafts — fields, calculations and workflows included. Publish with a public link in minutes.
## Start from a form that already works
Each template is a complete, working form — fields laid out, calculations written, and where the submission starts a process, the workflow drawn. Pick one and it opens in the builder as an editable draft in your own account.
[Contact us A short enquiry laid out across two rows.](https://faldaro.com/templates/contact) [Support request A ticket that moves through triage to resolved.](https://faldaro.com/templates/support-request) [Event registration Tickets, dietary needs and a total the server works out.](https://faldaro.com/templates/event-registration) [Job application Two steps, a CV upload and a shortlisting flow.](https://faldaro.com/templates/job-application) [Customer feedback A rating laid out in a row, and what sat behind it.](https://faldaro.com/templates/customer-feedback) [Incident report What happened, how bad, and an investigation flow.](https://faldaro.com/templates/incident-report) [Expense claim Three line items, a server-computed total, an approval flow.](https://faldaro.com/templates/expense-claim) [Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request) [Vendor onboarding Company, contacts and compliance across two pages.](https://faldaro.com/templates/vendor-onboarding) [NPS survey One score, one why, thirty seconds.](https://faldaro.com/templates/nps-survey) [Inspection checklist Pass/fail items, a defect count the server keeps.](https://faldaro.com/templates/inspection-checklist) [Membership application Join a club or association, with a fee the tier decides.](https://faldaro.com/templates/membership-application) [First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss) [Certificate of insurance request Who needs a certificate, for whom, and by when.](https://faldaro.com/templates/certificate-of-insurance-request) [Loss run request Ask for an insured's loss history and track it to delivery.](https://faldaro.com/templates/loss-run-request) [Event vendor application Apply for a stall, with a booth fee the server computes.](https://faldaro.com/templates/event-vendor-application) [Insurance quote calculator A business quote, priced on the server as people type.](https://faldaro.com/templates/insurance-quote) [Project request Propose a project and take it through review to a decision.](https://faldaro.com/templates/project-request)
None of them quite it? Describe the form in a sentence and the [AI builder](https://faldaro.com/features/ai) drafts it, or drop in the PDF it replaces — a template is only the fastest of the ways in.
Your turn
### Made something good? Publish it.
Any form in your account can become a template like these: one click publishes its design — fields, rules and workflow — at a link anyone can clone from. Your records, datasets and integrations never travel with it, and the link is yours to rotate or withdraw.
From any form’s menu
```
Share as template → Publish template → copy the /t/ link
```
Send it to a colleague at another company, drop it in a community, put it in a blog post — whoever opens it sees the design and makes it theirs in one click. Publishing again updates the template to your live form; the link never changes. And if it belongs in front of everyone, ask to list it in the community gallery on this page — a quick review, your organization’s name on the card, delisting yours any time.
Questions
### Templates, plainly
**Are the templates free?**
Yes — every template is available on every plan, the Free plan included. A template is a starting point, not a product: picking one creates an ordinary draft form in your account, and nothing about it is locked afterwards.
**Can I change the fields, the calculations or the workflow?**
All of it. A template opens in the builder as an unpublished draft — the same thing you would have built by hand — so every field, formula, state and move is yours to edit, and the form only starts accepting submissions once you publish it.
**What happens when I click “Use this template”?**
You sign in (or create a free account), the template loads into the builder as a draft, and you edit from there. Nothing is published and nothing is public until you decide it is.
**Why do some templates include a workflow?**
Because for most of these forms, the submission is the start of the work rather than the end of it. A support request gets resolved, an application gets a decision, an expense gets approved — the included workflow names those states and the moves between them, and you can rename or redraw all of it.
### A working form in the next five minutes
Pick a template, make it yours in the builder, publish a public link — the Free plan covers all of it.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free contact us form template
Source: https://faldaro.com/templates/contact
A short enquiry laid out across two rows. A free contact us template — edit any field, share a public link.
## Contact us template
A short enquiry laid out across two rows.
The shortest useful form, and a good first publish to check a link and a notification. Name and email share a row; the message spans the full width, because a third-width box invites a one-line answer.
[Use this template](https://faldaro.app/start/contact) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [support ticket intake](https://faldaro.com/use-cases/support-desk) — Tickets from users, routed by your rules into a desk shaped like your process.
### What’s in the form
6 fields — every one editable once the template is yours.
- Your name *
- Company
- Email *
- Phone
- Subject
- Message *
Questions
### The contact us template, answered
What picking this template does and does not commit you to.
**Is the contact us template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the contact us template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 6 fields, then publish when it reads right.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Support request A ticket that moves through triage to resolved.](https://faldaro.com/templates/support-request) [Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request) [Event registration Tickets, dietary needs and a total the server works out.](https://faldaro.com/templates/event-registration)
### Make the contact us form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/contact) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free support request form template
Source: https://faldaro.com/templates/support-request
A ticket that moves through triage to resolved. A free support request template — edit any field, share a public link, workflow included.
## Support request template
A ticket that moves through triage to resolved.
Shows the part a form builder does not have: the submission is a record with a state, and moving it along is a different power from editing it. Severity and category are indexed, so a report can group by them without exporting anything.
[Use this template](https://faldaro.app/start/support-request) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [support ticket intake](https://faldaro.com/use-cases/support-desk) — Tickets from users, routed by your rules into a desk shaped like your process.
### What’s in the form
8 fields — every one editable once the template is yours.
- Your name *
- Email *
- Summary *
- Impact *
- Area
- First noticed
- What happened? *
- Screenshot or log
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: New Triaged In progress Resolved
- Triage — New → Triaged
- Start work — Triaged → In progress
- Resolve — In progress → Resolved
- Reopen — Resolved → In progress
Questions
### The support request template, answered
What picking this template does and does not commit you to.
**Is the support request template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the support request template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 8 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “New” and moves through the included states — New, Triaged, In progress, Resolved. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request) [Contact us A short enquiry laid out across two rows.](https://faldaro.com/templates/contact) [Event registration Tickets, dietary needs and a total the server works out.](https://faldaro.com/templates/event-registration)
### Make the support request form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/support-request) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free event registration form template
Source: https://faldaro.com/templates/event-registration
Tickets, dietary needs and a total the server works out. A free event registration template — edit any field, share a public link.
## Event registration template
Tickets, dietary needs and a total the server works out.
The total is a computed field, recalculated on the server on every save and read — a browser cannot submit a total of its own choosing. The summary panel beneath it restates the figures without storing anything of its own.
[Use this template](https://faldaro.app/start/event-registration) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [event registration](https://faldaro.com/use-cases/event-registration) — Registrations from attendees that take the payment and send the confirmation.
### What’s in the form
9 fields — every one editable once the template is yours.
- Full name *
- Email *
- Organization
- Job title
- How many? *
- Price each computed on the server
- Total computed on the server
- Dietary requirements
- Accessibility requirements
Questions
### The event registration template, answered
What picking this template does and does not commit you to.
**Is the event registration template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the event registration template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 9 fields, then publish when it reads right.
**Who works out the calculated values?**
The server does. The Price each and Total fields are computed from the answers by the form’s own rules, so a browser can never fabricate them.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Event vendor application Apply for a stall, with a booth fee the server computes.](https://faldaro.com/templates/event-vendor-application) [Job application Two steps, a CV upload and a shortlisting flow.](https://faldaro.com/templates/job-application) [Customer feedback A rating laid out in a row, and what sat behind it.](https://faldaro.com/templates/customer-feedback)
### Make the event registration form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/event-registration) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free job application form template
Source: https://faldaro.com/templates/job-application
Two steps, a CV upload and a shortlisting flow. A free job application template — edit any field, share a public link, workflow included.
## Job application template
Two steps, a CV upload and a shortlisting flow.
A file field is what opts a public form into anonymous upload, so applicants attach a CV without an account. Split across two pages, because a long form on one page is where people give up.
[Use this template](https://faldaro.app/start/job-application) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [job application intake](https://faldaro.com/use-cases/job-applications) — Applications from candidates, with a pipeline behind them and every candidate answered.
### What’s in the form
13 fields, over 2 steps — every one editable once the template is yours.
#### About you
- Full name *
- Pronouns
- Email *
- Phone
- Address
- LinkedIn or portfolio
- Notice period
#### Your application
- Role applied for *
- How did you hear about us?
- Why this role? *
- CV *
- I have the right to work in this country *
- Everything I have entered is accurate *
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Received Screening Interview Offer Not proceeding · final
- Move to screening — Received → Screening
- Invite to interview — Screening → Interview
- Make an offer — Interview → Offer
- Not proceeding — Screening → Not proceeding
- Not proceeding — Interview → Not proceeding
Questions
### The job application template, answered
What picking this template does and does not commit you to.
**Is the job application template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the job application template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 13 fields across 2 steps, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Received” and moves through the included states — Received, Screening, Interview, Offer, Not proceeding. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Customer feedback A rating laid out in a row, and what sat behind it.](https://faldaro.com/templates/customer-feedback) [Incident report What happened, how bad, and an investigation flow.](https://faldaro.com/templates/incident-report) [Expense claim Three line items, a server-computed total, an approval flow.](https://faldaro.com/templates/expense-claim)
### Make the job application form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/job-application) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free customer feedback form template
Source: https://faldaro.com/templates/customer-feedback
A rating laid out in a row, and what sat behind it. A free customer feedback template — edit any field, share a public link.
## Customer feedback template
A rating laid out in a row, and what sat behind it.
Rating and reason are indexed, so they can be grouped and counted in a report without exporting anything. The rating renders horizontally, which is what stops a five-point scale reading as a list of unrelated options.
[Use this template](https://faldaro.app/start/customer-feedback) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
### What’s in the form
6 fields — every one editable once the template is yours.
- How would you rate us? *
- What mattered most?
- Would recommend us
- Anything else?
- Email
- Name
Questions
### The customer feedback template, answered
What picking this template does and does not commit you to.
**Is the customer feedback template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the customer feedback template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 6 fields, then publish when it reads right.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Incident report What happened, how bad, and an investigation flow.](https://faldaro.com/templates/incident-report) [Expense claim Three line items, a server-computed total, an approval flow.](https://faldaro.com/templates/expense-claim) [Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request)
### Make the customer feedback form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/customer-feedback) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free incident report form template
Source: https://faldaro.com/templates/incident-report
What happened, how bad, and an investigation flow. A free incident report template — edit any field, share a public link, workflow included.
## Incident report template
What happened, how bad, and an investigation flow.
A reporting form whose record then moves through investigation. Severity and location are indexed for filtering; the workflow deliberately allows reopening, because the commonest thing that happens to a closed incident is discovering it is not.
[Use this template](https://faldaro.app/start/incident-report) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [inspections](https://faldaro.com/use-cases/inspections) — Checklists that come back as a report, not a folder of photos.
### What’s in the form
6 fields — every one editable once the template is yours.
- One-line summary *
- Date *
- Severity *
- Where *
- What happened? *
- Photos or documents
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Reported Investigating Actions agreed Closed
- Start investigation — Reported → Investigating
- Agree actions — Investigating → Actions agreed
- Close — Actions agreed → Closed
- Reopen — Closed → Investigating
Questions
### The incident report template, answered
What picking this template does and does not commit you to.
**Is the incident report template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the incident report template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 6 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Reported” and moves through the included states — Reported, Investigating, Actions agreed, Closed. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Inspection checklist Pass/fail items, a defect count the server keeps.](https://faldaro.com/templates/inspection-checklist) [Expense claim Three line items, a server-computed total, an approval flow.](https://faldaro.com/templates/expense-claim) [Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request)
### Make the incident report form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/incident-report) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free expense claim form template
Source: https://faldaro.com/templates/expense-claim
Three line items, a server-computed total, an approval flow. A free expense claim template — edit any field, share a public link, workflow included.
## Expense claim template
Three line items, a server-computed total, an approval flow.
Every figure is added up on the server — a claimant cannot submit a total of their own choosing — and the claim moves through a plain approve/return flow. Duplicate the line trio to take more items, and extend the total formula with them.
[Use this template](https://faldaro.app/start/expense-claim) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
### What’s in the form
10 fields — every one editable once the template is yours.
- Name *
- Email *
- Item 1
- Amount 1
- Item 2
- Amount 2
- Item 3
- Amount 3
- Receipts *
- Total claimed computed on the server
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Submitted Approved Returned Paid
- Approve — Submitted → Approved
- Return with questions — Submitted → Returned
- Resubmit — Returned → Submitted
- Mark paid — Approved → Paid
Questions
### The expense claim template, answered
What picking this template does and does not commit you to.
**Is the expense claim template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the expense claim template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 10 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Submitted” and moves through the included states — Submitted, Approved, Returned, Paid. Every state and move is editable before you publish.
**Who works out the calculated values?**
The server does. The Total claimed field is computed from the answers by the form’s own rules, so a browser can never fabricate it.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Maintenance request Report a fault, triage it, see it fixed.](https://faldaro.com/templates/maintenance-request) [Vendor onboarding Company, contacts and compliance across two pages.](https://faldaro.com/templates/vendor-onboarding) [NPS survey One score, one why, thirty seconds.](https://faldaro.com/templates/nps-survey)
### Make the expense claim form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/expense-claim) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free maintenance request form template
Source: https://faldaro.com/templates/maintenance-request
Report a fault, triage it, see it fixed. A free maintenance request template — edit any field, share a public link, workflow included.
## Maintenance request template
Report a fault, triage it, see it fixed.
The classic operations queue: what is broken, where, and how urgently — with a workflow that separates "we have seen it" from "someone is on it". Priority and location are indexed so the list filters fast.
[Use this template](https://faldaro.app/start/maintenance-request) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [support ticket intake](https://faldaro.com/use-cases/support-desk) — Tickets from users, routed by your rules into a desk shaped like your process.
### What’s in the form
6 fields — every one editable once the template is yours.
- What is broken? *
- Priority *
- Where is it? *
- Your name *
- Anything that helps
- Photo
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Open Scheduled Being fixed Done
- Schedule — Open → Scheduled
- Start work — Scheduled → Being fixed
- Mark done — Being fixed → Done
- Reopen — Done → Open
Questions
### The maintenance request template, answered
What picking this template does and does not commit you to.
**Is the maintenance request template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the maintenance request template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 6 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Open” and moves through the included states — Open, Scheduled, Being fixed, Done. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Contact us A short enquiry laid out across two rows.](https://faldaro.com/templates/contact) [Support request A ticket that moves through triage to resolved.](https://faldaro.com/templates/support-request) [Vendor onboarding Company, contacts and compliance across two pages.](https://faldaro.com/templates/vendor-onboarding)
### Make the maintenance request form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/maintenance-request) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free vendor onboarding form template
Source: https://faldaro.com/templates/vendor-onboarding
Company, contacts and compliance across two pages. A free vendor onboarding template — edit any field, share a public link, workflow included.
## Vendor onboarding template
Company, contacts and compliance across two pages.
A two-page intake with the compliance questions kept off the first page, so a supplier sees the easy half first. The review flow ends in approved or declined — both terminal honesty, with a revisit path from declined for suppliers who fix the gap.
[Use this template](https://faldaro.app/start/vendor-onboarding) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [vendor intake & onboarding](https://faldaro.com/use-cases/vendor-onboarding) — Documents present, approvals earned, and a trail that survives an audit.
### What’s in the form
11 fields, over 2 steps — every one editable once the template is yours.
#### The company
- Registered name *
- Registration number *
- Website
- Country *
- Contact name *
- Email *
#### Compliance
- Liability insurance? *
- Will you process our data? *
- Certifications held
- Insurance certificate
- Anything else we should know
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Received In review Approved · final Declined
- Start review — Received → In review
- Approve — In review → Approved
- Decline — In review → Declined
- Revisit — Declined → In review
Questions
### The vendor onboarding template, answered
What picking this template does and does not commit you to.
**Is the vendor onboarding template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the vendor onboarding template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 11 fields across 2 steps, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Received” and moves through the included states — Received, In review, Approved, Declined. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[NPS survey One score, one why, thirty seconds.](https://faldaro.com/templates/nps-survey) [Inspection checklist Pass/fail items, a defect count the server keeps.](https://faldaro.com/templates/inspection-checklist) [Membership application Join a club or association, with a fee the tier decides.](https://faldaro.com/templates/membership-application)
### Make the vendor onboarding form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/vendor-onboarding) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free NPS survey form template
Source: https://faldaro.com/templates/nps-survey
One score, one why, thirty seconds. A free NPS survey template — edit any field, share a public link.
## NPS survey template
One score, one why, thirty seconds.
The whole art of a survey is being short. The score is indexed so reports can bucket promoters and detractors, and everything else is optional — a survey that demands a paragraph gets abandoned at the paragraph.
[Use this template](https://faldaro.app/start/nps-survey) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
### What’s in the form
4 fields — every one editable once the template is yours.
- How likely are you to recommend us, from 0 to 10 *
- What is the main reason for your score?
- Email, if we may follow up
- Account or order number
Questions
### The NPS survey template, answered
What picking this template does and does not commit you to.
**Is the NPS survey template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the NPS survey template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 4 fields, then publish when it reads right.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Inspection checklist Pass/fail items, a defect count the server keeps.](https://faldaro.com/templates/inspection-checklist) [Membership application Join a club or association, with a fee the tier decides.](https://faldaro.com/templates/membership-application) [First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss)
### Make the NPS survey form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/nps-survey) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free inspection checklist form template
Source: https://faldaro.com/templates/inspection-checklist
Pass/fail items, a defect count the server keeps. A free inspection checklist template — edit any field, share a public link, workflow included.
## Inspection checklist template
Pass/fail items, a defect count the server keeps.
Each check is a pass/fail with a numeric shadow, so the defect total is computed on the server rather than eyeballed. Add checks in pairs: the select people use, and the hidden 0/1 the total counts.
[Use this template](https://faldaro.app/start/inspection-checklist) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [inspections](https://faldaro.com/use-cases/inspections) — Checklists that come back as a report, not a folder of photos.
### What’s in the form
7 fields — every one editable once the template is yours.
- Site *
- Inspector *
- Access routes clear *
- Signage in place *
- Equipment condition *
- Defects found
- Photos
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Recorded Actions raised Verified
- Raise actions — Recorded → Actions raised
- Verify fixes — Actions raised → Verified
- Nothing to action — Recorded → Verified
Questions
### The inspection checklist template, answered
What picking this template does and does not commit you to.
**Is the inspection checklist template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the inspection checklist template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 7 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Recorded” and moves through the included states — Recorded, Actions raised, Verified. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Incident report What happened, how bad, and an investigation flow.](https://faldaro.com/templates/incident-report) [Membership application Join a club or association, with a fee the tier decides.](https://faldaro.com/templates/membership-application) [First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss)
### Make the inspection checklist form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/inspection-checklist) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free membership application form template
Source: https://faldaro.com/templates/membership-application
Join a club or association, with a fee the tier decides. A free membership application template — edit any field, share a public link, workflow included.
## Membership application template
Join a club or association, with a fee the tier decides.
The fee is a formula over the chosen tier — edit the numbers, not the plumbing — and the record then moves through a small approval flow. A good starting point for anything where people apply and someone says yes.
[Use this template](https://faldaro.app/start/membership-application) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
### What’s in the form
7 fields — every one editable once the template is yours.
- Full name *
- Email *
- Address
- Phone
- Tier *
- Annual fee computed on the server
- Why would you like to join?
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Applied Accepted Waitlisted Lapsed
- Accept — Applied → Accepted
- Waitlist — Applied → Waitlisted
- Accept from waitlist — Waitlisted → Accepted
- Mark lapsed — Accepted → Lapsed
- Renew — Lapsed → Accepted
Questions
### The membership application template, answered
What picking this template does and does not commit you to.
**Is the membership application template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the membership application template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 7 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Applied” and moves through the included states — Applied, Accepted, Waitlisted, Lapsed. Every state and move is editable before you publish.
**Who works out the calculated values?**
The server does. The Annual fee field is computed from the answers by the form’s own rules, so a browser can never fabricate it.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss) [Certificate of insurance request Who needs a certificate, for whom, and by when.](https://faldaro.com/templates/certificate-of-insurance-request) [Loss run request Ask for an insured's loss history and track it to delivery.](https://faldaro.com/templates/loss-run-request)
### Make the membership application form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/membership-application) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free first notice of loss (FNOL) form template
Source: https://faldaro.com/templates/first-notice-of-loss
Report a claim, then work it through to a decision. A free first notice of loss (FNOL) template — edit any field, share a public link, workflow included.
## First notice of loss (FNOL) template
Report a claim, then work it through to a decision.
The policy on the first page, the loss on the second, so a policyholder is never faced with everything at once. Loss type and policy number are indexed for triage, and the workflow runs from reported to a decision — with a way back from declined, because the commonest thing that happens to a declined claim is new evidence.
[Use this template](https://faldaro.app/start/first-notice-of-loss) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [insurance claims intake](https://faldaro.com/use-cases/insurance) — Claims from policyholders and brokers, with calculated estimates, approvals and a trail that survives a dispute.
### What’s in the form
12 fields, over 2 steps — every one editable once the template is yours.
#### The policy
- Policyholder name *
- Policy number *
- Email *
- Phone *
#### The loss
- Type of loss *
- Date of loss *
- Rough estimate
- Where did it happen? *
- What happened? *
- Police or fire report made? *
- Report number, if any
- Photos and documents
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Reported Acknowledged With an adjuster Approved Declined
- Acknowledge — Reported → Acknowledged
- Assign adjuster — Acknowledged → With an adjuster
- Approve — With an adjuster → Approved
- Decline — With an adjuster → Declined
- Reopen — Declined → With an adjuster
Questions
### The first notice of loss (FNOL) template, answered
What picking this template does and does not commit you to.
**Is the first notice of loss (FNOL) template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the first notice of loss (FNOL) template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 12 fields across 2 steps, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Reported” and moves through the included states — Reported, Acknowledged, With an adjuster, Approved, Declined. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Certificate of insurance request Who needs a certificate, for whom, and by when.](https://faldaro.com/templates/certificate-of-insurance-request) [Loss run request Ask for an insured's loss history and track it to delivery.](https://faldaro.com/templates/loss-run-request) [Insurance quote calculator A business quote, priced on the server as people type.](https://faldaro.com/templates/insurance-quote)
### Make the first notice of loss (FNOL) form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/first-notice-of-loss) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free certificate of insurance request form template
Source: https://faldaro.com/templates/certificate-of-insurance-request
Who needs a certificate, for whom, and by when. A free certificate of insurance request template — edit any field, share a public link, workflow included.
## Certificate of insurance request template
Who needs a certificate, for whom, and by when.
The request a landlord, venue or contractor sends before work can start. The certificate holder gets a section of its own, the deadline is a date rather than a sentence, and the workflow separates "we need more from you" from "being prepared" so nobody chases a request that is waiting on them.
[Use this template](https://faldaro.app/start/certificate-of-insurance-request) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [insurance claims intake](https://faldaro.com/use-cases/insurance) — Claims from policyholders and brokers, with calculated estimates, approvals and a trail that survives a dispute.
### What’s in the form
10 fields — every one editable once the template is yours.
- Your name *
- Email *
- Named insured *
- Policy number, if known
- Holder name *
- Needed by *
- Holder address *
- Add the holder as additional insured? *
- What it is for
- Contract or insurance requirements
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Requested Needs information Being prepared Issued
- Ask for information — Requested → Needs information
- Information received — Needs information → Requested
- Start preparing — Requested → Being prepared
- Mark issued — Being prepared → Issued
Questions
### The certificate of insurance request template, answered
What picking this template does and does not commit you to.
**Is the certificate of insurance request template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the certificate of insurance request template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 10 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Requested” and moves through the included states — Requested, Needs information, Being prepared, Issued. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Loss run request Ask for an insured's loss history and track it to delivery.](https://faldaro.com/templates/loss-run-request) [Insurance quote calculator A business quote, priced on the server as people type.](https://faldaro.com/templates/insurance-quote) [First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss)
### Make the certificate of insurance request form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/certificate-of-insurance-request) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free loss run request form template
Source: https://faldaro.com/templates/loss-run-request
Ask for an insured's loss history and track it to delivery. A free loss run request template — edit any field, share a public link, workflow included.
## Loss run request template
Ask for an insured's loss history and track it to delivery.
For agencies and brokers chasing loss runs across carriers: one record per carrier request, the insured's signed authorization attached up front, and a workflow that shows which requests are still sitting with a carrier.
[Use this template](https://faldaro.app/start/loss-run-request) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [insurance claims intake](https://faldaro.com/use-cases/insurance) — Claims from policyholders and brokers, with calculated estimates, approvals and a trail that survives a dispute.
### What’s in the form
9 fields — every one editable once the template is yours.
- Agency or brokerage *
- Email *
- Insured *
- Carrier *
- Policy number *
- Years of history *
- Needed by
- Signed authorization from the insured
- Anything else the carrier needs
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Requested With the carrier Received Delivered
- Sent to carrier — Requested → With the carrier
- Loss runs received — With the carrier → Received
- Delivered to requester — Received → Delivered
Questions
### The loss run request template, answered
What picking this template does and does not commit you to.
**Is the loss run request template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the loss run request template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 9 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Requested” and moves through the included states — Requested, With the carrier, Received, Delivered. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Insurance quote calculator A business quote, priced on the server as people type.](https://faldaro.com/templates/insurance-quote) [First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss) [Certificate of insurance request Who needs a certificate, for whom, and by when.](https://faldaro.com/templates/certificate-of-insurance-request)
### Make the loss run request form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/loss-run-request) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free event vendor application form template
Source: https://faldaro.com/templates/event-vendor-application
Apply for a stall, with a booth fee the server computes. A free event vendor application template — edit any field, share a public link, workflow included.
## Event vendor application template
Apply for a stall, with a booth fee the server computes.
For markets, fairs and festivals. The booth fee is computed on the server from the size and power the vendor chose, so nobody can submit a price of their own; add a payment step to collect it at submit. Category is indexed so a busy organiser can review one kind of stall at a time.
[Use this template](https://faldaro.app/start/event-vendor-application) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [event registration](https://faldaro.com/use-cases/event-registration) — Registrations from attendees that take the payment and send the confirmation.
### What’s in the form
12 fields — every one editable once the template is yours.
- Business name *
- What you sell *
- Contact name *
- Email *
- Phone
- Website or social page
- Tell us about your stall *
- Photos of your stall or products
- Booth *
- Electricity? *
- Booth fee computed on the server
- Certificate of insurance
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Applied Approved Waitlisted Declined
- Approve — Applied → Approved
- Waitlist — Applied → Waitlisted
- Decline — Applied → Declined
- Approve from waitlist — Waitlisted → Approved
Questions
### The event vendor application template, answered
What picking this template does and does not commit you to.
**Is the event vendor application template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the event vendor application template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 12 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Applied” and moves through the included states — Applied, Approved, Waitlisted, Declined. Every state and move is editable before you publish.
**Who works out the calculated values?**
The server does. The Booth fee field is computed from the answers by the form’s own rules, so a browser can never fabricate it.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Event registration Tickets, dietary needs and a total the server works out.](https://faldaro.com/templates/event-registration) [Insurance quote calculator A business quote, priced on the server as people type.](https://faldaro.com/templates/insurance-quote) [Project request Propose a project and take it through review to a decision.](https://faldaro.com/templates/project-request)
### Make the event vendor application form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/event-vendor-application) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free insurance quote calculator form template
Source: https://faldaro.com/templates/insurance-quote
A business quote, priced on the server as people type. A free insurance quote calculator template — edit any field, share a public link, workflow included.
## Insurance quote calculator template
A business quote, priced on the server as people type.
An indicative premium from revenue, hazard class, headcount, limit and deductible — computed on the server, so an applicant can never submit a price of their own, and a public link shows the figure without ever showing the formula behind it. The rates are placeholders: replace them with your own before you publish.
[Use this template](https://faldaro.app/start/insurance-quote) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [insurance claims intake](https://faldaro.com/use-cases/insurance) — Claims from policyholders and brokers, with calculated estimates, approvals and a trail that survives a dispute.
### What’s in the form
10 fields — every one editable once the template is yours.
- Business name *
- Email *
- What the business does *
- Years in business *
- Annual revenue *
- Employees *
- Liability limit *
- Deductible *
- Estimated annual premium computed on the server
- Anything the underwriter should know
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Quote requested In underwriting Quoted Bound Declined
- Start underwriting — Quote requested → In underwriting
- Send quote — In underwriting → Quoted
- Decline — In underwriting → Declined
- Bind — Quoted → Bound
Questions
### The insurance quote calculator template, answered
What picking this template does and does not commit you to.
**Is the insurance quote calculator template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the insurance quote calculator template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 10 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Quote requested” and moves through the included states — Quote requested, In underwriting, Quoted, Bound, Declined. Every state and move is editable before you publish.
**Who works out the calculated values?**
The server does. The Estimated annual premium field is computed from the answers by the form’s own rules, so a browser can never fabricate it.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[First notice of loss (FNOL) Report a claim, then work it through to a decision.](https://faldaro.com/templates/first-notice-of-loss) [Certificate of insurance request Who needs a certificate, for whom, and by when.](https://faldaro.com/templates/certificate-of-insurance-request) [Loss run request Ask for an insured's loss history and track it to delivery.](https://faldaro.com/templates/loss-run-request)
### Make the insurance quote calculator form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/insurance-quote) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Free project request form template
Source: https://faldaro.com/templates/project-request
Propose a project and take it through review to a decision. A free project request template — edit any field, share a public link, workflow included.
## Project request template
Propose a project and take it through review to a decision.
A request that goes somewhere: the problem before the solution, priority and department indexed for the review meeting, and a workflow with a real "not now" — deferred work can come back for review instead of being rejected to make the list shorter.
[Use this template](https://faldaro.app/start/project-request) [Browse all templates](https://faldaro.com/templates)
Free on every plan. Opens in the builder as an editable draft — nothing is published until you say so.
Used for [client intake](https://faldaro.com/use-cases/client-intake) — From inquiry to a signed letter with a retainer behind it.
### What’s in the form
9 fields — every one editable once the template is yours.
- Your name *
- Team or department *
- Email *
- Project name *
- What problem does this solve? *
- Priority *
- Estimated budget
- Wanted by
- Briefs or supporting documents
Included workflow
### What happens after someone submits
A submission lands in the first state and moves through the rest — each move is a named, permissioned act, and every one of these states and moves is editable.
start: Submitted In review Approved Deferred Rejected
- Start review — Submitted → In review
- Approve — In review → Approved
- Defer — In review → Deferred
- Reject — In review → Rejected
- Back to review — Deferred → In review
Questions
### The project request template, answered
What picking this template does and does not commit you to.
**Is the project request template free?**
Yes — free on every plan. It opens in the builder as an editable draft in your own account, and nothing is published until you choose to publish it.
**Can I change the fields in the project request template?**
All of them. The template is an ordinary draft form: add, remove or reword any of its 9 fields, then publish when it reads right.
**What does the included workflow do?**
A submission lands in “Submitted” and moves through the included states — Submitted, In review, Approved, Deferred, Rejected. Every state and move is editable before you publish.
**How do people fill it in?**
Publish the form and share its public link — submitters need no account and are never a paid seat. Rotate the link at any time to revoke it.
### More templates
Each one opens the same way: an editable draft in your own account, free on any plan.
[Contact us A short enquiry laid out across two rows.](https://faldaro.com/templates/contact) [Support request A ticket that moves through triage to resolved.](https://faldaro.com/templates/support-request) [Event registration Tickets, dietary needs and a total the server works out.](https://faldaro.com/templates/event-registration)
### Make the project request form yours
One click loads it into the builder as a draft in your own account — edit anything, then publish a public link when it reads right.
[Use this template](https://faldaro.app/start/project-request) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Typeform, Jotform & Formstack alternatives
Source: https://faldaro.com/alternatives
Honest comparisons with Typeform, Jotform, Formstack, Fillout and more: what each is good at, and when Faldaro fits intake from outside better.
## Choosing an intake platform, honestly
Comparison pages are usually feature checkboxes that rot the day a competitor ships and read as trash talk the day before. These follow two rules instead: the named tool gets credit for what it is genuinely good at — including when it is the better choice — and every claim about Faldaro is a mechanism you can check in behaviour, not an adjective.
- [Typeform alternative For when responses are metered against you and the form starts a process.](https://faldaro.com/alternatives/typeform)
- [Jotform alternative Not a longer feature list — a different answer to where the truth lives.](https://faldaro.com/alternatives/jotform)
- [Google Forms alternative For the day the responses sheet quietly becomes a system of record.](https://faldaro.com/alternatives/google-forms)
- [Microsoft Forms alternative For forms that leave the tenant — strangers, files, payments, follow-through.](https://faldaro.com/alternatives/microsoft-forms)
- [SurveyMonkey alternative For when a response stops being data to analyze and starts being work to do.](https://faldaro.com/alternatives/surveymonkey)
- [Formstack alternative For intake from outside the company, without a licence for every participant.](https://faldaro.com/alternatives/formstack)
- [Fillout alternative For when the submission needs an owner, a state and a deadline — not another layer of the stack.](https://faldaro.com/alternatives/fillout)
- [Anvil alternative For the team that runs the intake itself, rather than the developers building it into a product.](https://faldaro.com/alternatives/anvil)
- [Cognito Forms alternative For when the calculation is a price someone will be held to, and the entry is work with a state.](https://faldaro.com/alternatives/cognito-forms)
- [Tally alternative For when each response has become work to review, approve and answer.](https://faldaro.com/alternatives/tally)
- [Pipefy alternative For when the front door matters as much as the pipe behind it.](https://faldaro.com/alternatives/pipefy)
- [DocuSign PowerForms alternative For when the signature is one step of the intake, not the whole of it.](https://faldaro.com/alternatives/docusign-powerforms)
- [Formstack Documents alternative For documents that come from the submission itself, generated where the work moves.](https://faldaro.com/alternatives/formstack-documents)
- [Form builders and work tools in general The category-level comparison: the mechanisms that work differently here, each checkable in behaviour, plus an honest sorting of which tool actually fits.](https://faldaro.com/why-faldaro)
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Typeform alternative with workflows & payments
Source: https://faldaro.com/alternatives/typeform
A Typeform alternative for forms that start a process: submissions never capped or billed by count, approval workflows, Stripe payments and generated PDFs.
## The Typeform alternative for forms that start a process
Typeform is genuinely good at what it is for: a conversational, one-question-at-a-time survey that people enjoy filling in. If a beautiful survey is the whole job, use it. Teams come here when the form is a door rather than the whole job — when responses from the outside world are metered against them, and working what arrives is the part they actually run.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The meter
Response-metered plans make a busy month a billing event, and a cap reached mid-campaign is a form that stops collecting. Faldaro’s promise is the inverse: submissions are never capped and never billed by count — the free plan includes ten thousand a month, and no paid plan has a number at all.
#### The results table
A survey tool ends at the table of answers; working them — triage, approval, follow-up — happens somewhere else, after an export or a Zap. In Faldaro the submission is a record with a state machine: moving it is a separate, permissioned act from editing it, and every move can notify, generate documents or call your systems.
#### The numbers
A score or a total computed in the browser is whatever number arrived with the submission. Faldaro recomputes every calculated value on the server, on every save and every read — a browser cannot fabricate a total, and a price cannot be tampered into a discount.
The full category-level comparison — eleven mechanisms, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro).
Switching
### Moving is an afternoon, not a project
The form rebuilds itself from a description or a PDF, and your response history arrives as records — not attachments.
#### 1 Rebuild the form
Describe it to the AI assistant and it builds a working, editable draft — or upload the PDF you were replicating and the agent turns that into one. Logic and calculations are wired in the same conversation, and nothing publishes until you say so.
#### 2 Bring the history
Export your responses as CSV and import them: columns map to your fields by header, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
#### 3 Share the new link
Public links are tokenized, so the form id cannot be guessed or walked — and a link that spreads too far is revoked by rotating it, not by taking the form down.
### Fair questions
**Does Faldaro have one-question-at-a-time forms?**
Faldaro public forms can be paged — a wizard with a step counter, one section at a time — but the animated single-question experience is Typeform’s speciality and we will not pretend to match it. If that experience is why you chose Typeform and the answers do not need working afterwards, keep it. The trade Faldaro offers is everything that surrounds the form: workflow, documents, payments and an engine the browser cannot lie to.
**Do you meter responses at all?**
Submissions are never capped and never billed by count, on any plan. The free plan includes ten thousand a month and every paid plan is unlimited. The meters that do exist — storage, email sends, AI credits — track our own costs rather than your audience, and the pricing page states every one of them.
**Can I import my Typeform responses?**
Yes. Export them as CSV from Typeform and import the file: columns map to your fields by header, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations, no freshly minted reference numbers.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Stop counting responses
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Jotform alternative for approval workflows
Source: https://faldaro.com/alternatives/jotform
A Jotform alternative for approval workflows: approvers decide by email with no account, totals are computed on the server, and every decision is on the record.
## The Jotform alternative for approval workflows where the server owns the truth
Jotform’s breadth is real — templates, widgets, approvals, PDFs, payments; few tools cover as much surface, and this page will not pretend otherwise. The comparison worth making is not a longer feature list, because side by side the lists look alike. It is about where the truth lives when a number, a document or an approval is disputed — and whether the intake was built for the stranger who submits it or for the account that owns it.
Underneath the feature list
### Six differences in where the truth lives
Each one is a property of the architecture rather than a feature on a list — and each is checkable in behaviour before you commit anything.
#### A calculated total
In Faldaro, every calculated value is recomputed on the server on every save and every read. A browser cannot fabricate a total, because nothing it sends is trusted as one — the number in the record is the engine’s, not the page’s.
#### A payment
The server prices the submitted answers itself; the payment request has no field an amount could even ride in. Anything sold — a file, a ticket — is released only once the processor confirms settlement, never on the browser’s say-so.
#### A published form
Publishing creates an immutable version, and every submission keeps the exact definition it was filled against, forever. Editing a live form can never reinterpret the answers already collected under it.
#### The audit trail
Append-only because the database refuses updates and deletes on it — not because the application promises to behave. That distinction is what a dispute, an auditor or a regulator actually turns on.
#### A change you are afraid of
Named regression cases re-run through the real engine before you publish: if a change would move a value someone pinned down, you find out before your submitters do.
#### A partner organization
Not a shared login — an organization tree with isolation enforced by row-level security in PostgreSQL. Share a form with a partner and their submissions stay theirs, yours stay yours, and the database itself is what says so.
Every mechanism above is spelled out in full on the [security page](https://faldaro.com/security), and the category-wide comparison lives on [why Faldaro](https://faldaro.com/why-faldaro).
Switching
### Rebuild from the PDF you already print
Many forms began life as a paper or PDF form. That document is the fastest way back out: the agent rebuilds it as a draft, and your history follows as records.
#### 1 Recreate the form
Upload the PDF the form was built to replace and the agent turns it into a working, editable draft — or describe the form and it builds one. Logic, calculations and the workflow are wired in the same conversation, and nothing publishes until you say so.
#### 2 Import the history
A CSV export of your submissions imports directly: columns map to your fields by header, and every imported record is marked as imported in the audit log. Notifications, integrations and reference numbers stay quiet — history arrives as records, not as events.
#### 3 Point the world at the new link
Public links are tokenized and rotatable, payment collection works from day one, and the workflow starts carrying new submissions immediately — the imported ones sit in whatever state you gave them.
### Fair questions
**Jotform has approvals, PDFs and payments too. What is actually different?**
On a feature list, less than either vendor would like to admit — which is why this page does not argue the list. The difference is where the truth lives: totals recomputed server-side rather than trusted from the page, payment amounts priced from the answers rather than sent by the browser, published versions that are immutable, and an audit log the database itself refuses to rewrite. Those are properties of the architecture, and they are what matters the day a number or an approval is disputed.
**How does the pricing shape differ?**
Form-builder tiers usually meter the artifacts — how many forms you may keep, how many submissions arrive in a month. Faldaro meters neither: unlimited forms on every plan including the free one, and submissions never capped or billed by count. You pay for your team’s seats and for capabilities, never for your audience. Compare the two pricing pages directly; ours states every number the deployment actually enforces.
**Does Faldaro do e-signatures?**
Yes, on the Team plan and above. A workflow move requests signatures: each signer gets their own tokenized link, the document is frozen and fingerprinted before anyone signs, the evidence — what was shown, what happened, when, from where — is recorded in rows the application role cannot delete, and the signed PDF carries a certificate page.
**Can I bring my existing submissions across?**
Yes. Export them as CSV and import the file: columns map to your fields by header, workflow states come across where you have mapped them, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations, no freshly minted reference numbers.
### Put the truth on the server
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Google Forms alternative with payments & workflow
Source: https://faldaro.com/alternatives/google-forms
Outgrown Google Forms? Faldaro is free to start — unlimited forms, 10,000 submissions a month — and adds server-side calculations, workflows, payments and PDFs.
## The Google Forms alternative for when the sheet becomes the system
Google Forms is free, instant and already where your documents are — for a quick questionnaire it is the right tool, and this page will not pretend otherwise. Teams outgrow it the day the outside world starts arriving through it and the responses sheet quietly becomes a system of record: the thing you triage in, approve from and chase people through. That is a job a spreadsheet never signed up for.
The moment it stops fitting
### Four jobs a responses sheet was never built for
Each one is answered by a mechanism you can check in behaviour — not a feature name on a list.
#### The sheet becomes the workflow
A status column someone forgets to update, colour-coded rows, a tab per teammate — the process lives in conventions anyone can break. In Faldaro a submission carries a real state machine: who may move it is permissioned, moves fire notifications and documents, deadlines escalate by themselves, and an append-only audit log records who did what.
#### The formulas live one edit from wrong
Sheet formulas compute over cells anyone with the sheet can touch, and one dragged range rewrites history silently. Faldaro recomputes every calculated value on the server, on every save and every read — and published form versions are immutable, so old submissions are never reinterpreted by new questions.
#### Money has nowhere to go
Collecting payment beside a free form means a payment link pasted into the confirmation and a human reconciling two lists. Faldaro prices the submitted answers on the server, collects through Stripe, and releases anything sold only when the processor confirms the money arrived.
#### The open internet is not a classroom
A form for strangers needs hardening a quick questionnaire never did: Faldaro’s public links are unguessable tokens you can rotate, submissions are throttled and can require a captcha, respondents never need an account for anything — file uploads included — and one form serves every language from a translation table.
The category-wide version of this comparison — eleven mechanisms, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro). Staying on Google Forms for now? The guide to [Google Forms approval workflows](https://faldaro.com/guides/google-forms-approval-workflow) covers the status-column, Apps Script and add-on approaches, and where each runs out, and the guide to [Google Forms calculated fields](https://faldaro.com/guides/google-forms-calculated-fields) does the same for totals and quotes.
Starting is also free
### Moving costs nothing to try
Describe your form to the AI assistant and it builds a working draft — or upload a PDF and the agent rebuilds it as one. Download your responses sheet as CSV and import it; history arrives as records, marked as imported, replaying nothing. The free plan needs no card.
### Fair questions
**Is Faldaro free like Google Forms?**
The free plan is free forever: unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans add seats, remove the platform fee and the “Powered by Faldaro” line, and unlock integrations, e-signatures and more.
**Do people filling my form need an account?**
No. Public forms are anonymous by design — no sign-in for anything, including file uploads. The link itself is the only credential: an unguessable token you can rotate if it spreads further than you meant, without taking the form down.
**Can I import the responses I already have?**
Yes. Download your responses sheet as CSV and import it: columns map to your fields by header, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations — so your history arrives quietly, as records.
**When is Google Forms still the right choice?**
Often. A quick internal questionnaire, a poll, a sign-up sheet whose answers will be read once and never worked — a free tool that lives where your documents already live is exactly right for that, and moving it anywhere would be ceremony. The time to move is when the responses have a lifecycle: someone approves them, chases them, charges for them, or answers for them later.
### Retire the responses sheet
Free forever: unlimited forms, ten thousand submissions a month, and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Microsoft Forms alternative for external forms
Source: https://faldaro.com/alternatives/microsoft-forms
A Microsoft Forms alternative for forms that leave the tenant: public links, uploads with no sign-in, server-priced Stripe payments, approvals and PDFs.
## The Microsoft Forms alternative for forms that leave the tenant
Microsoft Forms has one unbeatable feature: it is already there. Every Microsoft 365 tenant has it, it costs nothing extra, and for a quiz or a pulse survey among people who are already signed in, using anything else would be ceremony. Teams come here when the form faces outward — strangers, files, payments — and working what arrives is the part they actually run.
The tenant boundary
### Four places the walls show
Each one is a difference in mechanism, checkable in behaviour before you commit anything — not a feature name on a list.
#### The form has to leave the tenant
Microsoft Forms is built inward: inside the organization it is frictionless, and the further outside you go the more you feel it — file upload questions, for one, require the respondent to sign in to your tenant. Faldaro’s public surface is anonymous by design: the link is an unguessable token you can rotate, nobody needs an account for anything — uploads included — and one form serves every language from a translation table.
#### Acting on a response means wiring it yourself
The results live in the responses view and Excel; a process around them — routing, approval, escalation — is a Power Automate flow someone builds and maintains beside the form. In Faldaro the process is part of the record: a state machine where moving a submission is a separate, permissioned act from editing it, moves fire notifications and generate documents, deadlines escalate by themselves, and an append-only audit log records who did what.
#### The workbook becomes the system of record
Once responses are triaged in a spreadsheet, the truth lives in cells anyone with the file can touch. Faldaro recomputes every calculated value on the server, on every save and every read, and published form versions are immutable — a browser cannot fabricate a total, and old submissions are never reinterpreted by new questions.
#### Money has nowhere to go
Collecting payment beside the form means a link pasted into the confirmation and a human reconciling two lists. Faldaro prices the submitted answers on the server, collects through Stripe, and releases anything sold — a file, a ticket — only when the processor confirms the money arrived.
The category-wide version of this comparison — eleven mechanisms, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro). Staying on Microsoft Forms for now? The guide to [Microsoft Forms approvals with external users](https://faldaro.com/guides/microsoft-forms-approval-workflow) walks through the Power Automate flow step by step, and where the tenant boundary stops it.
Switching
### Moving costs nothing to try
Describe your form to the AI assistant and it builds a working draft — or upload the PDF it was replacing and the agent rebuilds it as one. Export your responses to Excel, save as CSV and import; history arrives as records, marked as imported, replaying nothing. The free plan needs no card.
### Fair questions
**When is Microsoft Forms still the right choice?**
Often. A pulse survey, an internal poll, an auto-graded quiz for people who are already signed in to your tenant — a tool that is included in Microsoft 365, needs no new vendor and drops results where staff already work is exactly right for that. The time to move is when the form faces outward or the responses have a lifecycle: strangers fill it in, files come with it, money changes hands, or someone approves, chases and answers for each response afterwards.
**Do people filling a Faldaro form need an account?**
No. Public forms are anonymous by design — no sign-in for anything, including file uploads. The link itself is the only credential: an unguessable token you can rotate if it spreads further than you meant, without taking the form down. Anonymous submission is throttled and can require a captcha, because a form for strangers needs hardening a tenant-internal one never did.
**Can I bring the responses I already have?**
Yes. Export your responses to Excel, save them as CSV and import the file: columns map to your fields by header, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations, no freshly minted reference numbers — so history arrives quietly, as records.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Take the form outside
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# SurveyMonkey alternative for operational forms
Source: https://faldaro.com/alternatives/surveymonkey
A SurveyMonkey alternative for when a response is work, not a data point: submissions never metered, approval workflows, server-side calculations and payments.
## The SurveyMonkey alternative for when a response is work, not data
SurveyMonkey is a research instrument, and a good one: methodology-grade questions, panels, benchmarks, analysis. If the job is finding out what a population thinks, use it. Teams come here when the job changes shape — when each response is not a data point to aggregate but a piece of work someone outside the company sent you: to route, approve, charge for and answer for.
Research vs. operations
### Four differences in mechanism
Not adjectives — each one is checkable in behaviour before you commit anything.
#### A response is read; a submission is worked
A survey response earns its keep in aggregate — a chart, a cross-tab, a trend line. An operational submission is handled one at a time: someone approves it, chases it, charges for it, answers for it later. In Faldaro each submission is a record with a state machine — moving it is a separate, permissioned act from editing it, every move can notify, generate documents or call your systems, and deadlines escalate by themselves.
#### The meter
Response-metered plans make a busy quarter a billing event, and a cap reached mid-collection is a form that stops collecting. Faldaro’s promise is the inverse: submissions are never capped and never billed by count — the free plan includes ten thousand a month, and no paid plan has a number at all. You pay for seats and capabilities, never for your audience.
#### The numbers
A score or a quote computed in the page is whatever number arrived with the submission. Faldaro recomputes every calculated value on the server, on every save and every read — a browser cannot fabricate a total — and published versions are immutable, so old submissions are never reinterpreted by new questions.
#### What happens after submit
When a form collects money, files or commitments, the follow-through is the product: server-priced Stripe payments with delivery gated on settlement, generated PDFs, e-signatures requested by a workflow move, and an append-only audit log the database itself refuses to rewrite.
The full category-level comparison — eleven mechanisms, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro).
Switching
### Moving is an afternoon, not a project
The form rebuilds itself from a description or a PDF, and your response history arrives as records — not attachments.
#### 1 Rebuild the form
Describe it to the AI assistant and it builds a working, editable draft — or upload the PDF you were replicating and the agent turns that into one. Logic and calculations are wired in the same conversation, and nothing publishes until you say so.
#### 2 Bring the history
Export your responses as CSV and import them: columns map to your fields by header, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
#### 3 Share the new link
Public links are tokenized, so the form id cannot be guessed or walked — and a link that spreads too far is revoked by rotating it, not by taking the form down.
### Fair questions
**Does Faldaro do survey analytics?**
It has real reporting — saved reports with grouping, aggregation and date buckets, charts, CSV export, and AI-generated insights over a form’s submissions (trends, outliers, correlations). What it does not have is the research apparatus: respondent panels, benchmarks, a question bank built on survey methodology. If statistically defensible survey research is the job, SurveyMonkey is the right tool and we will not pretend otherwise. Faldaro is for when each response is work to be done, not a data point to be aggregated.
**Do you meter responses at all?**
Submissions are never capped and never billed by count, on any plan. The free plan includes ten thousand a month and every paid plan is unlimited. The meters that do exist — storage, email sends, AI credits — track our own costs rather than your audience, and the pricing page states every one of them.
**Can I import my SurveyMonkey responses?**
Yes. Export them as CSV and import the file: columns map to your fields by header, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations, no freshly minted reference numbers.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Stop counting responses
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Formstack alternative: docs, e-sign & approvals
Source: https://faldaro.com/alternatives/formstack
A Formstack alternative where forms, generated documents, e-signatures and approvals are one record — and clients, applicants and approvers are never licences.
## The Formstack alternative with documents, e-signatures and approvals in one record
Formstack is genuinely good at what it is for: an enterprise suite of forms, documents and signatures run by an IT team and wired into the systems a large company already owns. If your process lives inside the company and everyone in it holds a licence, it may well be the right choice. Teams come here when the participants are outside — clients, applicants, brokers, vendors — and paying a seat for each of them is the wrong shape for the work.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The licence
A suite priced by the people who use it treats every reviewer, approver and partner as a seat — right for an IT-run internal process, the wrong shape for intake where the participants are outside the company. Faldaro prices the team and never the audience: submitters, approvers deciding from their inbox, signers and portal users are never seats, and submissions are never billed by count.
#### The suite
Forms, documents and signatures sold as separate products connected by workflow means three places for the truth to live and an integration between each. In Faldaro they are one record: the document generates from the submission when its state changes, the signature request freezes and fingerprints that exact document, and the outcome lands on the record as a value a transition can gate on.
#### The front door
An enterprise suite is built inward-facing first; the public form is one deployment target among many. Faldaro’s public surface is the most designed part of the product: tokenized, revocable links; every refusal an identical not-found; throttles and captcha; a tracking link per record; translations served one locale at a time so the tables never ship.
The full category-level comparison — every mechanism, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro).
Switching
### Moving is an afternoon, not a project
The form rebuilds itself from a description or a PDF, and your submission history arrives as records — states and reference numbers included.
#### 1 Rebuild the form
Describe it to the AI assistant and it builds a working, editable draft — or upload the PDF the process runs on and the agent turns that into one. Logic and calculations are wired in the same conversation, and nothing publishes until you say so.
#### 2 Bring the history
Export your submissions as CSV and import them: columns map to your fields by header, reference numbers survive the trip, workflow states come across, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
#### 3 Open the door
Issue the public link and send it to anyone. Public links are tokenized, so the form id cannot be guessed or walked — and a link that spreads too far is revoked by rotating it, not by taking the form down.
### Fair questions
**Our procurement runs a security review. What can you show?**
The security page, mechanism by mechanism: tenant isolation enforced by PostgreSQL row-level security with the service refusing to start if the policies would not apply; an audit log that is append-only because the database revoked update and delete from the application role; every calculated value evaluated on the server; author-supplied patterns and report queries run under a budget. Each claim is checkable in behaviour, and security questionnaires are answered directly, in writing, from the same register — nothing is claimed that paper does not back.
**We run Salesforce. Is Faldaro a fit?**
Faldaro is not a Salesforce forms product and will not pretend to be one. It connects outward: signed webhooks on every transition, Zapier, and an API with keys scoped to explicit privileges. If your process lives inside Salesforce and the form is a data-entry surface for it, a Salesforce-native tool is the honest choice. If the process starts with outsiders and Salesforce is where the outcome eventually lands, the webhook is the seam.
**Can approvers, partners and clients work without licences?**
Yes — that is the shape of the product. Approvers decide from an emailed link with no account. Signers sign from a link, with the document frozen and fingerprinted before it is shown. Submitters track their own record through a status link or a portal reached by a magic link mailed to their own address. Partner firms are organizations of their own: share a form or folder with them, their submissions stay theirs, and only you can change the form.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Stop licensing your audience
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan — and nobody who submits, approves or signs is ever a seat.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Fillout alternative with workflow and records
Source: https://faldaro.com/alternatives/fillout
A Fillout alternative for when a submission needs an owner: a record with a state, a deadline, inbox approvals and a tracking link.
## The Fillout alternative for when the submission needs an owner
Fillout is genuinely good at what it is for: a fast, flexible form builder that slots into a no-code stack — the database, the automation and the portal are a connection away. If the form is one layer of a stack you already run and enjoy running, it is a fine choice. Teams come here when the submission itself needs a state, an owner and a deadline — and the stack is the part they are tired of maintaining.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The stack
A form layer over a no-code stack is at its best when the database, the automation tool and the portal are other products — and the truth about a submission lives in whichever one wrote last. In Faldaro the record is the truth: its state, its computed values, its documents, its payment and its audit trail are one row’s history, and every move is a permissioned act the database records.
#### The after
A submission that becomes a row in someone else’s table is worked by whatever that table can do. A Faldaro submission is a record with an owner, a state, a deadline that fires its own transition, an approval taken from an inbox and a tracking link the submitter watches — with nothing to wire between them.
#### The numbers
A score or a total computed in the browser is whatever number arrived with the submission. Faldaro recomputes every calculated value on the server, on every save and every read — a browser cannot fabricate a total, a price cannot be tampered into a discount, and a payment request has no field an amount could ride in.
The full category-level comparison — every mechanism, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro).
Switching
### Moving is an afternoon, not a project
The form rebuilds itself from a description or a PDF, and your response history arrives as records — not attachments.
#### 1 Rebuild the form
Describe it to the AI assistant and it builds a working, editable draft — or upload the PDF you were replicating and the agent turns that into one. Logic and calculations are wired in the same conversation, and nothing publishes until you say so.
#### 2 Bring the history
Export your responses as CSV and import them: columns map to your fields by header, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
#### 3 Share the new link
Public links are tokenized, so the form id cannot be guessed or walked — and a link that spreads too far is revoked by rotating it, not by taking the form down.
### Fair questions
**We like Fillout’s builder. Is Faldaro’s as good?**
Fillout’s builder is excellent and we will not claim to out-polish it. Faldaro’s builder is a canvas that speaks the same field vocabulary the engine validates, an inspector driven by what each field can actually do, named test cases that lock the logic before you publish, and an agent that drafts the whole form from a sentence or a PDF. The trade Faldaro offers is everything the builder connects to: the record, the workflow, the documents, the payment and the trail.
**Do you meter responses at all?**
Submissions are never capped and never billed by count, on any plan. The free plan includes ten thousand a month and every paid plan is unlimited. The meters that do exist — storage, email sends, AI credits — track our own costs rather than your audience, and the pricing page states every one of them.
**Our database is Airtable or Notion. Can Faldaro feed it?**
Yes — signed webhooks on every transition, Zapier, and an API with keys scoped to explicit privileges carry the record outward. The honest question is which system is the record. If the database stays your system of record and the form is its front end, keep the stack. Faldaro is for when the submission itself should be the record: worked where it landed, with the state, the documents and the audit trail on the same row.
**Can I import my Fillout responses?**
Yes. Export them as CSV and import the file: columns map to your fields by header, and every imported record is marked as imported in the audit log. The import replays nothing — no notifications, no integrations, no freshly minted reference numbers.
### Give the submission an owner
The free plan includes unlimited forms, ten thousand submissions a month and the same engine, workflows and records as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Anvil alternative for teams who run the intake
Source: https://faldaro.com/alternatives/anvil
An Anvil alternative for teams who run the intake: the PDF you already use becomes the form and the filled document, with workflow and audit around it.
## The Anvil alternative for teams who run the intake themselves
Anvil is genuinely good at what it is for: a developer’s document platform — fill PDFs, generate documents, collect signatures, and embed the whole flow in your own product through an API. If you are building software and documents are a feature of it, it is a strong choice. Teams come here when nobody is building software: the claims desk, the admissions office or the operations lead configures the intake in the browser, and the documents are one part of the record it produces.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### Who runs it
A document API is built for developers embedding document workflows into their own product. Faldaro is built for the team that runs the intake — the claims desk, the admissions office, the operations lead — who configure the form, the rules and the workflow in the browser and change them the day the process changes, with no release in between.
#### The PDF, both ways
Drop the PDF you make people send you and it comes back as a working form. Publish it, and the document generated when a record changes state can be a facsimile of that same PDF — its exact layout as the template, filled from the record. The visitor fills a form; the file that lands in the folder is the form your industry already requires.
#### After the document
A filled, signed document is where a document platform stops. In Faldaro it is one state of a record that also priced the answers on the server, routed itself, requested its approval by email, took a payment and keeps an audit trail the database refuses to rewrite.
The full category-level comparison — every mechanism, side by side — is on the [why Faldaro page](https://faldaro.com/why-faldaro).
Switching
### The PDF you already have is the whole migration
It becomes the form, then it becomes the document template — and the process around it is configured, not built.
#### 1 Bring the PDF
Upload the document you fill today and the agent turns it into a working, editable form — a fillable PDF’s own field definitions are read as fields. Or describe the process and it builds one. Nothing publishes until you say so.
#### 2 Keep the layout
The same PDF becomes the document template: its pages reproduced as the layout, merged values placed where the boxes were, wrapping and growing to fit what a submitter typed. Anything the conversion had to simplify is reported as a note, never dropped in silence.
#### 3 Open the door
Issue the public link and send it to anyone — no account on their side, never a seat on yours. The first submission arrives as a record: values the server computed, a state to move it through, and the filled document generated the moment its state changes.
### Fair questions
**Is there an API?**
Yes — API keys with an explicit privilege grant on every plan, a versioned evaluate-and-submit API, signed webhooks on every transition, Zapier, and a hosted MCP server so a model can drive the account with exactly the key’s permissions. It is not a document-generation API for your own product; it is the way your systems talk to your intake.
**Can Faldaro fill a PDF I upload?**
Yes. The facsimile engine turns each page into an editable template that keeps the original layout, and merged values are placed, wrapped and fitted where the boxes were — with the page’s own footer never pushed off the edge. Edges are stated honestly: some PDF features simplify in conversion (gradients, certain transparency effects, glyph-outline text), and every simplification is reported as a conversion note rather than silently changed. Typography comes from a bundled catalogue of faces, never from fonts extracted out of the PDF.
**Do you charge per document or per signature?**
No. Generated documents and signature requests are not metered. The meters that exist — storage, email sends, AI credits — track our own costs, and the pricing page states each of them. Nothing is ever billed as overage.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Run the intake, not the integration
The free plan includes unlimited forms, ten thousand submissions a month, generated PDFs and the same engine as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Cognito Forms alternative for priced intake
Source: https://faldaro.com/alternatives/cognito-forms
A Cognito Forms alternative for intake from outside: formulas evaluated on the server, records with workflow states, and partner firms that are never seats.
## The Cognito Forms alternative for intake that is priced, owned and worked
Cognito Forms is genuinely good at what it is for: capable calculations, repeating sections and tables, entry views, payments and document generation, in a builder that non-developers can drive. If your form collects and calculates and a person reads the result, it may well be the right choice. Teams come here when the calculated figure is a price someone will be held to, and each entry is a piece of work that needs an owner, a state and a deadline.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The calculation
Cognito Forms is rightly known for calculations. The question worth asking of any calculating form is where the answer is decided. In Faldaro every formula is re-run on the server on every save, from the declared fields only, and the result is stored apart from what was typed — a browser can display a total, but it can never supply one. The public page never receives the formula text at all.
#### The entry becomes work
Once an entry arrives, somebody has to own it. Faldaro makes every submission a record with a workflow state: named, permissioned moves between states, deadlines that fire their own transition, approvals decided from an emailed link with no account, and a status link the submitter can check without asking you.
#### The plan ladder
Cognito’s plans step up by monthly entries and by users. Faldaro prices the team and never the audience: no paid plan meters submissions, submitters and approvers are never seats, and partner firms are organizations of their own — share a form with a brokerage and its people work through it on its own account.
How the engine decides a value is in the [formulas guide](https://faldaro.com/docs/formulas); what happens after submit is on the [workflows page](https://faldaro.com/features/workflows); and the category-level comparison is on [why Faldaro](https://faldaro.com/why-faldaro).
Where the number lives
### Two columns, never merged
What a submitter typed and what the server computed are stored separately. The record shows both, and a dispute is settled by reading rather than reconstructing.
#### Typed input is cut to the form
Keys the form does not declare are dropped before evaluation, so a crafted request cannot slip in a value that a rule or a workflow guard then trusts.
#### Recorded values stay recorded
A reference number is allocated once and never renumbered; a payment status is written by the payment path, not by the submitter — and a transition can wait on either.
Start from a form that already calculates: the [expense claim template](https://faldaro.com/templates/expense-claim) totals itself on the server and ships with an approval workflow.
Switching
### Moving is an afternoon, not a project
The form rebuilds itself from a description or a PDF, your entries arrive as records, and test cases prove the prices before anyone else sees them.
#### 1 Rebuild the form
Describe it to the AI assistant, or hand it the PDF the process runs on, and it builds an editable draft — fields, logic and calculations together. Nothing publishes until you say so.
#### 2 Bring the entries
Export your entries as CSV and import them: columns map to your fields by header, workflow states and reference numbers come across, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
#### 3 Pin the numbers
On Team and above, write test cases for the prices that matter — these answers must produce this total — and run them against the draft before every publish. A change that would move a figure somebody pinned down says so before it goes live.
### Fair questions
**Are Faldaro’s calculations as capable as Cognito’s?**
They are deliberately a closed language: arithmetic, comparison and a fixed set of functions — numeric ones, collection functions for checkbox groups, tables and lists, and a blank check — evaluated by the server, never by a script engine. That covers pricing, scoring, totals and eligibility. If a form depends on something outside that set, try it on the free plan before moving; the builder tells you at publish time if an expression will not parse.
**Can people outside the company fill forms without an account?**
Yes. A public link carries an unguessable token rather than the form id, so the range cannot be walked, and a link that spreads too far is revoked by rotating it. Submitters never need an account, never become seats, and can follow their own record through a status link.
**Can partner firms submit through our forms?**
Yes — share a form or a whole folder with another organization. Their submissions belong to them and are isolated by row-level security in PostgreSQL, and only you can change the form. Sharing is refused rather than half-honoured at any level the platform cannot enforce.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. Paid plans remove the fee and the “Powered by Faldaro” line, and add seats, integrations, e-signatures and more — the pricing page lists exactly what each tier grants.
### Let the server keep the numbers
The free plan includes unlimited forms, ten thousand submissions a month and the same engine as every paid plan — and nobody who submits or approves is ever a seat.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Tally alternative with workflows & approvals
Source: https://faldaro.com/alternatives/tally
A Tally alternative for when responses become work: each submission a record with a workflow, approvals by email, generated PDFs and a status link.
## The Tally alternative for when responses become work
Tally is genuinely good at what it is for: a form you build like writing a document, a free plan with unlimited forms and submissions, calculations, payments and signatures included, and responses sent straight into Notion, Sheets or Airtable. If that is the whole job, stay — it is hard to beat. Teams come here when each response has become a piece of work: something to review, approve, answer with a document, and track until the person who sent it has their answer.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The work happens somewhere else
Tally collects beautifully and hands each response to the tool you connect — a Notion database, a sheet, an Airtable base — where the work then happens. Faldaro keeps the work on the response itself: every submission is a record with a workflow state, named moves that say who may take them, deadlines that fire their own transition, and an audit log of every step.
#### Someone has to approve it
When a response needs a yes before anything happens — a request, an application, a quote — Faldaro emails each approver their own approve/decline link, with no account and only the fields you chose to show. The verdict moves the record, and a later step can wait on it.
#### The submitter wants to know where it is
A thank-you page ends the conversation. Faldaro hands the submitter a status link that shows the stage their submission has reached — never the answers or your notes — and a no-account portal where they can see their own submissions, so “any update?” emails stop.
How the steps work is on the [workflows](https://faldaro.com/features/workflows) and [approvals](https://faldaro.com/features/approvals) pages; what the submitter sees is on [records and status links](https://faldaro.com/features/records).
From the stack you built
### Tally plus a database, mapped
Most teams who outgrow a form-into-database setup have rebuilt a workflow out of columns and automations. Here is where each piece lands.
#### A status column in Notion → a workflow
States and the moves between them are drawn as a diagram, each move can require a privilege, and a move into a final state is final. Nobody drags a card into Approved who was not allowed to.
#### An automation per step → actions on moves
A move sends the email, generates the PDF from your template, requests the e-signature or the payment, or creates the next form’s record — configured once on the workflow, not wired through a chain of integrations.
#### A total in a formula column → a value the server owns
Formulas run on the server on every save and the result is stored apart from what was typed, so the figure on the record is one nobody could have edited on the way in. A payment is priced by the same engine.
#### A shared database → partners as organizations
Share a form with a partner organization and its people submit through it on their own account; their submissions are isolated from yours and each other by the database, and only you can change the form.
Start from a form that already has its workflow: the [project request](https://faldaro.com/templates/project-request), [expense claim](https://faldaro.com/templates/expense-claim) and [job application](https://faldaro.com/templates/job-application) templates each ship with one.
### Fair questions
**Is Faldaro cheaper than Tally?**
No, and it is not trying to be. Tally’s free plan is one of the most generous in forms, and its paid plans are priced per account with the team included. If you collect responses and work them in another tool, Tally is very likely the better choice. Faldaro’s free plan covers the builder, workflows, approvals, status links and PDF documents; its paid plans are for teams whose responses have become work.
**Does Faldaro have a Notion integration?**
Not a native one. Faldaro connects outward through signed webhooks, Zapier and an API with keys scoped to explicit privileges — and the point of the switch is usually that the record, its state and its paperwork live in one place rather than being copied into a database somewhere else.
**Is the Faldaro editor like Tally’s?**
No — Tally’s type-anywhere, document-style editor is distinctive, and Faldaro’s builder is a canvas of fields with an inspector. You can skip most of it: describe the form to the AI assistant, or hand it a PDF, and it builds an editable draft.
**Can I bring my existing responses?**
Yes. Export them from Tally as CSV and import them: columns map to your fields by header, and every imported record is marked as imported in the audit log. Nothing replays — no notifications fire, no integrations trigger.
### Keep the work with the response
The free plan includes the builder, workflows, approvals by email and status links — and nobody who submits or approves is ever a seat.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Pipefy alternative with a first-class front door
Source: https://faldaro.com/alternatives/pipefy
A Pipefy alternative for teams whose process starts outside: a hardened public form, server-priced rules, tracking links and partner firms as organizations.
## The Pipefy alternative for intake that starts outside
Pipefy is genuinely good at what it is for: orchestrating internal processes — finance, HR, procurement, IT — through no-code pipes, automations, portals and AI agents, across a whole company. If the process is the product and the form is how work enters it, it may well be the right choice. Teams come here when the front door is the hard part: the people sending work are strangers, the form carries a price, and partner firms need to work through it without becoming users of your account.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The front door
A process platform starts from the pipe and treats the form as the way a card gets created. Faldaro starts from the other end: the public form is the most designed part of the product — tokenized, revocable links; every refusal an identical not-found; throttles and an optional captcha; translations served one locale at a time; a tracking link per record.
#### The price inside the form
When intake carries a quote, a fee or an eligibility score, the figure has to be one nobody can type. Faldaro evaluates every formula on the server on every save, stores it apart from what was submitted, and never sends the formula text to the public page — so the form is not an oracle for the pricing behind it.
#### Partners as organizations
Brokers, agencies and franchisees are not users of your account in Faldaro — they are organizations of their own. Share a form or folder with one and its people submit through it on their own seats, their records isolated from yours and from each other by PostgreSQL row-level security.
The public surface is described in full in the [public forms guide](https://faldaro.com/docs/public-forms), partner organizations in [partner sharing](https://faldaro.com/docs/sharing), and the category-level comparison on [why Faldaro](https://faldaro.com/why-faldaro).
Behind the door
### Still a process, just not a separate one
The record that arrives is the record that moves. States, deadlines, approvals, documents and signatures all hang off the one submission.
#### Transitions are default-deny
A move that names no privilege still requires one, so the easiest thing an author can do is also the safe thing. Deadlines fire only the one transition their author named.
#### Effects run after the move commits
Notifications, documents and webhooks run once the state change is saved, so an unreachable mail server cannot un-move a record, and nothing announces a move that did not happen.
See it end to end on the [approvals page](https://faldaro.com/features/approvals), or start from the [project request template](https://faldaro.com/templates/project-request), which ships with its workflow.
Switching
### Moving is an afternoon, not a project
The start form rebuilds itself, the phases become states, and the history arrives as records.
#### 1 Rebuild the start form
Describe the request to the AI assistant, or hand it the PDF people fill in today, and it builds an editable draft — fields, conditions and calculations together.
#### 2 Draw the phases as states
Each phase of the pipe becomes a workflow state, and each move a named transition with its own privilege, conditions and actions — notify, generate a document, request a signature or approval, call a webhook.
#### 3 Bring the cards
Export the history as CSV and import it: columns map to fields by header, states and reference numbers come across, and every imported record is marked as imported in the audit log. Nothing replays.
### Fair questions
**Does Faldaro have a kanban view like a pipe?**
Yes. A form’s submissions can be viewed as a table, a board with one column per workflow state, a calendar or cards. Dragging a card on the board takes the ordinary transition, so the same privileges, conditions and actions apply as from the record page — the board cannot skip a rule.
**Do requesters need an account to follow their request?**
No. Each record can have a status link showing its state, its reference number and its timestamps — never its field values. Submitters can also open a portal of all their own records through a magic link mailed to the address they gave, so possession of the mailbox is the credential.
**We need approvals from people outside the team.**
An approval request mails each approver a link; they decide from their inbox with no account. The verdict fires the transition the workflow named when the request was created, and an expired request can never read as consent.
**What does the free plan include?**
Unlimited forms, ten thousand submissions a month, the same logic and calculation engine and workflows as every paid plan, public links, PDF documents, email notifications, and payment collection with a three percent platform fee. The pricing page lists exactly what each tier adds.
### Build the front door first
The free plan includes unlimited forms, ten thousand submissions a month and the same engine and workflows as every paid plan — and nobody who submits or approves is ever a seat.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# DocuSign PowerForms alternative for intake
Source: https://faldaro.com/alternatives/docusign-powerforms
A DocuSign PowerForms alternative where the form, the workflow and the signature are one record — signed over frozen, fingerprinted bytes.
## The DocuSign PowerForms alternative for signatures inside the intake
PowerForms are genuinely good at what they are for: a reusable signing link made from a DocuSign template, where people you do not know in advance enter their own details and sign — waivers, registrations, consent forms — inside an e-signature platform many organizations already trust. If the signature is the whole job, they may well be the right choice. Teams come here when the signature is one step of an intake that also asks questions, calculates, gets reviewed and ends in a decision.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The signature is one step
A PowerForm makes a signing ceremony self-service. Most intake needs more around it: questions that branch, a calculated figure, a review, a decision, a letter. In Faldaro the form, the workflow and the signature are one record — the signature request is an action on entering a state, and its outcome is a value the next transition can wait on.
#### What was signed stays provable
When the request is sent, the document is rendered once from the submission, stored and fingerprinted with SHA-256; the signer reviews those exact bytes. Before the signed copy is assembled the platform re-checks the fingerprint, and refuses to certify if it no longer matches — a certificate over different bytes would be a lie.
#### The data is the record
The answers are not fields riding inside an envelope to be extracted later. They are the submission: validated, calculated on the server, reportable, exportable and searchable from the moment they arrive — and the signed PDF lands on the same record’s Documents tab.
Every detail of the evidence trail is in the [e-signatures guide](https://faldaro.com/docs/esignatures); the documents that get signed are on the [documents and payments page](https://faldaro.com/features/documents-payments).
Self-service, end to end
### From a stranger’s first click to a signed copy
The same no-login start a PowerForm gives you, with the rest of the intake built around it.
#### 1 A public link, not a login
Publish the form and share its link. The link carries an unguessable token, so anyone with it can start — and nobody can walk the range. Rotate it to revoke.
#### 2 The submitter fills it in
Branching questions, file uploads and calculated values, validated on the server. A signature field captures a drawn signature as part of submitting, on every plan.
#### 3 The workflow asks for signatures
On entering a state such as Awaiting signature, a request goes to the submitter’s own address — or to any email field, the assignee, or each address in a list. Each signer gets their own link and their own evidence trail.
A transition can then require `signature_status` to be signed before the record moves on — a value written by the server alone, so a submitter cannot sign for themselves. See how moves are gated on the [workflows page](https://faldaro.com/features/workflows).
Choosing honestly
### When a PowerForm is still the better tool
The fit is a question of shape, not quality.
#### Stay with PowerForms when
the whole job is getting a known document signed, your organization already standardizes on DocuSign for agreements, or the document needs certificate-based digital signing — which Faldaro does not offer.
#### Move the intake to Faldaro when
the signature follows questions that branch and calculate, someone has to review before anyone signs, the outcome decides what happens next, and the whole story has to be readable from one record months later.
### Fair questions
**Is a Faldaro signature legally binding?**
It is a standard electronic signature with a recorded evidence trail — the signer’s stated name, the drawn signature, the consent wording as shown, timestamps and IP address, and a certificate page stating the document’s fingerprint. That is the kind most business paperwork runs on. It is not a certificate-based digital signature (eIDAS “qualified” signing), and Faldaro does not verify identity beyond control of the mailbox the request went to. Whether that suffices for a given document is a question for your own counsel.
**Can the signer be someone we do not know in advance?**
Yes — that is the self-service case. The person who fills in the public form gives their email address, and the workflow’s signature request can be addressed to that field, so the stranger who started the intake is the one asked to sign.
**Can several people sign?**
Yes. Each recipient gets their own request and link. The record’s signature status reads signed only when everyone asked has signed; one refusal reads declined; cancelled and expired requests drop out, so a mis-addressed request never holds the workflow hostage.
**Which plans include it?**
The signature field is on every plan. Signature requests with the frozen document and certificate are on Team and above, and are not metered separately — the pricing page lists exactly what each tier grants.
### Put the signature where the work is
Start free with unlimited forms and ten thousand submissions a month; signature requests with a frozen, fingerprinted document come with Team.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Formstack Documents alternative — PDFs from forms
Source: https://faldaro.com/alternatives/formstack-documents
A Formstack Documents alternative: PDFs generated from the submission itself when its workflow moves, from blocks or an exact copy of the PDF you use today.
## The Formstack Documents alternative for documents born from intake
Formstack Documents — formerly WebMerge — is genuinely good at what it is for: no-code generation that pulls data from CRMs, form builders and other systems into Word, PowerPoint and PDF templates, and delivers the result onward. If your documents are driven by data living in many systems, it may well be the right choice. Teams come here when the data is an intake — a claim, an application, an order — and the document should be produced by the same record, at the moment its workflow moves.
The usual triggers
### Three reasons people search for this page
Not adjectives — each one is a difference in mechanism, and each is checkable in behaviour before you commit anything.
#### The document comes from the record
A standalone generator waits for data to be sent to it. In Faldaro the template merges the submission it belongs to — typed answers and server-computed values — and generation is a workflow action: when the claim reaches Approved, the settlement letter is produced and attached to that record.
#### The PDF you already use
When the paperwork must look exactly like the original — a certificate, a carrier-branded schedule, a government form — the facsimile engine turns its pages into the template itself: vector rules, editable text, extracted images. You click a line to bind a field to it. Converting is plain computation and costs no AI credits.
#### A template cannot be turned against you
Templates are a closed set of blocks — or, for a facsimile, markup the platform rebuilds itself from a closed vocabulary — never HTML it trusts. Every merged value is escaped, images are your own uploaded files rather than URLs, and the renderer is denied every external resource, so a submitted value cannot smuggle markup into your paperwork.
The full template reference — blocks, the facsimile engine, budgets — is in the [documents guide](https://faldaro.com/docs/documents). To turn a paper form into the online form that feeds it, try the free [PDF to online form converter](https://faldaro.com/tools/pdf-to-form).
How it runs
### From template to attached PDF
No merge service in between: the submission, the template and the generated document live in one place.
#### 1 Build or reproduce the template
Compose it from blocks — headings, paragraphs, tables, images, page breaks — or describe it and let the AI draft it, or reproduce your existing PDF exactly.
#### 2 Merge the submission
Reference field slugs in the text, repeat a table row per line item, show a paragraph only when a condition holds, and compute values with the same closed expression language the form uses.
#### 3 Generate on the move
Attach generation to a transition or a rule. It runs after the move commits, so a template that fails cannot un-move a record — and the PDF lands on the record’s Documents tab, ready to email or to send for signature.
See documents alongside payments and signatures on the [documents and payments page](https://faldaro.com/features/documents-payments), or start from the [certificate of insurance request template](https://faldaro.com/templates/certificate-of-insurance-request).
Choosing honestly
### When a dedicated generator is still the better tool
The fit is a question of where the data lives and what the output has to be.
#### Stay with a generator when
the data lives in a CRM or a spreadsheet rather than a form, the output must be an editable Word or PowerPoint file, or one document merges records from several systems at once.
#### Move to Faldaro when
the data is an intake from outside, the document belongs to one record and should appear the moment it moves, and it may need signing, paying or approving before the work is done.
### Fair questions
**Can Faldaro produce Word or PowerPoint files?**
No — Faldaro generates PDFs, with searchable text painted directly from the template. If your process needs editable Word or PowerPoint output, a dedicated document generator is the honest choice.
**Can it generate documents from Salesforce or a spreadsheet?**
Not directly. Faldaro templates merge Faldaro submissions. Data can arrive as submissions through the public form, the API, email-to-form or a CSV import, and generation then happens on the record — but if your documents are driven by data that lives in a CRM, a generator that reads the CRM is the better fit.
**Do templates stay stable once documents are out?**
Yes. Templates are versioned like forms: publishing freezes a version, a document renders through the version live for its submission, and editing a live template starts a new draft that changes nothing already produced.
**Which plans include documents?**
PDF documents are on every plan, including the free plan with unlimited forms and ten thousand submissions a month. Signature requests over a generated document are on Team and above — the pricing page lists exactly what each tier grants.
### Generate documents where the work moves
The free plan includes unlimited forms, ten thousand submissions a month and PDF documents generated from every one of them.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Guides: form approvals, intake and PDF forms
Source: https://faldaro.com/guides
Practical guides to approval workflows, turning PDFs into online forms and running intake from outside your organization — every option, not just ours.
## Guides
Practical answers to the questions teams ask when work starts arriving from outside: how to get a form approved, how to turn a PDF into something people can fill in, how to run intake without handing out logins. Each guide covers every reasonable option — including the ones that are not Faldaro.
Looking for how a Faldaro feature works? That is the [documentation](https://faldaro.com/docs).
### Approvals & workflow
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
- [Google Forms approval workflow Status columns, Apps Script and add-ons: the three ways to bolt approvals onto Google Forms, with the limits of each stated plainly.](https://faldaro.com/guides/google-forms-approval-workflow)
- [Membership application approval Why vetted memberships should take payment after approval, the six-step workflow, and three ways to build it — from a spreadsheet to a platform.](https://faldaro.com/guides/membership-application-approval)
### Forms & PDFs
- [Convert a PDF to a fillable online form Fillable PDFs versus web forms, three ways to convert, a checklist for doing it well — and how to produce the finished PDF from each response.](https://faldaro.com/guides/convert-pdf-to-online-form)
- [Generate a PDF from form submissions Built-in exports, document-generation services, WordPress plugins and code compared, with a checklist for long answers, repeats and versioning.](https://faldaro.com/guides/generate-pdf-from-form-submission)
### Choosing a tool
- [Google Forms calculated fields Quiz scoring, sheet formulas, Apps Script and add-ons: how to get totals out of Google Forms, and why none of them shows a price while people fill it in.](https://faldaro.com/guides/google-forms-calculated-fields)
### Put your process on Faldaro today
The Free plan is free forever — unlimited forms, ten thousand submissions a month, and the same builder, logic engine and workflows as every paid plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Microsoft Forms approval workflow: external users
Source: https://faldaro.com/guides/microsoft-forms-approval-workflow
Build a Microsoft Forms approval workflow with Power Automate, and what changes when the people submitting or approving are outside your Microsoft 365 tenant.
Approvals & workflow
## Microsoft Forms approval workflows, and what changes for external users
Inside one Microsoft 365 tenant, Forms plus Power Automate is a quick way to route a response for sign-off. The moment the person filling the form, or the person approving it, works somewhere else, the shape of the problem changes. Here is the standard build, and exactly where the edges are.
By the Faldaro team · Published September 25, 2026
### The standard build: Forms, Power Automate, Approvals
Microsoft Forms collects the response; Power Automate reacts to it; the Approvals connector asks someone to decide. The usual flow, which Microsoft and most tutorials describe in some variation, has five steps:
1. Trigger: When a new response is submitted. Pick your form in the Microsoft Forms connector. The trigger hands over only a response id.
2. Get response details. Pass the form id and that response id to fetch the actual answers, which then appear as dynamic content for later steps.
3. Start and wait for an approval. Choose an approval type, name the approvers, and write a title and details that include the answers the approver needs to see.
4. Condition on the outcome. Branch on whether the result was approved.
5. Act on each branch. Send an email, update a SharePoint list or Excel table, post to Teams — whatever “approved” and “rejected” mean for your process.
The approval action offers several types: everyone must approve, first to respond, custom responses (wait for one or wait for all), and sequential approval, where each approver responds in turn. Approvers can answer from an Outlook email, a Teams adaptive card, or the Power Automate action centre.
Two small traps catch almost everyone the first time. Forms owned by a group do not appear in the trigger’s drop-down, so you paste the form id from the address bar by hand. And the first approval flow in a non-default environment provisions a Dataverse database, which needs an environment administrator and takes a few minutes.
### External users are two different problems
“External users” usually means one of two people, and they hit different walls:
- External submitters — a customer, applicant, vendor or policyholder filling in the form.
- External approvers — a client signing off a change, a landlord approving a request, a partner firm reviewing a referral.
Many real processes have both. Take them one at a time.
### When the submitter is outside your organization
Microsoft Forms handles this with its Anyone can respond setting: anyone inside or outside your organization with the link can submit. The trigger fires for these responses the same way it does for internal ones, so the flow above still runs.
What you give up is worth knowing before you promise anything to the team:
- No verified identity. Recording the respondent’s name is available only when responses are restricted to people in your organization. For an external response, you know who sent it only if you ask — so add a required email question, and treat what is typed there as a claim rather than a verified address.
- No file uploads. Microsoft’s support documentation states that file upload questions are available only when the form is set to Only people in my organization or Specific people in my organization. For a claim with photos or an application with a CV attached, that is often decisive.
- No status for the submitter. Once they press Submit, the external person has no view into what happened next. Any update has to be an email your flow sends.
### When the approver is outside your organization
This is where most Forms approval projects stall. Power Automate assigns approvals to users in your tenant or environment — and that includes guest users, invited through Microsoft Entra B2B collaboration. Microsoft’s guest-user documentation sets out what that requires:
- The guest must accept the B2B invitation. Guests who have not accepted are removed from the approval’s assignee list: they receive no email and cannot respond. If every assignee is a pending guest, the approval fails to create.
- The guest needs a Power Automate licence, assigned either by your tenant or by their home tenant.
- No approving from the email itself. Actionable approval emails in Outlook are not supported for guest users; a guest follows the link to the Approvals page in your tenant, signs in, and decides there.
- Tenant settings can block it. Assigning approvals to people outside the environment relies on settings such as `AllowAdHocSubscriptions` in Entra and on the environment not being restricted to a security group.
For a long-term partner who already works in your tenant, that is manageable. For a client who approves one change request a quarter, it is a lot to ask: an invitation to accept, a sign-in to remember, and a licence question for somebody’s IT department.
### Common workarounds, and their costs
Teams in this position tend to reach for one of these:
- An internal proxy approver. Assign the approval to an internal colleague who emails the outside person, waits for a reply, and clicks Approve on their behalf. It works, but the record says the colleague approved, and the real decision lives in an inbox.
- Guest accounts for everyone. Workable for a small, stable set of partners; it turns every new approver into an onboarding task.
- Plain notification emails. The flow emails the outside person and a human updates a list when they reply. Simple, but nothing enforces or records the decision.
- A form tool built for external approvals. Move the form and its approval step to a tool whose approvers need no account at all. Covered below.
### Where the responses live
Two structural points matter for anything you will need to defend later. Forms responses, and any uploaded files, live with the form’s owner — uploads land in the owner’s OneDrive for Business, or the group’s site for a group form. And the approval’s history lives in Dataverse, separate from the response. If the owner leaves, or someone asks “who approved this, and what exactly did they see?”, the answer is spread across several places. Group-owned forms and a flow that writes the outcome back to a SharePoint list alongside the response go a long way here.
### When Microsoft Forms is the right answer
If the submitters and approvers are all colleagues, you already pay for Microsoft 365, and the process is short — time-off requests, internal purchase sign-offs, equipment requests — the Forms and Power Automate combination is hard to beat. It is already licensed, it lives where your people work, and approvals from Teams are genuinely pleasant. Do not move a process like that for the sake of it.
The case for another tool gets stronger as more of the people involved sit outside the tenant, as submissions need files or computed figures, and as the process gains steps, deadlines and a need for a record that answers for itself.
### Option: an intake platform built for people outside
Faldaro is built around exactly this case — work that arrives from outside the organization and needs a decision. It is one option among several; here is how it handles the two problems above, stated as mechanisms rather than adjectives:
- Submitters need no account. A form is published on a revocable public link; submitters are never seats. A form that declares a file field accepts uploads from anonymous submitters, and a status link can show them where their submission stands.
- Approvers need no account either. The workflow’s Request an approval action emails each named approver their own approve/decline link. They see only the fields you chose to show, and decide with a comment. With several approvers, the move fires once everyone has said yes; any no reads as declined.
- The link can do exactly one thing. An approval link takes the one move you named for approve (and optionally one for decline). If the record has already moved on, the verdict is recorded and nothing moves.
- Stalls escalate on their own. A waiting state can carry a deadline and the move to take when it passes, and the audit log records that the deadline did it.
- One record. The response, the decision — who, when, with what comment — and everything that happened afterwards sit on the same submission, in an append-only audit log.
Approvals are on every plan, the free one included. The [approvals page](https://faldaro.com/features/approvals) shows the feature, the [workflow documentation](https://faldaro.com/docs/workflows) explains every setting, and the [Microsoft Forms comparison](https://faldaro.com/alternatives/microsoft-forms) covers the wider trade-off honestly — including where Microsoft Forms is the better fit.
### A quick checklist
- Are all submitters in your tenant? If not, can you live without verified names and file uploads?
- Are all approvers in your tenant? If not, will each accept a guest invitation, hold a licence, and sign in to approve?
- Does anyone outside need to see the status of their submission?
- When someone asks who approved what, and on what information, where will you look?
If every answer points inside the tenant, build it in Power Automate. If most point outside, choose a tool designed for the outside world.
### Questions
**Can someone outside my organization approve a Microsoft Forms response?**
Only as a guest user of your Microsoft Entra tenant. Power Automate can assign an approval to a guest, but the guest must have accepted the B2B invitation, needs a Power Automate licence from your tenant or their own, and must act from the Approvals page in your tenant — actionable approval emails in Outlook are not supported for guests.
**Can external people fill in the form itself?**
Yes. Set the form to “Anyone can respond” and anyone with the link can submit. The trade-off is identity: names are recorded only when responses are restricted to your organization, and file upload questions are available only in the organization-only modes.
**What happens if an external approver never accepts the guest invitation?**
Microsoft’s documentation says guests who have not accepted are removed from the approval’s assignee list: they get no email and cannot respond. If every assignee is a pending guest, creating the approval fails.
**Do I need a paid licence to build the approval flow?**
The Approvals connector is a standard connector, so any licence that grants Power Automate with standard connectors — including Power Automate rights bundled with many Office 365 and Dynamics 365 plans — is enough to create the flow. Check the licensing guide for your specific plan.
On this page
- The standard build: Forms, Power Automate, Approvals
- External users are two different problems
- When the submitter is outside your organization
- When the approver is outside your organization
- Common workarounds, and their costs
- Where the responses live
- When Microsoft Forms is the right answer
- Option: an intake platform built for people outside
- A quick checklist
### Keep reading
- [Microsoft Forms alternative An honest comparison for forms that go outside your tenant.](https://faldaro.com/alternatives/microsoft-forms)
- [Approvals from the inbox Approvers decide from an emailed link, with no account and no seat.](https://faldaro.com/features/approvals)
- [Workflows, in the docs States, moves, deadlines and the Request an approval action.](https://faldaro.com/docs/workflows)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
- [Google Forms approval workflow Status columns, Apps Script and add-ons: the three ways to bolt approvals onto Google Forms, with the limits of each stated plainly.](https://faldaro.com/guides/google-forms-approval-workflow)
- [Membership application approval Why vetted memberships should take payment after approval, the six-step workflow, and three ways to build it — from a spreadsheet to a platform.](https://faldaro.com/guides/membership-application-approval)
### Approvals that work outside your tenant
Anyone submits from a link; approvers decide from their inbox with no account. Free on every plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# How to set up a form approval workflow
Source: https://faldaro.com/guides/form-approval-workflow
A step-by-step guide to form approval workflows: define the decision, the states and the approvers, handle deadlines, and pick the right tool for the job.
Approvals & workflow
## How to set up a form approval workflow
Purchase requests, expense claims, change requests, vendor applications: most organizations have a handful of forms where somebody has to say yes before anything happens. This guide walks through designing that approval properly, then compares the tools you can build it in.
By the Faldaro team · Published September 25, 2026
### What a good approval workflow does
Before choosing a tool, it helps to agree on what “working” means. A good approval workflow:
- Collects everything the decision needs, once, in a consistent shape.
- Puts the request in front of the right person without anyone forwarding emails.
- Makes the decision easy to take — ideally from wherever the approver already is.
- Never lets a request disappear: every request is somewhere, and waiting has a limit.
- Records the decision — who, when, and on what information — where you can find it later.
- Does the follow-up automatically, so approval always leads to the same next steps.
Most broken approval processes fail on the fourth and fifth points: a request sits in someone’s inbox for a fortnight, and months later nobody can say who signed it off.
### Step by step
1. Write down the decision. Name the decision being made, who makes it, and which facts they need to make it. Everything else in the workflow follows from that sentence.
2. Build the form around what the approver needs. Ask for exactly the information the decision depends on, make it required, and compute totals rather than asking people to type them.
3. Define the states. List where a request can be — Submitted, In review, Approved, Rejected, and usually Returned for changes — and which moves connect them.
4. Name the approvers and the rule. For each approval step, decide who approves and whether one yes is enough or everyone must agree.
5. Choose how approvers respond. Decide where the decision happens: an email link, an app, a chat message. The fewer sign-ins it takes, the faster approvals come back.
6. Add deadlines and escalation. Decide how long a request may wait at each step and what happens when that time runs out.
7. Automate what happens after the decision. Notify the requester, generate the document, start the next step — so every approval ends the same way.
8. Test with real examples, then publish. Run a few realistic requests through every path, including rejection and return, before anyone depends on it.
### Designing the states
The states are the backbone. A good default for a single-approver process is Submitted → In review → Approved or Rejected, plus Returned for requests that need changes rather than a no. Returned matters more than it looks: without it, “please add the quote” becomes a rejection and a brand-new request, and the history splits in two.
For multi-step approvals, give each step its own state:
- Submitted → Manager review → Finance review → Approved
- A condition that skips finance under a threshold, rather than a second form
- Final states — Approved, Rejected, Withdrawn — that nothing moves out of
Name each move by what the person does (Approve, Send back, Escalate), and decide who is allowed to take it. A move anyone can take is not an approval.
### Choosing approvers, and the approval rule
Decide per step whether one approver is enough (first to respond) or everyone named must agree. “Everyone must agree” is the safer rule for money and risk; “first to respond” is faster for routine requests shared across a team. Whichever you choose, decide what a single rejection means — in most processes, one no should stop the request.
Then ask where each approver sits. Colleagues in your own systems can approve anywhere. A client, landlord, partner firm or external consultant is different: if your tool requires them to have an account, every approval starts with an invitation and a password.
### Deadlines and escalation
Every waiting step should have a time limit and a consequence. Common patterns:
- Remind the approver after a day.
- Escalate to a deputy or manager after two.
- Expire the request after a set period, telling the requester — an unanswered approval should never quietly count as a yes.
### Your options for building it
| Approach | Good for | Where it runs out |
| --- | --- | --- |
| Email and a spreadsheet | A handful of requests a month, one approver, no budget | Nothing enforces the process; decisions live in inboxes; no deadlines |
| Microsoft Forms + Power Automate | Microsoft 365 organizations where everyone involved is in the tenant | External approvers need guest access and a licence; external submitters cannot upload files |
| Google Forms + Apps Script or an add-on | Google Workspace teams with someone comfortable maintaining a script | Scripts run as their creator, within daily quotas; approval state lives in a sheet |
| Dedicated workflow or intake tools | Recurring processes with several steps, external parties, or an audit requirement | Another tool to adopt; check how each one prices approvers and submitters |
The Microsoft and Google routes each have a guide of their own: [Microsoft Forms approvals for external users](https://faldaro.com/guides/microsoft-forms-approval-workflow) and [Google Forms approval workflows](https://faldaro.com/guides/google-forms-approval-workflow).
### Building it in Faldaro
Faldaro is one of the dedicated tools, built for intake from outside the organization. The eight steps above map onto it directly:
- The form is built in the browser — or drafted from a description or an existing PDF — with totals computed on the server, so a browser cannot fabricate a figure the approver relies on. A free [expense claim](https://faldaro.com/templates/expense-claim) or [project request](https://faldaro.com/templates/project-request) template is a head start.
- The states are drawn as a diagram in the builder’s Workflow tab, with a Review and approve quick start. Each move names the privilege required to take it, and can require a condition or filled-in fields first.
- The approvers are reached by the Request an approval action: each named approver is emailed a personal approve/decline link that needs no account, showing only the fields you chose. With several approvers, the move fires once everyone has said yes; any no reads as declined.
- Deadlines sit on states: after a set wait, the platform takes the move you named, such as Escalate, and the audit log says the deadline did it. An expired approval request never counts as a yes.
- What happens next — a notification, a generated PDF, an e-signature request, a payment request, a linked record on another form — is configured on the states, and runs after the move commits.
Approvals are on every plan, including Free. See [approval workflows](https://faldaro.com/features/approvals) for the overview and [the workflow docs](https://faldaro.com/docs/workflows) for every setting.
### Common mistakes
- Approving the wrong version. If the request can be edited after approval, record what was approved, or lock it.
- Letting the requester set the flag. An “approved” field anyone can tick is not an approval; the decision should be recorded by the system.
- No way back. Without a Returned state, every correction becomes a rejection and a fresh request.
- Showing approvers everything. An approver outside the organization should see the fields they are deciding on, not the whole record.
- No owner for the queue. Someone should be able to see every waiting request in one place.
### Questions
**What is a form approval workflow?**
A form approval workflow is a process where a submitted form is routed to one or more people who approve or reject it, with the outcome recorded and follow-up actions — notifications, documents, next steps — triggered by the decision.
**Should approvals be sequential or parallel?**
Sequential when each approver depends on the one before (a manager, then finance over a threshold). Parallel when approvers are independent and you only need everyone’s agreement, which is usually faster.
**Can people outside my organization approve?**
It depends on the tool. Some require every approver to have an account or a guest identity in your system; others send each approver a personal link that needs no sign-in. If your approvers are clients, partners or landlords, make this the first question you ask a tool.
**How do I stop approvals getting stuck?**
Give every waiting step a deadline and a defined consequence — a reminder, an escalation to someone else, or an automatic move — and make the queue of waiting requests visible to whoever owns the process.
On this page
- What a good approval workflow does
- Step by step
- Designing the states
- Choosing approvers, and the approval rule
- Deadlines and escalation
- Your options for building it
- Building it in Faldaro
- Common mistakes
### Keep reading
- [Approval workflows in Faldaro Approvers decide from their inbox, with no account. On every plan.](https://faldaro.com/features/approvals)
- [Workflow automation States, permissioned moves, deadlines and what each move does.](https://faldaro.com/features/workflows)
- [Expense claim template A free template with a computed total and an approval workflow included.](https://faldaro.com/templates/expense-claim)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [Google Forms approval workflow Status columns, Apps Script and add-ons: the three ways to bolt approvals onto Google Forms, with the limits of each stated plainly.](https://faldaro.com/guides/google-forms-approval-workflow)
- [Membership application approval Why vetted memberships should take payment after approval, the six-step workflow, and three ways to build it — from a spreadsheet to a platform.](https://faldaro.com/guides/membership-application-approval)
### Build your approval workflow on the Free plan
A form, the states, the approvers — approvers decide from an emailed link with no account.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# How to convert a PDF to a fillable online form
Source: https://faldaro.com/guides/convert-pdf-to-online-form
Fillable PDF or web form? How to turn a PDF into something people can fill in on any device, the ways to do it, and how to get a PDF back out at the end.
Forms & PDFs
## How to convert a PDF into a fillable online form
Most organizations have a PDF that people print, fill in by hand, scan and email back — or download, type into, and attach. Turning it into an online form removes most of that friction. This guide covers the options, how to do the conversion well, and how to keep producing the PDF when you still need it.
By the Faldaro team · Published September 25, 2026
### First: fillable PDF, or online form?
“Make this PDF fillable” means two different things, and it is worth deciding which one you need before you start.
| | Fillable PDF | Online form |
| --- | --- | --- |
| How people fill it | In a PDF reader, after downloading | In any browser, on any device |
| How it comes back | As a file, usually by email | As a response in a list |
| Validation | Limited; easy to skip fields | Required fields, formats and logic enforced |
| Conditional questions | Awkward | Show and hide questions based on answers |
| Phones | Often painful | Designed for it |
| Looks exactly like the original | Yes | No — but it can generate the original from each response |
A fillable PDF is the right answer when the document itself is the deliverable and the people filling it are comfortable with PDF software. If you are collecting information from many people, especially on their phones, and then acting on it, an online form is almost always the better tool.
### Option 1: make a fillable PDF in Acrobat
Adobe Acrobat’s Prepare a form tool takes an existing document and detects the likely fields automatically, turning blank lines and boxes into fillable text fields that you can then move, adjust or add to. It is the quickest way to a fillable PDF, and the result looks exactly like the original.
What it does not change is the rest of the process: somebody still downloads the file, fills it in, saves it, and sends it back; somebody still opens each file and retypes the answers wherever they are needed.
### Option 2: rebuild it by hand in a form builder
Any form builder — Google Forms, Microsoft Forms, Typeform, Jotform, Faldaro — can recreate the PDF’s questions as a web form. Done by hand, that means reading the PDF top to bottom and adding each question, choosing its type, and copying its options. For a one-page form, that is half an hour. For a twelve-page application with tables and conditional sections, it is a day, and the most common source of mistakes: a skipped question, a checkbox that should have been a single choice, an option list with a typo.
### Option 3: convert it with AI
AI converters read the PDF — including a scan or a photo with no text layer — and draft the web form for you: fields, types, choices and sections. You still review it, but you start from a nearly finished form rather than a blank page.
Faldaro’s [free PDF to online form converter](https://faldaro.com/tools/pdf-to-form) works this way. Drop a PDF, or a PNG, JPEG or WebP photo of a paper form up to 5 MB, and it comes back as a preview of the web form. It needs no account, and the file is read once to draft the preview and not stored. If you sign up, the builder can generate the full form from the whole document — the same import is available inside the builder and in the AI assistant — ready to edit and publish.
### How to convert a PDF well
Whichever route you take, the difference between a good conversion and a faithful copy is in these details:
1. Fix the field types. A date should be a date picker, an email an email field, an amount a currency field. PDF forms express all of these as blank lines.
2. Replace “if yes, go to section 4” with logic. Paper forms tell people what to skip. A web form can simply hide the questions that do not apply.
3. Compute what the form asks people to add up. Totals, subtotals and percentages should be calculated, not typed.
4. Make required fields required. This is where most of the time saved comes from: no more chasing missing answers.
5. Split long forms into steps. One section per page reads far better on a phone than a single endless scroll.
6. Drop the office-use-only box. Fields your team fills in afterwards belong in the review process, not in front of the person submitting.
7. Ask for attachments properly. “Please enclose a copy of…” becomes a file upload field.
### Getting a PDF back out
The usual objection to leaving the PDF behind is that someone downstream — an insurer, a regulator, a client’s legal team — still expects the PDF. You do not have to choose. A form tool that generates documents can produce the familiar PDF from every response.
In Faldaro, a document template can be a reproduction of your original PDF: the PDF’s own pages become the template, with lines, boxes, text and logos kept, and you bind form fields onto the places the answers belong. Converting the pages is plain computation and costs no AI credits. A workflow can then generate the filled document as a record moves — when it is accepted for review, say, or approved — attach it to the record, and — on plans that include e-signatures — send it out to be signed. The [documents and payments page](https://faldaro.com/features/documents-payments) shows it end to end, and the [document docs](https://faldaro.com/docs/documents) list the honest edges, such as gradients being left out.
### What happens after the form
The reason the PDF was painful was never really the PDF. It was that every returned copy was a small project: open it, check it, retype it, forward it, remember it. Once responses arrive as structured records, the rest of the process can come with them — a review step, an approval from the right person, a notification to the submitter, a tracking link so they can see progress. That is where most of the time goes, and where most of the time is saved. The [form approval workflow guide](https://faldaro.com/guides/form-approval-workflow) covers that part.
### Quick recommendation
- The document is the product, and a few people fill it in: make a fillable PDF.
- Many people fill it in, often on phones, and you act on the answers: convert it to an online form.
- You need both: convert it, and generate the PDF from each response.
To see what your PDF looks like as a web form, try the [free converter](https://faldaro.com/tools/pdf-to-form) — it takes a minute or two, with no signup.
### Questions
**What is the difference between a fillable PDF and an online form?**
A fillable PDF is still a document: people download it, fill in its fields in a PDF reader and send the file back. An online form is a web page: people fill it in in any browser, the answers are validated as they type, and each response lands in a list rather than an inbox.
**Can I convert a scanned PDF or a photo of a paper form?**
With an AI-based converter, usually yes, because it reads the page the way a person would rather than relying on a text layer. Faldaro’s free converter accepts a PDF or a PNG, JPEG or WebP photo up to 5 MB; a very blurry photo gives a rougher draft.
**Will I still be able to produce the original PDF?**
Yes, if your form tool generates documents from responses. In Faldaro, a document template can reproduce the original PDF’s pages exactly and fill each response’s answers into it, so the web form and the familiar paperwork coexist.
**Is it free to convert a PDF to an online form?**
Faldaro’s converter at /tools/pdf-to-form is free and needs no account; it drafts a preview and does not store your file. Signing up — also free — lets you build and publish the full form.
On this page
- First: fillable PDF, or online form?
- Option 1: make a fillable PDF in Acrobat
- Option 2: rebuild it by hand in a form builder
- Option 3: convert it with AI
- How to convert a PDF well
- Getting a PDF back out
- What happens after the form
- Quick recommendation
### Keep reading
- [Free PDF to online form converter Drop a PDF or a photo of a paper form. No signup, file not stored.](https://faldaro.com/tools/pdf-to-form)
- [Generate PDFs from submissions Your own document, filled in with each response — with e-signatures.](https://faldaro.com/features/documents-payments)
- [Form builder Logic, server-side calculations and multi-step forms.](https://faldaro.com/features/form-builder)
- [Generate a PDF from form submissions Built-in exports, document-generation services, WordPress plugins and code compared, with a checklist for long answers, repeats and versioning.](https://faldaro.com/guides/generate-pdf-from-form-submission)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
### Turn your PDF into a form people can fill in
Start with the free converter, then build, publish and receive responses on the Free plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Google Forms approval workflow: how to build one
Source: https://faldaro.com/guides/google-forms-approval-workflow
Add approvals to Google Forms with a status column, Apps Script or an add-on: how each works, where each runs out, and when to move to a workflow tool.
Approvals & workflow
## How to build an approval workflow on Google Forms
Google Forms is free, familiar and quick to build — but it has no approval step. Teams add one in three ways: a status column in the response sheet, an Apps Script, or a Marketplace add-on. Here is how each works, where each runs out, and the signs it is time for a tool built for approvals.
By the Faldaro team · Published September 25, 2026
### What Google Forms gives you to work with
Out of the box, a Google Form can:
- Send responses to a Google Sheet, one row per response, via Link to Sheets.
- Collect email addresses — either verified, where the respondent signs in and their Google Account address is recorded, or responder input, where they type one.
- Send respondents a copy of their answers, on request or always.
- Email the form owner when a new response arrives.
That is a collection tool, and a good one. Everything to do with a decision — who decides, what they decided, what happens next — has to be added on.
### Approach 1: a status column in the response sheet
The simplest version needs no code. Link the form to a sheet, and let the approver work in it:
1. Link the form’s responses to a Google Sheet.
2. Turn on the owner’s new-response email notification, or share the sheet with the approver.
3. Add Status, Approved by and Decision date columns, with a drop-down (data validation) on Status: Pending, Approved, Rejected.
4. Use a filter view or conditional formatting so pending rows stand out.
This works for a small team handling a few requests a week. Its limits are that nothing enforces it: anyone with edit access can set any status on any row, the requester hears nothing unless someone emails them, and a request no one looks at simply waits. Keep the status columns to the right of the form’s columns, and never sort or reorder the response rows — the form keeps writing to that sheet.
### Approach 2: Apps Script
Apps Script lets you run code when a response arrives. An installable form submit trigger — on the form or on its linked sheet — can email an approver, write a Pending status, or call another service. A minimal version that emails an approver looks like this:
```
// In the Google Sheet linked to your form: Extensions → Apps Script.
// Add an installable "On form submit" trigger for this function.
function onFormSubmit(e) {
const answers = e.namedValues; // { "Question title": ["answer"], ... }
const row = e.range.getRow(); // where this response landed
const amount = answers['Amount'][0];
MailApp.sendEmail({
to: 'approver@example.com',
subject: 'Approval needed: request in row ' + row,
htmlBody: 'Amount: ' + amount + '
' +
'Review the request in the sheet and set its status.',
});
}
```
To let the approver decide from the email itself, the usual next step is a small web app in the same project: the email contains Approve and Reject links pointing to the web app, which writes the decision back to the row. That is where the work grows. You need:
- Unguessable links. A link like `?row=12&decision=approve` can be edited by anyone who sees it. Generate a random token per request, store it, and check it before recording anything.
- One decision per request. Refuse a second click, or a click after the request was withdrawn.
- Notification of the requester, from the same script.
- Escalation, usually a time-driven trigger that scans for rows pending too long.
Three constraints shape any Apps Script solution:
- It runs as a person. Google’s documentation is explicit that installable triggers always run under the account of the person who created them. Emails come from that account, and if it is suspended when someone leaves, the workflow stops.
- It runs within quotas. Apps Script limits emails sent per day, total trigger runtime per day and time per execution — with consumer accounts allowed less than Google Workspace accounts. Check the current quota table before relying on a script for volume.
- Someone has to maintain it. A script is code: when the form changes — a question renamed, for instance, changes the key in `e.namedValues` — the script needs updating, by someone who understands it.
### Approach 3: a Workspace Marketplace add-on
Several add-ons in the Google Workspace Marketplace package the Apps Script pattern into a configuration screen: choose approvers, write the email, define the statuses. They save you writing and maintaining the code, and many support multi-level approvals.
Before installing one, check the same things you would check of any vendor: the scopes it asks for (many need access to your forms, sheets and Gmail), where it stores approval data, whether approvers outside your domain are supported, and how it is priced — per user, per form or per response. The underlying data still lives in your Form and Sheet, so the structural limits of that pairing remain.
### Limits that no approach removes
Whichever way you add approvals, some properties come from Google Forms itself:
- File uploads need a Google sign-in. Google’s help centre states that respondents must sign in to a Google Account to answer a file upload question, and uploads are stored in the owner’s Drive. For applicants, customers or claimants without Google accounts, that is a barrier.
- Identity is typed unless verified. Verified email collection requires the respondent to sign in; otherwise the email on a response is whatever was typed.
- The response is not the record. The answers live in the form and sheet, the decision in a column or script storage, the correspondence in Gmail. Answering “who approved this, and what did they see?” means looking in several places, and a sheet cell holds no history of who changed it to Approved beyond the sheet’s version history.
- No status for the submitter. The person who submitted cannot check progress; they learn only what someone emails them.
### When to move to a workflow tool
A Google Forms approval setup is doing fine while it is small. The signs it has outgrown the pairing:
- More than one approval step, or approvals that depend on the answers (over a threshold, a different approver).
- Approvers or submitters outside your Google Workspace, especially ones who need to attach files.
- Requests stalling, with no one noticing until the requester chases.
- An audit or dispute where you need to prove who decided what, and when.
- The only person who understands the script is about to go on holiday.
### Option: an intake platform with approvals built in
Faldaro is a form platform built for intake from outside the organization, with the approval step as part of the form rather than a script beside it. In Faldaro terms:
- Anyone can submit from a revocable public link without an account, and a form that declares a file field accepts uploads from those anonymous submitters.
- A workflow is drawn, not coded — states such as Submitted, In review, Approved and Rejected, and moves between them that each name who may take them.
- Approvers decide from an emailed link with no account: the Request an approval action sends each approver a personal link showing only the fields you choose. The link can take exactly the move you delegated, once.
- Deadlines escalate a request that waits too long, and every move lands in an append-only audit log on the record.
- The submitter can follow along through a status link that shows the current state and reference number, never the answers or internal notes.
Approvals are on every plan, including Free. The [Google Forms comparison](https://faldaro.com/alternatives/google-forms) covers the wider trade-off — including when Google Forms is the better fit — and the [approval workflow guide](https://faldaro.com/guides/form-approval-workflow) covers designing the process whichever tool you choose.
### Questions
**Does Google Forms have a built-in approval workflow?**
No. Google Forms collects responses and can send them to a linked Google Sheet, but it has no notion of a response being approved or rejected. Approvals are added with a status column in the sheet, an Apps Script, or a Workspace Marketplace add-on.
**Whose account does an Apps Script approval run as?**
An installable trigger always runs under the account of the person who created it. Emails are sent from that account, quotas are counted against it, and if that person leaves, the automation goes with them unless someone recreates it.
**Can people outside my organization approve with Google Forms?**
With Apps Script, yes — the script can email any address a link to a web app that records the decision. You are then responsible for making those links unguessable and single-purpose, because anyone who has the link can use it.
**Can external submitters upload files to a Google Form?**
Only if they sign in: Google’s help centre states that respondents must sign in to a Google Account to answer a file upload question. Uploaded files are stored in the form owner’s Google Drive.
On this page
- What Google Forms gives you to work with
- Approach 1: a status column in the response sheet
- Approach 2: Apps Script
- Approach 3: a Workspace Marketplace add-on
- Limits that no approach removes
- When to move to a workflow tool
- Option: an intake platform with approvals built in
### Keep reading
- [Google Forms alternative An honest comparison for forms that need payments and workflow.](https://faldaro.com/alternatives/google-forms)
- [Approvals from the inbox Approvers decide from an emailed link, with no account and no seat.](https://faldaro.com/features/approvals)
- [Workflow automation States, permissioned moves, deadlines and what each move does.](https://faldaro.com/features/workflows)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
- [Membership application approval Why vetted memberships should take payment after approval, the six-step workflow, and three ways to build it — from a spreadsheet to a platform.](https://faldaro.com/guides/membership-application-approval)
### Approvals without the script
A form, its states and its approvers — decided from an emailed link with no account. Free on every plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Google Forms calculated fields: what works
Source: https://faldaro.com/guides/google-forms-calculated-fields
Google Forms has no calculated field. Four workarounds — quiz scoring, ARRAYFORMULA, Apps Script and add-ons — what each can do, and when you need a real one.
Choosing a tool
## Google Forms calculated fields: what works, and what doesn’t
Google Forms has no calculated field. There is no box that adds up a quantity times a price, or shows a quote while someone is filling in the form. There are still four ways to get a number out of responses, each computing it after the respondent has submitted. Here is how each works, and when you need a different tool.
By the Faldaro team · Published September 25, 2026
### What Google Forms can and cannot calculate
Google Forms collects answers. It can validate them — a number within a range, text that matches a pattern — and in quiz mode it can score them. What it cannot do is hold a field whose value is computed from other answers. Every workaround below moves the arithmetic somewhere else, which has two consequences worth knowing before you choose:
- The respondent never sees the result while filling in the form. A quote, a total or a fee is computed after they press Submit.
- The computed number lives apart from the answers — in the quiz score, a sheet column or a script — so it is only as reliable as whatever computes it.
### Option 1: quiz mode scoring
Turn the form into a quiz in Settings, give each question an answer key and a point value, and Google Forms adds up the points for each response. You can release the score immediately after submission, so the respondent sees it on the confirmation page.
This is the right tool for assessments, self-checks and simple eligibility screens. It is the wrong one for money: points only accrue for answers that match the key, so there is no way to multiply a quantity by a price, apply a percentage or cap a figure.
### Option 2: a formula column in the linked sheet
Link the form to a Google Sheet and add a column that computes from the answer columns. Because each response is inserted as a new row, a formula in a single cell does not reliably follow new responses; write one `ARRAYFORMULA` in the header row so the whole column is computed at once:
```
=ARRAYFORMULA(IF(ROW(C:C)=1, "Total",
IF(C:C="", "", C:C * D:D)))
```
This handles most internal needs: totals for a report, a fee to invoice, a score to sort by. Its limits are that the respondent sees nothing, anyone with edit access can change the formula or overwrite a result, and a renamed or reordered question can silently shift which column the formula reads.
### Option 3: Apps Script on submit
An installable form submit trigger can compute a figure the moment a response arrives, write it to the sheet, and email it — to the respondent as a quote, or to your team:
```
// In the linked Google Sheet: Extensions → Apps Script.
// Add an installable "On form submit" trigger for this function.
function onFormSubmit(e) {
const qty = Number(e.namedValues['Quantity'][0]);
const price = 25; // the unit price lives here, in code
const total = qty * price;
e.range.getSheet()
.getRange(e.range.getRow(), e.range.getLastColumn() + 1)
.setValue(total);
}
```
A script can express any logic, and it keeps prices out of the form itself. The trade-offs are the ones every script carries: it runs as the person who created the trigger and stops if their account does, it works within Apps Script’s daily quotas, and when a question is renamed the key in `e.namedValues` changes and the script breaks until someone who understands it fixes it.
### Option 4: a Marketplace add-on
Several Google Workspace Marketplace add-ons add calculations to Google Forms, typically by generating a companion form or a results page that can compute values. Before installing one, check what it can access (form, sheet and Gmail scopes are common), where the computation runs, whether respondents see the result before or after submitting, and how it is priced.
### When you need a real calculated field
The workarounds above are fine for scoring and back-office totals. A calculated field is worth moving for when:
- People should see the number before they commit — a quote, a booking fee, a membership price.
- The number is charged, so it has to be the one the rules computed, not one anybody could change.
- The pricing is yours to keep — rates you would rather a competitor could not read from the page.
- Other rules depend on it: show a question over a threshold, route a large request for review.
### How Faldaro handles calculated fields
In Faldaro a calculated field is part of the form, and its formula is evaluated on the server:
- Formulas reference fields by name — ``quantity` * `unitPrice`` — using arithmetic, comparisons and a closed set of functions (MAX, MIN, ROUND and a few more). Nothing in a formula can execute code, and every formula is checked when you publish.
- The public form can show the result as people type. With live evaluation switched on for a link, the server returns the computed values on each change — the values only, never the formula behind them.
- The submitted figure is the server’s. Every save re-runs the formulas and stores the result separately from the answers, so a total edited in the browser is replaced by the real one. A payment is priced by the same engine.
- Hidden questions count as zero, so a total stays correct when conditional logic hides an add-on the respondent did not choose.
The [quote calculator page](https://faldaro.com/tools/quote-calculator) shows a working example, and calculated fields are on every plan, the Free plan included.
### Questions
**Can Google Forms calculate a total?**
Not on the form itself. Google Forms has no calculated field that updates while someone fills it in. The usual workarounds compute the total afterwards — in quiz scoring, in a formula column of the linked Google Sheet, or in an Apps Script — so the respondent never sees the figure while answering.
**Does quiz mode count as a calculation?**
Only for scoring. Quiz mode awards points for answers that match an answer key and adds them up, and it can show the respondent their score after they submit. It cannot multiply a quantity by a price, apply a discount or compute anything that is not a sum of points for correct answers.
**Why does my formula column break when new responses arrive?**
New form responses are inserted as new rows, and a formula typed into one cell does not reliably follow them. The usual fix is a single ARRAYFORMULA in the header row of a new column, which computes the whole column at once, including rows added later.
**Can the respondent see the result before submitting?**
Not with Google Forms alone. Showing a live total needs a form tool that evaluates formulas while the form is being filled in.
On this page
- What Google Forms can and cannot calculate
- Option 1: quiz mode scoring
- Option 2: a formula column in the linked sheet
- Option 3: Apps Script on submit
- Option 4: a Marketplace add-on
- When you need a real calculated field
- How Faldaro handles calculated fields
### Keep reading
- [Quote calculator form A price from the answers, computed on the server as the applicant types.](https://faldaro.com/tools/quote-calculator)
- [How Faldaro formulas work Field references, the closed function set, and why hidden fields count as zero.](https://faldaro.com/docs/formulas)
- [Google Forms alternative An honest comparison, including when Google Forms is the better choice.](https://faldaro.com/alternatives/google-forms)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
- [Convert a PDF to a fillable online form Fillable PDFs versus web forms, three ways to convert, a checklist for doing it well — and how to produce the finished PDF from each response.](https://faldaro.com/guides/convert-pdf-to-online-form)
### Totals that compute as people type
Calculated fields evaluated on the server — shown live, never forgeable. Free to start.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Approve membership applications before payment
Source: https://faldaro.com/guides/membership-application-approval
How to set up a membership application approval workflow: apply, review, approve, then request payment — so you only charge the members you have accepted.
Approvals & workflow
## How to approve membership applications before taking payment
Most membership tools are built to take the money at sign-up. Clubs, associations, co-operatives and professional bodies that vet applicants need the steps in a different order: apply, review, approve, then pay. Here is how to set that up, the ways to build it, and what to automate once it works.
By the Faldaro team · Published September 25, 2026
### Why the order matters
Charging at the moment of application is the default in most sign-up flows, and for open memberships it is right. When applications are reviewed, it creates three problems:
- Refunds for everyone you decline. Card processors generally keep their fee on a refunded payment, so each decline costs you money as well as an awkward email.
- Pressure on the reviewer. Declining someone who has already paid feels like a bigger decision than declining an application, and reviews get softer.
- A worse first impression. A declined applicant who paid and waited for a refund is the one most likely to complain publicly.
Asking for payment after approval removes all three: money is only requested from people you have accepted.
### The workflow, step by step
1. Application. A public form collects who the applicant is, the tier they want, and what the committee needs to decide — references, qualifications, a short statement. Compute the fee on the form from the tier, so the amount is settled before anyone reviews it.
2. Review. The application lands in a queue as Applied. A reviewer approves, declines, or waitlists it — or sends it to the committee when the rules require more than one approver.
3. Approval. The approving decision moves the record to Approved and, in the same step, emails the applicant a payment link for the fee computed at application.
4. Payment. When the payment is confirmed, the record moves to Active — and only then.
5. Welcome. The move to Active sends the welcome email, generates the certificate or card, and records the renewal date.
6. Decline and waitlist. Each has its own considerate email, and a waitlisted application can be promoted later without the applicant starting again.
### Three ways to build it
#### Membership management software
Dedicated membership platforms handle directories, events, renewals and dues, and many offer an application approval setting. If you need the whole membership back office, start there — and check two things: whether payment can wait until after approval, and whether reviewers need a paid admin seat to decide.
#### A form, a spreadsheet and invoices
The low-cost version: a form collects applications into a sheet, a reviewer marks each row, and approved applicants are sent an invoice by hand. It works at a few applications a month. Past that, the gaps show: nothing tells an applicant where they stand, an invoice can go to someone who was never approved, and a payment is matched to its application by hand.
#### A form platform with workflow and payments
The middle path: one tool where the application, the review, the payment request and the welcome are steps of the same record. It suits organizations whose membership back office is simple but whose vetting matters.
### Building it in Faldaro
Each step of the workflow above maps to something Faldaro does as standard:
- The application is a public form on a revocable link. The [membership application template](https://faldaro.com/templates/membership-application) computes the fee from the tier on the server, so no applicant can submit a price of their own.
- The review is a workflow: Applied, Approved, Waitlisted, Declined, Active — with each move naming who may take it. For a committee, a Request an approval action emails each member a personal approve/decline link with no account; the approval takes effect once everyone has said yes, and a deadline can escalate an application nobody has looked at.
- The payment is a Request a payment action on the approving move. It prices the fee at that moment, freezes the amount, and emails the applicant a Stripe checkout link — money goes to your own Stripe account.
- Activation waits for the money. The move to Active can require ``payment_status` = "succeeded"`, a value the server records from Stripe’s signed confirmation, so no one can activate a membership that has not been paid.
- The welcome is a set of actions on that move: the email, a certificate generated as a PDF from your own template, and anything else the membership triggers.
- The applicant can follow along on a status link — the current step and reference number, never the committee’s notes.
Approvals, payments and documents are on every plan, including Free. The [approval workflow guide](https://faldaro.com/guides/form-approval-workflow) covers designing the review itself, whichever tool you use.
### Questions
**Should we charge the membership fee when someone applies, or after approval?**
If you approve applications, ask for payment after approval. Charging at application means refunding everyone you decline — which costs processing fees you usually do not get back — and applicants who were declined after paying are the ones most likely to complain. Charging after approval asks for money only from people you have already said yes to.
**How many people should approve an application?**
As few as the organization’s rules require. Many clubs and associations need one reviewer for most applications and a committee only for exceptions. Where the bylaws require several approvers, set a deadline for the decision, so an application does not wait on the one committee member who is away.
**Do approvers need an account in our membership system?**
Not necessarily. Tools that send approvers a personal approve/decline link let volunteer committee members decide from their inbox without a login, which is often the difference between a decision this week and next month.
**What should happen after the member pays?**
The welcome: a confirmation email, a membership certificate or card, access to whatever the membership unlocks, and a renewal date recorded. Automate it on the payment confirmation rather than on someone noticing the payment arrived.
On this page
- Why the order matters
- The workflow, step by step
- Three ways to build it
- Building it in Faldaro
### Keep reading
- [Membership application template Tiers, a fee the server computes, and an applied-to-accepted workflow.](https://faldaro.com/templates/membership-application)
- [Approvals from the inbox Committee members decide from an emailed link, with no account.](https://faldaro.com/features/approvals)
- [Payments How a payment is priced on the server and requested on a workflow move.](https://faldaro.com/docs/payments)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
- [Google Forms approval workflow Status columns, Apps Script and add-ons: the three ways to bolt approvals onto Google Forms, with the limits of each stated plainly.](https://faldaro.com/guides/google-forms-approval-workflow)
### Apply, approve, then pay
A membership form, a review step and a payment requested on approval — on the Free plan.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# How to generate a PDF from every form submission
Source: https://faldaro.com/guides/generate-pdf-from-form-submission
Four ways to generate a PDF from each form submission — built-in exports, document services, plugins and code — plus how to fill the PDF you already use.
Forms & PDFs
## How to generate a PDF from every form submission
A form collects answers; the people downstream often want a document — a quote on your letterhead, a completed application, a certificate, the official form a regulator expects. Here are the four ways to produce a PDF from each submission, what each is good at, and how to keep the result exactly on the layout you need.
By the Faldaro team · Published September 25, 2026
### First, decide what the PDF is for
The right approach depends on who reads the document:
- A record for your own files — a copy of the answers, dated and filed. Almost any form tool’s built-in export does this.
- A document you send — a quote, a confirmation letter, a certificate — on your branding, with only some of the answers, in sentences rather than a list.
- An existing form filled in — the carrier’s application, the government form, the supplier set-up sheet — whose layout is not yours to change.
### Option 1: the form builder’s built-in PDF
Many form builders can download or email a PDF of each submission, usually with a choice of layouts and a logo. It is quick and needs no set-up. Its limits are layout control — the document follows the form’s structure, not the one your reader expects — and automation: check whether the PDF can be generated at a particular moment, such as when a submission is approved, rather than only on arrival.
### Option 2: a document-generation service
Dedicated document-automation tools take a template — a Word document, an HTML page or a fillable PDF with named fields — and merge data into it, usually connected to your form through an integration platform. They are flexible and good at documents with many variants. The costs are a second product to pay for, an integration to maintain, and a PDF that lives in a different system from the submission it came from.
### Option 3: WordPress plugins
If your forms run on WordPress, several form plugins and add-ons generate PDFs from entries, often with a visual template editor. They suit sites already built on WordPress, and inherit its hosting, updates and plugin compatibility along with the feature.
### Option 4: code
Developers can fill a fillable PDF’s fields with a PDF library, or render HTML to PDF with a headless browser. It is fully controllable and costs nothing per document; you own every edge case — fonts, long values, page breaks, and keeping the template in step with the form as either changes.
### A checklist for any approach
- Long answers: test with the longest realistic value. Does it wrap, shrink, overflow or vanish?
- Repeating items: line items, dependants, vehicles — can the template repeat a row per item, and what happens past the page?
- Conditional content: can a paragraph or clause appear only when an answer calls for it?
- Formatting: currency, dates and numbers formatted for the reader, not as stored.
- Timing: generated at the right moment — on approval, not on arrival — and never twice.
- Versioning: when the template changes, documents already produced stay exactly as they were.
- Where it lands: attached to the submission it came from, so the record and its paperwork stay together.
### How Faldaro generates documents
In Faldaro a document template belongs to the same platform as the form, and a generated PDF attaches to the submission it came from:
- Reproduce the PDF you already use. The facsimile engine turns a PDF’s own pages into the template, line for line: text stays editable, rules and boxes stay sharp, logos become images. You bind the form on top — click a line to merge a field into it, give an element a condition, repeat a row per list item. Converting is plain computation, not AI, and costs no credits.
- Or build from blocks — headings, paragraphs, tables, images, page breaks — with merged values, conditional blocks and repeating rows, for documents that are yours to design.
- Long values are typeset, not cropped. A bound area wraps inside its column and grows its row, pushing what follows down; growth is capped by the page so a footer is never pushed off.
- Generated on the right step. A workflow move or a rule produces the document — “when the claim reaches Approved, generate the settlement letter” — after the move commits, and the PDF is listed on the submission.
- Templates are versioned. Publishing freezes a version; a document renders through the version that was live for it, so editing the template changes nothing already produced.
- Signing follows naturally. A workflow can request an e-signature on the generated document, frozen and fingerprinted before the signer sees it (Team plan and above).
Honest edges, reported when a PDF is converted rather than discovered later: gradients and fill patterns are left out, and a repeated row stops at the limit you set instead of flowing onto continuation pages. The [documents guide](https://faldaro.com/docs/documents) covers the details, and generated PDFs are on every plan, including Free.
### Questions
**Can I fill my existing PDF with each form submission?**
Yes, in two ways. If the PDF is a fillable one, its form fields can be filled by a PDF library or a document-automation service that maps your answers onto them. If it is a flat PDF — a scan or a designed document with no fields — you need a tool that turns its pages into a template you can bind answers to, which is what Faldaro’s facsimile engine does.
**Why not just print the submission to PDF?**
For internal records that is often enough. It fails when the PDF goes to someone outside — a client, a regulator, a carrier — who expects your letterhead, a fixed layout, or the official form they already know, rather than a list of questions and answers.
**What happens when an answer is too long for the space on the page?**
It depends on the tool. Many fill a fixed box and either shrink the text until it is unreadable or cut it off. Faldaro wraps a long value inside its column and grows the row, pushing the content below down; if that would push the footer off the page, the text compresses slightly instead.
**Can the generated PDF be signed?**
In Faldaro, yes: a workflow can request an e-signature on the generated document. The document is frozen and fingerprinted before it is shown to the signer, and the signed copy carries a certificate page. E-signatures are on the Team plan and above.
On this page
- First, decide what the PDF is for
- Option 1: the form builder’s built-in PDF
- Option 2: a document-generation service
- Option 3: WordPress plugins
- Option 4: code
- A checklist for any approach
- How Faldaro generates documents
### Keep reading
- [Documents & e-signatures Generated PDFs, e-signatures and payments from one submission.](https://faldaro.com/features/documents-payments)
- [Documents guide Block templates, the facsimile engine, and how generation is triggered.](https://faldaro.com/docs/documents)
- [PDF to online form The other direction: turn the PDF people fill in into a web form.](https://faldaro.com/tools/pdf-to-form)
- [Convert a PDF to a fillable online form Fillable PDFs versus web forms, three ways to convert, a checklist for doing it well — and how to produce the finished PDF from each response.](https://faldaro.com/guides/convert-pdf-to-online-form)
- [Microsoft Forms approvals for external users The standard Forms + Power Automate approval flow, step by step — and exactly what breaks when submitters or approvers are outside your tenant.](https://faldaro.com/guides/microsoft-forms-approval-workflow)
- [How to set up a form approval workflow Eight steps from "someone needs to sign this off" to a working approval process, and an honest look at the tools you can build it in.](https://faldaro.com/guides/form-approval-workflow)
### Your PDF, filled from every submission
Reproduce the document you already use, bind the answers, and generate it on the workflow step that needs it.
[Start free](https://faldaro.app/auth/signup) [See pricing](https://faldaro.com/pricing)
No card required.
---
# Documentation
Source: https://faldaro.com/docs
Guides to Faldaro: getting started, server-evaluated formulas, approval workflows, integrations with signature verification, API keys and public forms.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Documentation
How Faldaro works, stated plainly. Each guide describes mechanisms you can verify, in the order you will meet them. New here? Start with getting started, then core concepts.
### Start here
- [Getting started From an empty organization to a published form collecting real submissions.](https://faldaro.com/docs/getting-started)
- [Core concepts The five nouns the whole platform is built from, and how they fit together.](https://faldaro.com/docs/concepts)
### Building forms
- [Formulas & logic Computed fields, operators, what rules can do, and why the server owns every total.](https://faldaro.com/docs/formulas)
- [Workflows Draw the states and moves, decide who may take each, attach effects and deadlines, and see why a move is withheld.](https://faldaro.com/docs/workflows)
- [Field library Reusable field groups, inserted by copy so published forms stay immutable.](https://faldaro.com/docs/field-library)
- [Datasets Reference tables that supply field options, including cascading dropdowns.](https://faldaro.com/docs/datasets)
- [Reference numbers Counters that issue formatted references, allocated once and never reissued.](https://faldaro.com/docs/reference-numbers)
### Working with data
- [Submissions Finding, assigning, importing and exporting the records your forms collect.](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports Grouped, aggregated questions asked of live submissions — and pinned to the dashboard.](https://faldaro.com/docs/reports)
- [Data retention Delete submissions on a schedule, permanently and provably.](https://faldaro.com/docs/retention)
### Sending & delivering
- [Documents PDFs generated from a submission: templates, merging, conditions and limits.](https://faldaro.com/docs/documents)
- [Notifications Email templates, who receives them, and what happens when mail does not arrive.](https://faldaro.com/docs/notifications)
- [Payments Server-priced payments through your own Stripe account, splits and refunds.](https://faldaro.com/docs/payments)
- [E-signatures Per-signer signing links from a workflow, with an evidence trail and a certificate on the signed PDF.](https://faldaro.com/docs/esignatures)
- [Digital products Deliver files to submitters, gated on payment when the rules priced one.](https://faldaro.com/docs/objects)
### Access & sharing
- [Public forms Tokenized links, what they deliberately withhold, translating a form, and branding.](https://faldaro.com/docs/public-forms)
- [Partner sharing Let a partner organization use your form without either side seeing the other’s data.](https://faldaro.com/docs/sharing)
- [Users & roles Privileges, roles, the organization tree, invitations and deactivation.](https://faldaro.com/docs/admin)
- [Single sign-on Sign in through your own identity provider over OIDC.](https://faldaro.com/docs/sso)
### Connecting & extending
- [Integrations & webhooks Zapier, Slack and signed webhooks — including how to verify a delivery.](https://faldaro.com/docs/integrations)
- [Email-to-form Forward a message to a form’s own address and it becomes a submission, sender verified.](https://faldaro.com/docs/inbound-email)
- [API keys Machine credentials that hold exactly the privileges you grant them.](https://faldaro.com/docs/api-keys)
- [API reference The versioned HTTP API: evaluate a payload, file a submission, rate limits.](https://faldaro.com/docs/api)
- [MCP server Connect Claude and other MCP clients to your account with an API key.](https://faldaro.com/docs/mcp)
- [AI & agents The assistant, inline AI and standing agents — and the limits on all three.](https://faldaro.com/docs/ai)
### Your account
- [Plans & billing What each plan includes, how seats are counted, and what happens at a limit.](https://faldaro.com/docs/billing)
---
# Getting started
Source: https://faldaro.com/docs/getting-started
From an empty organization to a published form collecting real submissions: folders, the builder, the AI assistant, publishing and your first public link.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Getting started
Five steps from an empty organization to a form collecting real submissions. The dashboard keeps a checklist of its own alongside these — first form, first link, first submission, first teammate, first integration — each ticked off from what actually exists rather than from anything you mark done.
### 1. Create your organization
[Sign up](https://faldaro.app/auth/signup) with a name, an email and the organization's name. The organization is the boundary everything else lives inside: every form, submission and file belongs to it, and the database itself enforces that separation — a query from one organization cannot see another's rows.
### 2. Make a folder, then a form
Folders are the sections of your app — an insurer makes Policies and Claims, a support desk makes Tickets. Nothing in Faldaro assumes a domain; the vocabulary is yours. Inside a folder, create a form: start from one of the 18 templates, import a template file, or begin empty.
The fastest path is the assistant. Press Build with AI, say what you want to collect, and it creates the folder, the form and the fields — with exactly your permissions, never more — as an editable draft.
### 3. Design and publish
The builder edits a draft. Publishing makes that draft the live version and freezes it: submissions keep the definition they were filled against forever, and editing a live form starts a new draft rather than rewriting history. Publishing also validates everything — formulas that cannot compute, workflows that cannot be exited, patterns that cannot compile are refused with the reason, not discovered by a submitter.
### 4. Share a public link
A form is never reachable anonymously just because it exists. Someone with the publish privilege issues a link: an unguessable token that renders the form to anyone who holds it. Rotate the link and the old URL stops working — the recovery for a link that spread too far.
### 5. Watch submissions arrive
Each submission is a record: it carries the data, every value the server computed, and — if the form has a workflow — a state that people with the right privilege move it through. Reports, notifications, documents and integrations all hang off that record.
### Where to go next
[Core concepts](https://faldaro.com/docs/concepts) is the ten-minute map of everything below — worth reading once before you build in earnest. After that, follow whichever your work needs:
- [Formulas & logic](https://faldaro.com/docs/formulas) — totals the server owns, and everything else a rule can do.
- [Workflows](https://faldaro.com/docs/workflows) — draw the states and moves from draft to done, audited, with deadlines that fire themselves.
- [Submissions](https://faldaro.com/docs/submissions) — finding, assigning and importing the records you collect.
- [Notifications](https://faldaro.com/docs/notifications) and [documents](https://faldaro.com/docs/documents) — the email and the paperwork.
- [Payments](https://faldaro.com/docs/payments) — charge for what the form collects, priced on the server.
- [Reports](https://faldaro.com/docs/reports) — ask questions where the answers already live.
- [Users & roles](https://faldaro.com/docs/admin) — bring your team in and decide what each can do.
[Next Core concepts](https://faldaro.com/docs/concepts)
On this page
- 1. Create your organization
- 2. Make a folder, then a form
- 3. Design and publish
- 4. Share a public link
- 5. Watch submissions arrive
- Where to go next
---
# Core concepts
Source: https://faldaro.com/docs/concepts
The five nouns Faldaro is built from — organizations, folders, forms, versions and submissions — and the rules that hold between them.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Core concepts
Five nouns carry the whole platform: organizations, folders, forms, versions and submissions. Everything else — workflows, documents, payments, reports — hangs off those. This page is the map; the other guides are the territory.
### The spine: folders → forms → submissions
A folder groups forms. A form collects submissions. That is the entire model, and it is deliberately free of any business vocabulary: an insurer configures a Policies folder and a Claims folder, a support desk configures Tickets, a council configures Permits. None of them waits on a developer, because nothing in Faldaro is specific to a domain — the platform takes the shape of your work.
Folders nest, so the structure can mirror how your organization is actually arranged rather than a flat list of forms. Open one and its forms are listed with what each has collected — how many submissions, and when the latest arrived — so choosing where to work is a glance, not a tour.
### Versions: published means frozen
A form is edited as a draft. Publishing turns that draft into an immutable version and leaves the next edit to a fresh draft. Every submission records which version it was filled against and keeps it forever.
This is what makes editing a live form safe. Change a question, a formula or a workflow and nothing already collected is reinterpreted: old submissions still carry the definition their submitter actually saw. The same rule holds for datasets and document templates.
Immutability protects what exists; it says nothing about whether the next version still behaves. That is what [form test cases](https://faldaro.com/docs/formulas) are for.
### Two kinds of data on every submission
A submission carries submitted data — what the person typed — and calculated data — what the server computed. They are stored separately and never merged, which is the mechanism behind a promise made throughout these docs: a browser cannot fabricate a total, because nothing it sends is ever treated as one. Every write re-runs the engine and every read recomputes for display.
### Organizations, and the tree they form
Every folder, form and submission belongs to an organization. Organizations nest into a tree, and a role granted on one organization also grants its privileges on every organization beneath it — so administering a parent means administering the whole subtree without a separate assignment per child. Nothing flows upward or sideways.
Isolation between organizations is enforced by the database itself, not by application code: a query that loses its organization returns nothing rather than everything. Sharing across organizations is possible and deliberately narrow — see [sharing with partners](https://faldaro.com/docs/sharing).
### Privileges, not roles
Permissions are granted as named privileges (`form:write`, `submission:read`, `billing:read`…) collected into roles you assign to people. The privilege list is defined once by the platform and served to every part of the product, so what the interface offers and what the server enforces can never disagree. You cannot grant a privilege you do not hold yourself.
### The pieces that hang off a submission
| Piece | What it is | Guide |
| --- | --- | --- |
| Workflow | The states a submission moves through, and what each move does | Workflows |
| Documents | PDFs generated from a submission's values | Documents |
| Notifications | Emails a rule or a transition sends | Notifications |
| Payments | Money collected, priced by the form's own rules | Payments |
| Datasets | Reference tables that supply field options | Datasets |
| Reports | Grouped, aggregated questions asked of live submissions | Reports |
| Integrations | Deliveries to Zapier, Slack or your own endpoint | Integrations |
### Two ways in, besides the app
A [public link](https://faldaro.com/docs/public-forms) lets anyone fill a form with no account at all, and an [API key](https://faldaro.com/docs/api-keys) lets another system evaluate and file submissions over [the API](https://faldaro.com/docs/api). Both are bounded by exactly the same privilege checks and isolation as a signed-in person — there is no second, weaker path into your data.
[Previous Getting started](https://faldaro.com/docs/getting-started) [Next Formulas & logic](https://faldaro.com/docs/formulas)
On this page
- The spine: folders → forms → submissions
- Versions: published means frozen
- Two kinds of data on every submission
- Organizations, and the tree they form
- Privileges, not roles
- The pieces that hang off a submission
- Two ways in, besides the app
---
# Formulas & calculations
Source: https://faldaro.com/docs/formulas
How computed fields work: the closed function set, field references, hidden-field semantics, and why totals are recomputed on the server, never the browser.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Formulas & calculations
A computed field carries a formula instead of an input. The server evaluates it on every save and every read — a browser cannot submit a total of its own choosing, and a stale total is never served.
### Writing a formula
Reference other fields by slug in backticks, and combine them with ordinary arithmetic and comparisons:
```
`ticketCount` * `ticketPrice`
`amount1` + `amount2` + `amount3`
40 + (`tier` - 1) * 25 + MAX(0, `tier` - 2) * 60
```
#### Operators
| Operators | Meaning | Binds |
| --- | --- | --- |
| * / % | Multiply, divide, remainder | Tightest |
| + - | Add, subtract (and unary minus) | ↓ |
| > = Equality is a single `=`, not `==`. `AND` and `OR` are words, in capitals. Brackets group as you would expect, and when in doubt they cost nothing.
#### Functions
The function set is deliberately closed: `MAX`, `MIN`, `ROUND`, `ABS`, `FLOOR` and `CEIL`. Formulas are parsed and executed by a small purpose-built evaluator — never handed to a scripting engine — so a formula is data, and there is no formula that can run code.
There is no `IF`. Conditional behaviour is expressed as a rule with conditions rather than a branch inside an expression, which keeps the two readable separately — and arithmetic often does the job on its own, as the `MAX(0, …)` line above does.
#### Text and numbers
String literals use quotes — ``status` = "approved"` — and comparisons work on text as well as numbers. A numeric value that arrived as text is understood as a number, so a dropdown whose values are `"1"`, `"2"`, `"3"` can be arithmetic on without conversion.
### What the engine does with missing values
A field the submitter has not reached yet is absent, and a formula referencing an absent field is not computable — it produces nothing rather than a confident total derived from half a form. Give optional numeric fields a default of `0` when a running total should always show.
A hidden field is different from an unfilled one, deliberately: hiding a field neutralizes its value to zero or empty, so `base + addOn` with a hidden `addOn` yields `base` — the field contributes nothing, but the formula still computes.
When a formula stops being computable, its recorded value is cleared rather than left standing. A figure on screen is always this pass's answer, never a fossil of the last one.
### Rules: everything else logic can do
A formula on a field is the short form. The logic builder holds rules — conditions, and what happens when they hold. The full set:
| Effect | What it does |
| --- | --- |
| Set a variable | Assigns an expression's result to a computed field. |
| Format a value | Writes a presentation string — currency, whole numbers — into a computed field. |
| Show / Hide | Reveals or hides fields. Hidden fields are not required and contribute nothing to calculations. |
| Set an outcome | Raises a named flag with a message — “Needs approval”, “Refer to underwriting”. |
| Set the workflow state | Moves the submission directly, letting logic drive the state machine. |
| Send | Queues a notification or a document. |
| Reference number | Allocates from a sequence — see below. |
| Send to an integration | Queues a delivery to a named connection. |
| Deliver objects | Hands the submitter files. |
| Collect payment | Prices the submission — see payments. |
Note which of these leave the platform — sending, integrations, delivery, payment. Those are recorded during evaluation and performed only when a submission is really saved, because evaluation also runs on previews, on read, and on failed validation. Looking at a form never emails anybody.
### Reference numbers
A reference number is allocated exactly once, from a sequence you define, at the moment a submission is first committed — and never re-allocated. Editing a record does not renumber it, because evaluation only ever asks for a number; the allocation happens on the save path, under a lock, so two simultaneous saves cannot collide on one.
### Server-owned, always
Submitted data and computed data are stored separately and never merged. Every write re-runs the engine; every read recomputes for display. Two recorded exceptions exist because recomputing must not mean forgetting: a reference number is allocated exactly once, and a value a workflow transition set stays set. A live formula always wins over either.
### Prove it before you publish
Form test cases pin named inputs to expected outputs and re-run through the real engine — run them against a draft to answer the only question that matters before publishing: would this change a value somebody pinned down? Comparison is canonical for numbers (`42`, `42.0` and `"42"` agree) and asserts only the keys each case names, so adding an unrelated field never breaks the suite.
Test cases are owner-only authoring tools: a partner an organization shared a form with uses the form rather than maintaining its tests.
[Previous Core concepts](https://faldaro.com/docs/concepts) [Next Workflows](https://faldaro.com/docs/workflows)
On this page
- Writing a formula
- What the engine does with missing values
- Rules: everything else logic can do
- Reference numbers
- Server-owned, always
- Prove it before you publish
---
# Workflows
Source: https://faldaro.com/docs/workflows
Draw the states and moves between them, decide who may take each, attach what a move sets off, and see on every record where it is and why a move is withheld.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Workflows
A submission is a record with a state. A workflow declares the states, the moves between them, and what happens when a move is made — drawn as a picture in the builder, and shown on every record as where it is and what can happen next.
### Building one
The Workflow tab in the form builder is a diagram. States are boxes, laid out left to right by how many moves it takes to reach them from the start; moves are arrows with their button text on them. Select a state or a move and the rail beside the picture edits it; click the paper to deselect. Moves available from any state (a Cancel, say) are listed beneath the picture rather than drawn from every box.
An empty form offers four quick starts — Review and approve, Ticket, Application and To do — each a complete workflow you rename rather than a blank page. Or type a state's name into Add a state: its id is derived from the name (In review becomes `in-review`), never typed, so there is no id to misspell. Picking a quick start on a form that already has states asks first, and Undo brings the old workflow back.
The picture carries a few marks worth knowing:
| Mark | Means |
| --- | --- |
| Play triangle on a box | The start state — where every new submission begins. |
| Flag on a box | A final state. Nothing moves out of it. |
| Clock on a box | The state has a deadline. |
| Lock on an arrow | The move names a required privilege. |
| Funnel on an arrow | The move has a condition. |
| Checklist on an arrow | The move requires fields to be filled in first. |
| Warning triangle | Something to look at, listed under the picture. |
### States
A state has a name, a colour, and two switches. Start state is where new submissions begin — the first state you add takes it until you say otherwise. Final state means the record is finished: the engine refuses every move out of one, so mark a state final only when reopening truly must be impossible. A final state cannot carry a deadline, because a finished record has no clock to run out.
The colour is one of six — grey, blue, green, amber, red, teal — and it is how a state looks everywhere it appears: the box in the diagram, the chip beside a record's title, the status column of the submissions table. The engine ignores it; it exists so Rejected reads as red at a glance without anyone reading the word. Anything outside the six shows as grey.
A state's rail also lists the moves out of it and into it (each a chip that opens the move), and the actions that run when a submission enters or leaves it. Removing a state takes everything that named it — its moves, its actions, and any deadline that fired one of those moves — so the document never keeps a reference to a state that no longer exists.
### Moves
A move — the API and the audit log call it a transition — is a button on the record. It has the text on that button, a from state (or any state) and a to state. Publishing validates the whole graph: every move must connect declared states, and one out of a final state can never be taken, which the builder warns about before the server refuses it.
Three guards decide whether the button shows on a given record:
| Guard | What it does |
| --- | --- |
| Who may take it | A privilege the person must hold, chosen from the catalogue. Leave it on the default and the move needs submission:transition — never nothing. Moving a record and editing its data are separate powers held by separate privileges. |
| Only when | A condition on the record's values, built with the same pickers as a logic rule — field, operator, value — or written as a formula. The button appears only while it holds. |
| Must be filled in first | Fields that must have a value before the move is allowed. The record names the missing ones. |
The engine re-checks every guard when the button is pressed, whatever the page showed. That is what makes it safe for the page to also explain a move it could not offer — see on the record.
### Effects: what a move does
Actions belong to states, not moves: each state has a When entering list and a When leaving list, edited in its rail. The menu that adds one is split in two, because the two halves behave differently.
| Action | Does |
| --- | --- |
| With the move | |
| Set a field | Writes a value or a formula's result onto the submission — a decision, a date, a flag a later move can require. Pick one of the form's fields, or something else to write a key no field displays. |
| Assign to someone | Routes the record to a person picked by name, or to whoever a formula names. Their membership is checked, so a rule cannot hand work to somebody outside your organization. |
| After the move | |
| Send a notification | Queues an email template, chosen by name, to the recipients you tick: the assignee, the owner, the creator, any email field on the form — or a list field of addresses, each email-shaped entry reached (capped at twenty). |
| Generate a document | Renders a PDF template and attaches it to the submission. |
| Request a payment | Prices the form's payment rule now and emails the payer a checkout link — the deposit asked for on approval, not at submission. |
| Request a signature | Emails each named signer their own signing link for a frozen, fingerprinted document — with an evidence trail and a certificate on the signed copy. |
| Request an approval | Emails each named approver their own approve/decline link — no account needed. You choose which move an approval takes, which (if any) a decline takes, and exactly which fields the approver is shown; with several approvers, the move fires once everyone has said yes. |
| Deliver a file | Adds one of your deliverable files to the submitter's download link. |
| Create a linked submission | Opens a record on another form, chosen by name — a claim from a policy — as a draft, since a rule rather than a person is filling it in. The link between the two is kept. |
| Call a webhook | Posts to an https address of your own that an operator has allow-listed. |
| Send to an integration | Queues a delivery to a named connection — never a URL. |
Set a field and assign happen inside the move itself. Everything that leaves the platform happens after the move commits, from a queue with retries: an unreachable mail server delays a notification, it never un-moves the record. Each queued effect is a visible row you can inspect on the submission's Activity tab, not a hope.
A value a move set is remembered rather than recomputed, so a later move can be gated on a flag an earlier one raised — including ``payment_status` = "succeeded"`, which is how work waits for [money to clear](https://faldaro.com/docs/payments), and ``signature_status` = "signed"`, which is how it waits for [everyone asked to sign](https://faldaro.com/docs/esignatures), and ``approval_status` = "approved"`, recorded when approvers decide from their emailed links.
An approval link's power is exactly what you delegated and nothing more: it can take the one move you named per verdict, every data-dependent guard still applies at decision time, and a link opened after the record has already moved on records the verdict without moving anything. The decision — who, when, from where, with what comment — lands on the record's Approvals tab.
### Deadlines
A state can carry a clock: after 2 days without a move, Escalate. You set the wait in hours or days and choose one move that leaves the state; the platform takes that move itself when time runs out, with every check except the caller's privilege, because there is no caller — the authorization happened when someone with `form:write` published it. The move's own rail says when a deadline also fires it.
A deadline fires once per stay in the state, and only for submissions created after the version that declared it was published — publishing one never retroactively arms existing records. A move that loops back into the same state cannot be a deadline's, since re-entry would reset the clock and it would fire forever; a recurring reminder is an [agent's](https://faldaro.com/docs/ai) job.
### What the builder checks
Under the picture, the builder lists what is wrong in plain words, and clicking a line selects the state or move it is about. Two levels:
- Things to fix are what publishing would refuse: a move to a state that no longer exists, two moves sharing an id, a required field the form does not have, a condition the engine cannot parse, a deadline with no move or the wrong one, an action with no template, no form, no file or a webhook that is not https.
- Worth a look is what publishes but almost never means what you meant: a state nothing moves out of that is not marked final (a dead end), a state no move leads to, a move out of a final state, two moves out of one state with the same button text, a button with no text, an action that sets nothing or assigns nobody.
The server runs its own validation at publish regardless; the builder's list is the same rules said earlier, where they can be fixed with one click.
### On the record
A submission's page shows its state as a chip in the state's colour beside the title, and under the header a strip of every state in the order the workflow flows, with the current one lit. The strip is the map and the pin, not a history: a rejected claim never passed through Approved, and the page does not pretend it did.
The moves the person may take right now are the buttons in the header, the first one accented; hovering says where it leads. A move into a final state asks before it is taken, because nothing moves out of one afterwards. Moves that exist from this state but were not offered are listed under the strip with the reason: the privilege it needs, the fields to complete first, or that its condition does not hold — never the condition's text, so the page is not an oracle for the rule behind it.
The [submissions table](https://faldaro.com/docs/submissions) shows the same coloured chips, and above it the workflow's states are a row of counted filters in flow order — how many records sit in each, and one click to see only those. My work groups everything assigned to you by state across every form.
### Everything is audited
Every move lands in the audit log with who, when and what — a deadline's move says the deadline did it — and the log is append-only at the database-permission level. What happened is what the log says happened.
[Previous Formulas & logic](https://faldaro.com/docs/formulas) [Next Field library](https://faldaro.com/docs/field-library)
On this page
- Building one
- States
- Moves
- Effects: what a move does
- Deadlines
- What the builder checks
- On the record
- Everything is audited
---
# Field library
Source: https://faldaro.com/docs/field-library
Save reusable groups of fields and insert them into any form. Insertion copies — slugs deduped, references rewritten — so published forms stay immutable.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Field library
Save a group of fields once — an address block, a signature section, a standard disclosure — and insert it into any form. Inserting copies the fields into the form; nothing references the group afterwards, which is exactly what keeps published forms immutable.
### Saving a group
In the builder, the Field library panel sits beside the palette. Save this page as a group captures the current page's fields under a name and publishes them to your organization's library. Groups version like everything else: editing one clones a draft, publishing replaces the live version, and publishing runs the same field-level checks a form's own publish runs — a group whose fields would be refused on a form is refused as a group, with the same messages.
### Inserting one
Insert copies the group's live fields onto the current page as ordinary fields. The copy is careful about identity: slugs that would collide with the form (or with a previous insertion of the same group) are renamed, and the group's internal references — a total's formula naming its siblings, a summary panel's rows, a cascading picker's parent — are rewritten to match. References to fields outside the group are left alone, so a group's formula may deliberately name a field it expects the form to have.
Each inserted field carries a small provenance stamp recording which group and version it came from. It is a label, not a link: the engine ignores it, and nothing about the form resolves through the group afterwards.
### Styled fields
A field can carry its own look — label and text colours, background, border, accent, corner radius, and a scoped CSS escape hatch — set in the inspector's Style section. Describe a look in plain English and the AI proposes one onto the canvas for you to keep, tune or clear; nothing applies to submitters until you save and publish. Styles render on the public form page and in the builder's preview; the app's own screens keep the app's theme.
A styled field saved to the library is a reusable style: insert it as a new field, or use Copy a saved style in the inspector to put its look onto a field you already have. Styles pass the same publish fence as everything else — colours must be real hex, the CSS is size-capped and may not contain ` A form that changed because somebody edited a library group would break the platform's oldest promise: a published version is immutable, and a submission keeps the definition it was filled against. So insertion copies, editing a group affects only future insertions, and archiving a group breaks nothing that already used it. If you need the same fix in five forms that share a block, update the group and re-insert — the stamp tells you which forms carry which version.
### Who can use it
The library needs the same permission as building forms. Groups belong to your organization and are isolated the way everything else is; they do not travel with cross-organization form shares.
[Previous Workflows](https://faldaro.com/docs/workflows) [Next Datasets](https://faldaro.com/docs/datasets)
On this page
- Saving a group
- Inserting one
- Styled fields
- Copy, deliberately — not reference
- Who can use it
---
# Datasets
Source: https://faldaro.com/docs/datasets
Reference tables that supply a field’s options: importing rows, publishing versions, cascading dropdowns, and how choices are enforced server-side.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Datasets
Reference tables that supply a field's options — a price list, a branch directory, a product catalogue. Maintained in one place, published like a form, and used by any number of forms without copying the list into each.
### Creating and publishing
Under Datasets (`dataset:read` to view, `dataset:write` to edit), create a dataset, then either type rows into the grid or import a CSV. The header row becomes your columns.
Datasets are versioned exactly like forms: you edit a draft and publish it. A form field bound to a dataset offers nothing until that dataset has a published version — the editor warns you when you bind to one that has never been published.
Publishing takes effect immediately on every live form using the dataset. This is the point: correct a price in one place and every form that offers it is correct from the next page load. It is also the thing to be careful about — there is no per-form pinning of a dataset version.
### Importing a CSV
Import replaces the draft's columns and rows; it is not a merge. Quoted fields, embedded commas and doubled quotes are handled, values are trimmed, blank lines are skipped, and a blank header becomes “Column 2”. Importing does not publish — review the draft and publish when it looks right.
A dataset holds at most 50,000 rows. Values are stored as text; a dataset has no column types.
### Binding a field to a dataset
In the form builder, add a combobox field and open its dataset binding: choose the dataset, then the column whose values become the options. Any fixed options on the field are set aside while a dataset is bound, and come back if you unbind it.
Options are served distinct, non-empty and sorted alphabetically — the dataset's own row order is not preserved, and duplicate values collapse to one. Name your values so alphabetical order reads sensibly.
### Cascading dropdowns
A field can filter its options by what was chosen in another field — country then city, category then product. In the binding, set the filter field to the slug of the field supplying the value, and the filter column to the dataset column it should be matched against.
Always set the filter column explicitly. Left empty, the platform falls back to matching against a column named after the other field's slug — which works only if they happen to be identical, and generated slugs never are. The dependent field stays disabled with "Choose the previous field first" until its parent has a value.
Matching is exact and case-sensitive, so the values in the two columns must agree exactly.
### Choices are enforced, not merely offered
When a submission is saved, values on dataset-backed fields are re-checked on the server against the same filtered lookup the form used. A value that is not among the available options is refused — "'City' is not one of the available options" — so a hand-crafted request cannot store a product that is not in your catalogue.
The one deliberate exception: if the dataset has been unpublished or removed, the check is skipped rather than blocking a form nobody can currently fix.
### Archiving
Archiving (`dataset:delete`, held only by administrators unless you grant it) keeps published versions and stops the dataset being offered. Check which forms bind to it first: a bound field whose dataset is gone offers no options, and submitters simply cannot choose anything.
### Datasets are not submissions
A dataset is reference data you maintain, not data people submit. There is no CSV export for datasets, no per-row permissions, and no history beyond versions. If you need to collect and work rows, that is a form — see [working with submissions](https://faldaro.com/docs/submissions).
[Previous Field library](https://faldaro.com/docs/field-library) [Next Reference numbers](https://faldaro.com/docs/reference-numbers)
On this page
- Creating and publishing
- Importing a CSV
- Binding a field to a dataset
- Cascading dropdowns
- Choices are enforced, not merely offered
- Archiving
- Datasets are not submissions
---
# Reference numbers
Source: https://faldaro.com/docs/reference-numbers
Counters that issue formatted references like INV-00001: prefixes, padding, resets, and why a reference is allocated exactly once and never reissued.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Reference numbers
Counters that issue formatted references — INV-00001, CLM-0042 — allocated exactly once per submission and never reissued. A record's reference is the thing people quote on the phone, so nothing is allowed to change it.
### Creating a generator
Under Reference numbers (`sequence:read` to view, `sequence:write` to manage), a generator carries a prefix, a suffix, how many digits to pad to, and where the count starts. The editor previews the next reference as you type, so you can confirm the format without consuming a number.
| Setting | Notes |
| --- | --- |
| Prefix / suffix | Any text — INV-, /24. |
| Digits | Zero-padding, 1 to 20. Five digits makes 00001. |
| Start at | Fixed when the generator is created — use Reset to move the counter afterwards. |
### Using one on a form
In the logic builder, add a rule whose effect is a reference number, naming the generator and the field the value should land in. A rule can override the prefix or suffix for that form alone, which is how one counter serves several document types.
Publishing checks the wiring: a rule that names no generator, names one that does not exist, or names no field to write into is refused with that exact reason.
### Allocated once, and only on a real save
The engine never allocates while it is evaluating. It records that a number is wanted, and the allocation happens on the save path — under a row lock, so two submissions arriving at the same instant cannot receive the same number.
That distinction has consequences you can rely on:
- Previewing a form burns no numbers. Neither does a failed validation, nor simply reading a record.
- Editing a submission never renumbers it. The reference is looked for across every earlier version of the record, not just the one being written.
- The number is server-owned. It is stored as computed data, so no client can supply or alter one.
### Resetting
Reset is the only way to move a counter, and it is deliberately separate from editing: setting it backwards can produce a duplicate reference, so the action is called out in the interface and recorded in the audit log with who did it.
A common legitimate use is the new financial year — change the suffix to `/25` and reset to 1.
### If a generator goes missing
Archiving a generator that a live form still uses does not break submissions: the allocation is skipped and the record saves without a reference rather than failing for the person filling it in. That is deliberate — but it is also why forms cannot be published referencing a generator that is not there. A form that quietly stops numbering its records is worse than one that refuses to publish.
### Imported history
[Importing submissions](https://faldaro.com/docs/submissions) from a CSV records the reference from the file verbatim instead of allocating a new one, so historic records keep the numbers people already know. Set the generator's counter above your highest imported number afterwards, or the next real submission will collide with your history.
[Previous Datasets](https://faldaro.com/docs/datasets) [Next Submissions](https://faldaro.com/docs/submissions)
On this page
- Creating a generator
- Using one on a form
- Allocated once, and only on a real save
- Resetting
- If a generator goes missing
- Imported history
---
# Working with submissions
Source: https://faldaro.com/docs/submissions
Search, filter, assign, archive, export and import the records your forms collect — including exactly what a CSV import deliberately does not fire.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Working with submissions
Finding, filtering, assigning, importing and exporting the records your forms collect. A submission is not a row in a results table — it is a record with a state, an owner and a history.
### Finding things
A form's submission list searches, filters and sorts on the server. Search matches the current revision of each record, deliberately: a value that has since been corrected should stop turning up. Press / anywhere on the page to start typing into it.
When the form has a [workflow](https://faldaro.com/docs/workflows), its states sit above the table as a row of chips in the order they flow, each carrying how many records are in it — the pipeline at a glance. Click a state to narrow the list to it; click it again, or All, to widen back out. The counts are for the whole form, whatever the search box says.
Sorting is available on created date, updated date, name and workflow state — plus any field you have marked indexed or show in list in the form's field settings. Filtering by a field works on those same fields, so if a field cannot be filtered on, that flag is what to change. Field filters match exactly rather than partially; use search for partial matches, or a [report](https://faldaro.com/docs/reports) for anything richer.
Everything is in the URL — the search, the filters, the page. A filtered view is a link you can send to a colleague.
### Four views
The table is one of four shapes the same records take: a board whose columns are the workflow's states (dragging a card takes the exact move the record page offers, guards intact), a calendar placed by created, updated or any date field, and cards. The view rides the URL, so the board itself is a shareable link. More in [Records & sharing links](https://faldaro.com/docs/records-sharing) — along with per-record status links, @mentions, and the submitter portal.
### Reading the table
The columns are the fields the form marks show in list, headed by their own labels, plus the record's status and when it was created and last updated. A wide form scrolls sideways; the name column stays pinned while it does, so every other cell is always read against the record it belongs to. Numbers sit flush right in tabular figures, and a long value truncates with its full text on hover.
Columns lets you hide any of them for today — the choice is remembered per form in your browser and changes nothing about the data; an export still carries every field. A record that has no name yet, such as an empty draft, is listed as Untitled with its number rather than borrowing the form's name.
### My work
My work is everything assigned to you across every form, grouped by workflow state. It is the queue view for people who work records rather than build forms.
### Assigning
Assignment needs `submission:assign` — deliberately a different privilege from editing, because routing work and changing its content are different powers. Assign one record from its detail page, or tick several in the list: a bar with the count, an Assign to picker and Archive follows you along the page until you clear the selection, and up to a hundred records go together. A [workflow transition](https://faldaro.com/docs/workflows) can also assign automatically as part of a move.
Only people who can reach the organization are offered, including those reaching it by inheritance from a parent.
### Moving a record
When the form has a [workflow](https://faldaro.com/docs/workflows), a record's page shows its state as a coloured chip beside the title, a strip of every state with the current one lit, and the moves you may take as buttons in the header — the first one accented as the expected next step. A move into a final state asks first. Moves that exist from this state but were not offered are listed under the strip with the reason: the privilege needed, the fields to complete first, or that the move's condition does not hold. The status column of the list uses the same chips, and the counted chips above the table offer the workflow's states in the order they flow.
### Archiving
Archiving (`submission:delete`) removes records from lists and reads while keeping their versions, files and payment rows intact and auditable. It is not deletion — for scheduled, permanent removal see [data retention](https://faldaro.com/docs/retention).
### Exporting
Export CSV, in the form's menu beside its title, exports the whole filtered result set — not just the page you are looking at — up to 50,000 rows. It needs the `report:export` privilege and a plan that includes exporting.
Columns come from the form's live schema, so a field nobody has filled in still gets an empty column, and the file's shape does not change with its contents. Text cells that begin with `=`, `+`, `-` or `@` are prefixed with an apostrophe so a submitted value cannot execute as a formula in a spreadsheet.
Computed values are not exported. The file carries what people submitted; totals, allocated reference numbers and other server-derived values are not field columns in it. If you need a computed figure in a spreadsheet, build a [report](https://faldaro.com/docs/reports) — reports can select computed fields.
### Importing history
Import CSV (`submission:write`), in the same menu, brings past records in. Column headers are matched to your fields by label first, then slug, case-insensitively, which is what lets a Faldaro export be re-imported unedited.
Every file is previewed before anything is written: a dry run reports what mapped, what was ignored, and the first problem on each bad row. Rows are then imported independently — a bad row is skipped and reported rather than failing the whole file.
| Column | Treated as |
| --- | --- |
| ID, Created, Updated | Ignored. The timeline stays honest — map historic dates into a date field of your own. |
| Reference | Recorded verbatim, so historic records keep the numbers people already quote. |
| Workflow state | Sets the state — and additionally requires submission:transition. Unknown states are refused per row. |
| Anything else | Matched to a field, or listed as ignored. |
Files are capped at 2,000 rows and a larger file is refused rather than silently truncated — split it. Yes/no columns accept true/false and yes/no; blank cells are skipped rather than written as empty. Tick as draft to import records that required-field validation does not yet bind.
#### What importing deliberately does not do
Imported records run through the real engine, so totals are computed and validation applies. But nothing fires:
- No notifications are sent.
- No integrations or webhooks are dispatched.
- No agents run.
- No workflow transitions execute, even when a state is imported.
- No payments are matched and no [deliveries](https://faldaro.com/docs/objects) are minted — imported history has no submitter waiting to claim anything.
- No reference numbers are allocated; the value from your file is used instead.
Loading three years of history should not email three years of customers. Every imported record is marked as imported in the audit log.
Afterwards, set your [reference number](https://faldaro.com/docs/reference-numbers) counter above the highest value you imported, or the next real submission will collide with your history.
### The form's own settings
Two settings that belong to the form rather than to its draft sit under the table, each as one row stating the fact: Partner organizations — whom the form is [shared with](https://faldaro.com/docs/sharing), if anyone — and Data retention — how long its submissions are [kept](https://faldaro.com/docs/retention). Open a row to change it. Everything else about the form is edited in the builder.
[Previous Reference numbers](https://faldaro.com/docs/reference-numbers) [Next Records & sharing links](https://faldaro.com/docs/records-sharing)
On this page
- Finding things
- Four views
- Reading the table
- My work
- Assigning
- Moving a record
- Archiving
- Exporting
- Importing history
- The form's own settings
---
# Records & sharing links
Source: https://faldaro.com/docs/records-sharing
Boards, status links, shared reports and digests, the submitter portal and @mentions — and the one token discipline behind every outward link.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Records & sharing links
Everything a record can become once it may leave the account: a board you drag, a status a submitter tracks, a report page anyone can open, an approval decided from an inbox, a portal, a template. Every outward link follows one discipline — an unguessable, revocable token carrying a curated projection, never the data behind it.
### Views: table, board, calendar, cards
A form's submissions page renders the same result set four ways. The board 's columns are the workflow's own states; dragging a card takes exactly the move the record page offers, through the same endpoint, with every server-side guard intact — privilege, conditions, required fields. A drop the rules withhold explains itself in the column while the card hovers, and a move into a final state asks first. Records that predate the workflow gather in a leading No status column. The calendar places records by created, updated, or any date field; cards are the table as a grid. The chosen view rides the URL, so a colleague can be sent the board itself.
### Status links: “track your request”
Any record can carry a public status page. Mint the link from the record's header (it needs the same privilege as publishing a public link — exposing a record's state is the same class of decision), and whoever holds it sees the record's current stage in your workflow, its reference number, and when it last moved. Never the answers, never who is working on it, never the rules. One link per record, stable across edits; replace retires the old URL everywhere at once.
To send one automatically, write `{{status_link}}` into a notification template. The link is minted lazily, on the first send whose template actually references it — writing the marker into the template is the decision to expose the record's status.
### Approvals by email
A workflow's Request an approval action mails each named approver their own approve/decline link — the person who signs off on requests rarely wants another account, and now they never need one. You delegate exactly one move per verdict when you author the action, and choose which fields the approver's page shows; nothing else from the record ever reaches it. The decision lands with a name, a comment and a timestamp on the record's Approvals tab, a later move can require ``approval_status` = "approved"`, and with several approvers the move waits for every yes while any no reads declined. See [workflows](https://faldaro.com/docs/workflows) for the authoring details.
### Shared reports, embeds, badges and digests
A saved grouped report — counts, sums, averages per category — can be shared four ways: a live read-only page at a tokenized URL, an iframe embed of the same page for your own site, a live badge — a one-number SVG image for READMEs, wikis and docs, served off the same token and available when the report's first count or sum can be honestly totalled — and a daily or weekly email digest to up to twenty addresses whose owners never need an account. A report that lists individual records is refused at sharing time, and a shared report later edited into a listing goes dark rather than serving rows: aggregates travel, records never do. The digest letter itself carries the numbers and a link to the live page when one exists.
### The submitter portal
The portal lets the people who filled your forms in track all their records with nothing but their email address. It is off until you switch it on, per form, by choosing which EMAIL field identifies the submitter — in the form's settings strip, under the submissions table. Only that field ever matches: an address that merely appears somewhere inside a record (a reference, a cc) never unlocks it.
Once enabled, the public form page grows a “track my submissions” affordance. A visitor types their address; if any records match, a link is mailed to that address — possession of the mailbox is the credential — and the page answers identically whether anything matched, so the request itself confirms nothing. The mailed link lasts 24 hours and lists each record's status, exactly what its status page would show.
### Publishing a form as a template
Share as template, in the form's menu, publishes the form's design at a public link anyone can clone from. What travels is the design: fields, calculations, show/hide rules, outcomes, and the workflow's states and moves. What never travels is anything org-local — records, dataset bindings, linked-record fields, notification templates, integrations, recipients. The stripping happens when you publish, not when someone reads, so the published copy never held anything private. Publishing again refreshes the template from your live form at the same link; rotate or remove it any time.
Two ways to put a published template in front of people. The same dialog has a community gallery switch: asking lists your template — after a quick review — on faldaro.com's templates page, attributed to your organization by name, and turning the switch off delists it immediately, approval or not. And a public form link's own dialog can offer visitors cloning: with the per-link switch on and a template published, the form page itself carries a quiet "clone this design" line — every public form becomes a doorway to making one like it.
### Counters, QR codes and link previews
A public form link's dialog also has a response counter switch: on, the public page shows the form's response count as social proof — a number counted server-side, never a window into the records behind it, and off by default like every disclosure here. Every share dialog offers the link as a downloadable QR code (PNG for print, SVG for design tools) — rotating the link orphans every printed code, which is exactly what rotation means. And a pasted `/f/`, `/t/` or `/v/` link unfurls in chat and social apps as a real preview card — the form's name and description, the template's shape, the report's title; never numbers, and never anything from a status, portal, claim or signing link, whose pages must stay out of preview caches entirely.
### Mentions and linked records
Typing `@` in a record's comments offers your organization's members; a mention sends the comment by email with a link to the record and surfaces a “Mentioned you” card on the recipient's dashboard. Every mentioned id is re-checked against membership on the server, mentions are capped per comment, and the write is audited like any other. A linked record field holds a reference to a record of another form — validated on every write to exist, be live, and belong to exactly the declared form — and is deliberately absent from public forms: a picker over your records has no business in front of an anonymous visitor.
### What every link here has in common
A 256-bit token that is the whole of the URL's authority; revocation by rotating it, which kills the old URL everywhere at once; a payload that is a curated projection of exactly what the surface needs; and uniform refusals, so probing a link never reveals whether it existed. On the Free plan these pages — and the notification emails your forms send — carry a small “Powered by Faldaro” line; paid plans remove it. The features themselves ship on every plan — sharing must never hit a paywall.
[Previous Submissions](https://faldaro.com/docs/submissions) [Next Reports](https://faldaro.com/docs/reports)
On this page
- Views: table, board, calendar, cards
- Status links: “track your request”
- Approvals by email
- Shared reports, embeds, badges and digests
- The submitter portal
- Publishing a form as a template
- Counters, QR codes and link previews
- Mentions and linked records
- What every link here has in common
---
# Reports
Source: https://faldaro.com/docs/reports
Group and aggregate live submissions: columns, summaries, date buckets, filter operators, charts, dashboard pins and CSV export.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Reports
Group, aggregate and filter live submissions where they already are. A report is a saved question, not an export — it re-runs against current data every time somebody opens it, and can be pinned to the dashboard as a live widget.
### Building one
A report belongs to exactly one published form, chosen when you create it and fixed thereafter. Under Reports (`report:read` to view and run, `report:write` to build), pick columns or build a grouped summary, add filters, and watch the preview update as you go.
Reports are shared across your organization rather than owned by one person, and they are not versioned: editing one changes it for everybody.
Alongside your form's own fields, six built-in columns are always available: submission number, name, workflow state, created, updated, and who created it. Computed fields are reportable too, marked as such in the picker.
### Two shapes, and they are exclusive
A report is either a list — pick columns, get rows — or a summary — pick groupings, get one row per group with aggregates. Adding a grouping switches the report to the second shape and the chosen columns stop applying.
| Aggregate | Notes |
| --- | --- |
| Count of rows | The only one that needs no field. |
| Distinct values of | How many different values appear. |
| Sum of / Average of | Numeric fields only. |
| Smallest / Largest | Any ordered field. |
Date and date-time fields can be grouped into day, week, month, quarter or year buckets — this is how "submissions per month" is built. Several groupings can be combined.
### Filters
| For | Operators |
| --- | --- |
| Text | is, is not, contains, does not contain, is any of, is empty, is not empty |
| Numbers | = ≠ > ≥ Two behaviours worth knowing: contains ignores case, and is not deliberately includes records where the field was never filled in — "not approved" means exactly that, including the ones nobody has touched.
Filters are validated when you save and again when the report runs, and every problem is reported at once with the field named — "'Amount' is not text, so 'contains' does not apply".
### Charts and the dashboard
A summary with exactly one grouping and a numeric result can be shown as a chart: a date bucket draws a line, anything else draws bars, up to eight series.
Pin a report and it becomes a live dashboard widget for everyone in the organization, showing the first few rows and re-running on its own. Pins are organization-wide, not personal, and keep the order you pinned them in.
### Sharing, embedding, badges, digests
A grouped report can leave the account four ways: a live read-only page at a tokenized URL, an iframe embed of that page for your own site, a one-number SVG badge served off the same link (for READMEs, wikis and docs — available when the report's first count or sum can be honestly totalled), and a daily or weekly email digest to addresses whose owners never log in. All of them serve aggregates only — an ungrouped listing is refused at sharing time, and a shared report later edited into one goes dark rather than serving rows. Details in [Records & sharing links](https://faldaro.com/docs/records-sharing).
### Export
Export CSV needs the `report:export` privilege and a plan that includes exporting; without the plan the button says so rather than failing after the click. Text cells beginning `=`, `+`, `-` or `@` are prefixed with an apostrophe so a submitted value cannot execute as a formula in whoever's spreadsheet opens it, and the file carries a byte-order mark so Excel reads it correctly. Every export is recorded in the audit log before the bytes leave.
### Limits
- Reports built in the interface return up to 200 rows; the display tells you when there are more.
- A report that runs longer than ten seconds is stopped and asks you to narrow it — an expensive question is not allowed to occupy the database indefinitely.
- Only the current revision of each submission is counted, and archived submissions never appear.
- Fields come from the form's live version. Submissions filled against an older version that never had a field show empty for it — nothing is invented for them.
### Beyond reports
A report answers the question you asked. Each form's Insights page goes looking for the questions worth asking — server-computed statistics narrated by AI into ranked findings, with every count backed by a real query, plus outcome prediction from your own history. See [AI & agents](https://faldaro.com/docs/ai).
[Previous Records & sharing links](https://faldaro.com/docs/records-sharing) [Next Data retention](https://faldaro.com/docs/retention)
On this page
- Building one
- Two shapes, and they are exclusive
- Filters
- Charts and the dashboard
- Sharing, embedding, badges, digests
- Export
- Limits
- Beyond reports
---
# Data retention
Source: https://faldaro.com/docs/retention
Set how long a form keeps submissions and Faldaro deletes them permanently on schedule — what is removed, what survives, and how each purge is proven.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Data retention
Set how long a form keeps its submissions and Faldaro deletes them for you — permanently, on schedule, and provably. Retention is off by default: nothing is ever deleted unless somebody sets a window.
### Setting a window
Open the form: below its list of submissions, the Data retention row says what the form does today — Kept forever is how every form starts. Open the row and set a number of days; leave it empty to keep submissions forever.
It sits with the submissions rather than in the builder on purpose: everything in the builder is a draft that changes nothing until you publish, and this is the opposite — it takes effect on save, for records already collected.
The clock runs from a submission's last update, not its creation — a record still being worked on is not deleted out from under the person working it.
Changing this setting requires both `form:write` and `submission:delete`. Scheduling the deletion of every record a form will ever collect is a heavier act than deleting one by hand, so it needs the privilege that permits deletion, not merely the one that permits editing.
### It applies to everything the form has collected
Retention is a property of the form, not of a published version. Setting it today reaches submissions made last year, against versions long since replaced. This is deliberate: a retention promise is about data, and the data you most need to delete is the oldest.
A consequence worth pausing on before you save: setting a short window on an established form can delete a great deal on the next sweep. The setting applies as soon as it is saved, with no publish step in between.
### What deletion actually removes
The record and everything belonging to it:
- The submission and every version of its data
- Uploaded files — the stored bytes, not merely the reference to them
- Generated documents, queued notifications and integration deliveries
- Links to related submissions, and any agent runs against it
Payment records survive, with their link to the submission cleared. Financial history has its own obligations that outlive the record it priced, and quietly destroying it to satisfy a form setting would be the wrong default.
Deletion is permanent. There is no archive, no bin and no undo — that is what makes it worth something to a regulator.
### Provable, in the audit log
Every purge writes an entry to the [audit log](https://faldaro.com/docs/admin) naming the submission and the window it exceeded. Because the audit log is append-only at the database level, “we deleted it on schedule” is a claim you can evidence long after the data itself is gone — which is the half of a retention policy that auditors actually ask about.
### When it runs
A sweeper runs hourly, so deletion happens within about an hour of a record becoming eligible rather than at a fixed time of day. Records are removed in batches, so a large backlog drains over several passes instead of one enormous burst.
Clearing the window, or lengthening it, always wins: a record that is no longer eligible when the sweeper reaches it is left alone. If you set a window by mistake, clear it — anything not yet swept survives.
### Related
- [Export submissions](https://faldaro.com/docs/submissions) before setting a short window if you need a copy.
- Deleting a form archives it and keeps its submissions; retention is the only feature that removes submitted data on a schedule.
[Previous Reports](https://faldaro.com/docs/reports) [Next Documents](https://faldaro.com/docs/documents)
On this page
- Setting a window
- It applies to everything the form has collected
- What deletion actually removes
- Provable, in the audit log
- When it runs
- Related
---
# Documents
Source: https://faldaro.com/docs/documents
Generate PDFs from a submission: block templates, merged values, conditions and repeats, images, versioning and render limits.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Documents
A document template turns a submission into a PDF: a quote, a policy schedule, an inspection report, a receipt. Templates are built from blocks rather than markup, so what a template can do is a closed set the platform fully understands.
### Building a template
Templates live under Documents and are edited as blocks — headings, paragraphs, tables, lists, images, page breaks. Inside text you merge values from the submission by referencing field slugs, and a computed value can be calculated in the template itself using the same expression language as [formulas](https://faldaro.com/docs/formulas).
Blocks can be conditional (show this paragraph only when a condition holds) and repeated (one table row per item). Presentation — currency, whole numbers — is applied after a value is calculated, never inside the calculation, so a formatted figure can never be mistaken for a number to compute with.
Table rows can repeat too — one row per line item of a list-valued field — and a row can carry its own condition, so a totals row appears only when there is something to total. Page setup travels with the template: size, orientation, margins, a typeface and text size, page numbers, and running header and footer lines that can merge submission values.
Templates are versioned like forms: publishing freezes a version, and a document generated against a submission renders through the version that was live for it. Editing a live template starts a new draft and changes nothing already produced.
### Starting from a description or a PDF
Where AI is configured, the editor can draft the template for you: describe it in a sentence, pick the form whose fields it should merge, or hand it the paperwork you send today. A reproduced PDF keeps its structure and wording, its embedded images are extracted into your account's own files and placed where the source shows them, and the page setup — size, margins, typeface — is matched as closely as the block vocabulary allows. Each blank or fill-in area comes back as a merge field. The result lands in the editor unsaved, for you to read and adjust like anything else; a document too rich to reproduce in one template says so rather than returning half of one.
### Exact reproduction: the facsimile engine
When the document must look like the original — a government form, a certificate, a carrier-branded schedule — rebuild-as-blocks is the wrong tool, and the editor has a second one: Reproduce a PDF exactly. The PDF's own pages become the template, line for line and column for column: rules and boxes stay vector-sharp, text stays selectable and editable, logos and icons — every one of them — become ordinary images in your files. Converting is plain computation, not AI, and costs no credits.
You then bind the form on top: click a line to merge a field into it, white-out pre-printed content a value replaces, give any element a condition, or group a row of elements and repeat it per item of a list field — with the same expression language as everywhere else, and nothing that executes code. Where AI is configured, one prompt does the binding pass for you — “make the name, date and policy-number lines merge fields” — and every proposed edit lands on the canvas for your review. The assistant can edit these templates too, through the same operations.
Long values behave like the page was typeset for them: a bound area can soft-wrap into its column and grow its row, pushing everything below down while the row's own background stretches — and growth is capped by the page itself, so when a value would push the page's footer off the edge, the grown text compresses slightly instead.
Typography is matched, not defaulted. The source's typefaces map onto bundled open faces: the geometric sans a branded document is set in lands on one with the full light-to-bold weight hierarchy, and the standard office faces land on metric-compatible equivalents, so column widths hold and substituted lines keep their measure. The editor's canvas and the painted PDF draw from the same font files — what you see while binding is what prints. Bullets and checkmarks drawn in symbol fonts come through as real characters, not the stray letters their raw codes spell.
Honest edges, each reported at conversion rather than discovered later: gradients and fill patterns are left out, a repeated row stops at the limit you set rather than flowing onto continuation pages, and glyphs outside the bundled typefaces print as `?`. Generated PDFs are painted directly from the pages — searchable text, not screenshots.
### Why blocks instead of HTML
The renderer builds the output itself from a closed node set and never parses markup you supply. Every merged value is escaped on the way in, and the PDF converter is denied every external resource — a template cannot make this server fetch anything, and a submitted value cannot smuggle markup into your paperwork.
Templates written as raw HTML before blocks existed keep rendering exactly as they always have. Published versions are immutable, so nothing converts implicitly: the editor converts only when you ask, and nothing changes until you save.
### Images
An image block names a file you have uploaded to Faldaro, never a URL. Uploads are accepted on the strength of the bytes themselves rather than the filename, and are embedded directly into the PDF. This is why a document renders identically for everyone, forever: there is no remote asset to move, expire, or be blocked by a mail client. Images extracted from a reproduced PDF become ordinary files of yours through exactly the same door, subject to the same size checks and storage allowance as a hand upload.
### Generating a document
Documents are produced on demand from a submission, or automatically by a [workflow transition](https://faldaro.com/docs/workflows) or a rule — "when the claim reaches Approved, generate the settlement letter". Generated documents attach to the submission and are listed on it.
Generation happens after the transition commits, so a template that fails cannot un-move a record — and one document blowing its limits never discards the other effects of the same move.
### Limits, and why they exist
Rendering has a budget: how many nodes it visits, how deep they nest, how many rows a repeat may produce, how large the output may grow. Repeat counts come from submitted data, which means an unbounded template is an unbounded amount of work bought with one submission. Ordinary documents never approach these limits.
The renderer skips anything it does not recognize rather than failing — a live document must degrade, not vanish. That tolerance is precisely why publishing is strict: expressions that do not parse, and content that could never render, are refused at publish time, when the author is present to fix them.
### Related
- [Notifications](https://faldaro.com/docs/notifications) share this template engine for email, minus images and page breaks.
- [Digital products](https://faldaro.com/docs/objects) deliver files to submitters, which is a different thing from generating one.
[Previous Data retention](https://faldaro.com/docs/retention) [Next Notifications](https://faldaro.com/docs/notifications)
On this page
- Building a template
- Starting from a description or a PDF
- Exact reproduction: the facsimile engine
- Why blocks instead of HTML
- Images
- Generating a document
- Limits, and why they exist
- Related
---
# Notifications
Source: https://faldaro.com/docs/notifications
Email templates a form’s rules can send: merge values, dynamic recipients including anonymous submitters, the outbox, and why mail sometimes waits.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Notifications
Email templates a form's rules and workflow transitions can send. Written once, referenced by slug, versioned like everything else — and queued rather than sent inline, so a mail server having a bad afternoon never costs you a submission.
### Writing a template
Templates live under Notifications (`notification:read` to see them, `notification:write` to edit). Each has a slug — that is what a rule references — a subject line, and a body built from the same blocks as [documents](https://faldaro.com/docs/documents).
Merge values by wrapping a field slug in double braces, in the subject as well as the body:
```
Order {{reference}} received
```
A placeholder whose value is missing renders as nothing rather than leaving braces in the email. Editing a live template starts a draft; publishing makes a new version and leaves everything already sent alone.
Where AI is configured, the editor can draft the email for you — describe it, pick the form whose fields it should merge, or hand it a document to turn into the email version. The subject line comes back with the body, and both land in the editor unsaved for your review. Email cannot carry embedded images or page breaks, so a reproduced document keeps its wording, structure and tables and says plainly what it left behind.
### What you can merge in
- Anything the submitter typed, by field slug.
- Anything the server computed — totals and other computed fields, the allocated [reference number](https://faldaro.com/docs/reference-numbers), values a workflow transition set, and payment status.
- `{{download_link}}` when the submission has [files to claim](https://faldaro.com/docs/objects) — one link regardless of how many files, since the claim page lists them.
- `{{status_link}}` — the record's public [status page](https://faldaro.com/docs/records-sharing). Minted lazily, on the first send whose template actually references it: writing the marker into the template is the decision to expose the record's status, and templates that never mention it never mint a link.
- `{{approval_link}}` and `{{signing_link}}` — in the templates a workflow's [Request an approval](https://faldaro.com/docs/workflows) and [Request a signature](https://faldaro.com/docs/esignatures) actions deliver, each recipient's own link. Give the link real context around it — the form's name, the fields that matter — or it reads as phishing.
Payment-request emails are the exception worth knowing: they carry `{{payment_link}}`, `{{payment_amount}}` and `{{payment_currency}}` and nothing else — a field slug referenced in that particular template renders blank.
### Two kinds of recipient
The template itself can carry fixed addresses — the ops inbox that should see every one of these. The rule or transition that sends it can add dynamic recipients, written as:
| Recipient | Resolves to |
| --- | --- |
| assignee | Whoever the submission is assigned to. |
| owner | The submission's owning user. |
| creator | Whoever created it. |
| field:emailAddress | The address in that field of the submission — or, for a list field, every email-shaped entry in it, up to twenty. |
`field:` is how you reach an anonymous submitter: a public form has no creator, owner or assignee, so the address they typed is the only way to write to them. A field value that is not a valid email address is skipped — everyone else still receives the message — and a list field's fan-out is capped at twenty addresses, because a submitter-controlled list must not be able to turn one submission into a mailing.
Publishing checks every recipient: a descriptor that is not one of the four above, or a `field:` naming a slug the form does not have, is refused at publish time rather than discovered when nothing arrives.
### Email is not a document
Two blocks are refused in an email template, with the reason given at publish: images, because mail clients strip them, and page breaks, because an email has no pages. Everything else — headings, lists, tables, conditions, repeats, bold, italic, underline and links — behaves as it does in a document.
### The outbox
Sending is queued, never inline. A notification becomes a row that a sender drains on a schedule, retrying up to five times before it is marked failed with the reason kept. You can see exactly what happened on the submission's own Activity tab, where queued messages show as Queued alongside integration deliveries and agent runs.
This is why an unreachable mail server never breaks a submission: the record is already saved, and the email is a row waiting its turn.
### When mail does not arrive
- Sending may be switched off for the deployment. Messages queue and wait rather than being lost — ask your operator whether mail is enabled.
- The monthly email allowance may be used up. Over-allowance messages are held, not discarded: they send when the month rolls over or the plan grows, and a banner tells account holders. Account email — password resets, invitations — is never held.
- No recipient resolved. A message with nobody to send to fails immediately and says so.
- A template that has been archived is skipped by the rules that reference it, and forms cannot be published referencing one.
### When mail arrives in spam
Every message Faldaro sends is structured the way filters want it — HTML with a plain-text twin carrying the same links — so a spam verdict almost always means the sending domain is not authenticated. That is deployment configuration, not template content: the From address must be on a domain the deployment controls (never a `gmail.com` address relayed through another server, which fails alignment by definition), that domain's DNS must authorize the relay (SPF), sign the mail as itself (DKIM), and publish a DMARC record — Gmail requires one of bulk senders outright. Open a received message's Show original in Gmail: SPF, DKIM and DMARC should each say PASS with your domain named. Self-hosting? The operations runbook walks through the exact records per provider.
Content plays a smaller part, but a signing or payment mail is one long tokenized link — exactly the shape phishing takes — so give the template a sentence of real context around it: who is asking, for what, on which form. A near-empty body with a bare link earns suspicion a normal message never sees.
[Previous Documents](https://faldaro.com/docs/documents) [Next Payments](https://faldaro.com/docs/payments)
On this page
- Writing a template
- What you can merge in
- Two kinds of recipient
- Email is not a document
- The outbox
- When mail does not arrive
- When mail arrives in spam
---
# Payments
Source: https://faldaro.com/docs/payments
Collect money through a form with the price computed on the server, paid into your own Stripe account — including splits, refunds and gating work on settlement.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Payments
A form can charge for what it collects. The price is computed by the form's own rules on the server — never sent by the page — and the money moves through Stripe into your own connected account.
### How a price is decided
You do not put an amount in a payment request. A rule on the form carries an amount expression, and the server prices the submitted answers by running the engine over them. When the payment is finally created the amount is derived again and a mismatch is refused.
The request body has no field an amount could even ride in. That is the mechanism behind the guarantee: a modified page, a replayed request or a hand-built API call cannot buy a thousand-pound service for a penny, because the price was never the caller's to state.
### Asking for payment later
Not every payment happens at submission. A [workflow transition](https://faldaro.com/docs/workflows) can carry a Request a payment action: it prices the form's existing payment rule at the moment of the move, freezes that figure, and emails the payer a checkout link through a [notification template](https://faldaro.com/docs/notifications) you name — the deposit asked for when a quote is approved, rather than before anyone has agreed to it.
Both the price and the audience are settled at the moment of asking. The amount and the resolved recipient addresses are stored on the payment row as the transition found them, so editing the submission afterwards cannot change what the link asks for, or who it was addressed to.
The link itself is minted a moment later by the same kind of queue everything else here uses, because the mail's entire content is the URL and a URL cannot be templated before it exists. That is why a payment-request email carries only `payment_link`, `payment_amount` and `payment_currency` — see [notifications](https://faldaro.com/docs/notifications). Checkout links expire after a day by default.
Publishing checks the wiring, as everywhere: a transition that requests a payment on a form with no rule to price it, or names no template, or names one that does not exist, or names nobody to send it to, is refused with that exact reason.
Completion arrives exactly as it does for a payment taken at submission — from Stripe's signed confirmation — and records the same values. A later transition can gate on payment having succeeded without knowing which of the two ways it was collected.
### Connecting an account
Payments go into your Stripe account, connected under Settings → Payments. Faldaro never holds your money and no Faldaro API response ever carries a Stripe secret — the publishable key is the only Stripe credential that reaches a browser.
Recipient accounts resolve in the organization that owns the form. This is the deliberate inverse of how integrations resolve: a notification belongs to whoever submits, but the payment belongs to whoever authored the price. A partner submitting against a form you shared with them pays you.
### Splits
A payment can be divided between several connected accounts. The split is frozen in whole cents at the moment the payment is created, using largest-remainder rounding so the parts sum to the total exactly. Editing the split configuration later cannot change what an already-charged payment pays out.
Payouts to recipients are queued by Stripe's own confirmation that the charge succeeded — never by the browser returning from checkout. The system this replaced paid recipients from a success callback, which meant a closed tab was a missed payout.
### What the submission records
Completion lands on the submission as computed values, so the rest of the platform can act on it without knowing anything about Stripe. The most useful consequence: a workflow transition can require that payment succeeded before a record may move —
```
`payment_status` = "succeeded"
```
…and [digital delivery](https://faldaro.com/docs/objects) uses the same fact to decide whether files are released.
### Refunds
Refunds are full-amount and operator-initiated, from the payment record in the app. Running a refund twice is safe: the second attempt lands on Stripe's idempotency cache rather than refunding twice, so a double-click costs nothing.
A refund also reverses every split transfer that has already been sent, recording each reversal as it lands. If one reversal fails, its error is recorded and running refund again retries just that part — the refund itself is not repeated.
A refund issued from the Stripe dashboard instead reverses nothing: Stripe does not know about your splits. Faldaro records that fact on the payment — how many sent transfers were left unreversed — and only that fact. Refund from Faldaro when splits are involved.
### Payments on public forms
An anonymous submitter can pay: the amount is still priced server-side from their answers, and delivery of anything sold is gated on settlement rather than on the browser reaching a success page. See [public forms](https://faldaro.com/docs/public-forms) and [digital products](https://faldaro.com/docs/objects).
### What is not supported
- Partial refunds — refunds are full-amount only.
- Subscriptions or recurring charges on a form. (Your own Faldaro subscription is separate: see [billing](https://faldaro.com/docs/billing).)
- Payment methods Stripe does not offer in your account's country.
[Previous Notifications](https://faldaro.com/docs/notifications) [Next E-signatures](https://faldaro.com/docs/esignatures)
On this page
- How a price is decided
- Asking for payment later
- Connecting an account
- Splits
- What the submission records
- Refunds
- Payments on public forms
- What is not supported
---
# E-signatures
Source: https://faldaro.com/docs/esignatures
Request signatures from a workflow: per-signer links, a frozen and fingerprinted document, an evidence trail, and a certificate page on the signed PDF.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## E-signatures
Ask someone to sign — a countersignature on an approval, an agreement, a waiver — from a workflow. Each signer gets their own link, the platform records who signed what and when, and the signed PDF carries a certificate page stating exactly that.
### Requesting a signature
A signature is asked for by a [workflow](https://faldaro.com/docs/workflows) action: Request a signature, on entering a state — Awaiting signature, typically. You choose the notification template that carries the link, who signs (the assignee, the owner, the creator, or any email field on the form — a customer's own address, usually; a list field of addresses asks each email-shaped entry, up to twenty), and optionally which [document template](https://faldaro.com/docs/documents) they sign. Name no document and the signer is shown a generated summary of the record instead. Each recipient becomes their own request, with their own link and their own evidence trail; re-entering the state never mails a second, competing link to someone whose request is still open.
The email's template carries `{{signing_link}}` the way a payment request carries its checkout link, and can merge `{{form_name}}`, `{{signer_email}}` and the submission's own field values — so the mail can say who is asking and for what, which matters for [deliverability](https://faldaro.com/docs/notifications): a bare link with no context is the shape spam filters distrust most. The notification editor's Start from panel offers a ready-made Signature request template with exactly that structure. You can also set the consent wording the signer agrees to (there is a sensible default) and how long the link lives — 30 days unless you say otherwise, up to a year.
### What the signer signs is frozen
At the moment the request is sent, the document is rendered once, stored, and fingerprinted — its SHA-256 digest is recorded on the request, and shown on the signing page. The signer reviews and signs those exact bytes: later edits to the record or the template change nothing about what their link shows, because a signature over a moving target would attest nothing. Before the signed copy is assembled, the platform re-reads the stored bytes and re-checks the digest; if they no longer match, it refuses to produce a certificate rather than certify something the signer never saw.
### The signing page
The link opens an ordinary page — no account, no sign-in; the unguessable link is the whole of the signer's authority, the public-form discipline. It shows who the request was sent to, the document to review, its digest, and the consent wording. The signer types their name, draws their signature (or types it — the typed name is rendered as a signature, for anyone who cannot draw with a pointer), ticks the consent box and signs. They can equally decline, with a reason, and the requester sees both the refusal and the reason. A link that was cancelled, expired or never existed reads identically: not available. A link already signed keeps working — revisiting it shows when they signed and, once it is ready, offers their signed copy.
### The evidence, and the certificate
Signing records the signer's stated name, the drawn signature, the consent wording as it was shown, and the when-and-from-where: timestamps for sent, first viewed, consented and signed, plus the signer's IP address and browser. The signed copy is then assembled — the frozen document, untouched, followed by a signature page and a certificate of completion stating the document's digest, the signer's identity claim, the timeline and the consent text. It lands on the record's Documents tab like any generated PDF, and the signer can download their own copy from their link. Every step is written to the [audit log](https://faldaro.com/docs/admin), with the signer — `signer:their@address` — as the actor.
This is a standard electronic signature with a recorded evidence trail — the kind most business paperwork runs on. It is not a certificate-based digital signature (eIDAS “qualified” signing), and Faldaro does not verify the signer's identity beyond their control of the mailbox the request was sent to.
### Gating work on the outcome
The outcome is recorded on the submission as `signature_status` — `requested`, `signed` or `declined` — written by the server and only the server: a submitter sending the key themselves is ignored, exactly as with payment status. A transition can therefore require ``signature_status` = "signed"` before it can be taken. With several signers, `signed` means everyone asked has signed; one refusal reads `declined`; cancelled and expired requests drop out of the reckoning, so a mis-addressed request never holds the gate hostage — cancel it and ask again.
### Managing requests
The record's Signatures tab lists every request with where it stands — queued, awaiting signature (and whether it has been viewed), signed, declined, cancelled, expired. From there you can copy the link, re-send the email (the same link, so nothing the signer already has goes stale) or cancel, which stops the link resolving at once. Requests never disappear: they are evidence, and cancellation is a status, not a deletion.
### The signature field is a different thing
A Signature field on a form — the draw-here box a submitter fills in as part of submitting — is available on every plan and involves no request, no link and no certificate: it stores the drawn image with the submission. Signature requests — the links, the evidence trail, the certificate — are included in the Team plan and above. The plan gates publishing a form that asks for signatures; requests already sent keep working whatever happens to the subscription, and the signing page never behaves differently because of it.
And when what you need is a decision rather than a signature — a manager's yes or no, not a legally attested document — use the Request an approval action instead: the same emailed-link shape, on every plan, whose verdict takes a workflow move you chose. See [Records & sharing links](https://faldaro.com/docs/records-sharing) and [workflows](https://faldaro.com/docs/workflows).
[Previous Payments](https://faldaro.com/docs/payments) [Next Digital products](https://faldaro.com/docs/objects)
On this page
- Requesting a signature
- What the signer signs is frozen
- The signing page
- The evidence, and the certificate
- Gating work on the outcome
- Managing requests
- The signature field is a different thing
---
# Digital products & delivery
Source: https://faldaro.com/docs/objects
Deliver files to submitters with a claim link that needs no account, gated on payment when the submission’s own rules priced one.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Digital products & delivery
Upload a file once, then let a form hand it to whoever qualifies — on submission, on a workflow move, or only once payment has settled. The submitter needs no account: their claim link is the whole of their authority.
### Objects
An object is a file in your library — a guide, a template pack, a licence key file, a recorded session. They live under Deliverable files, have their own read and write privileges, and are deliberately separate from files submitters upload: an object's lifetime is yours, not a submission's.
### Delivering one
A rule on the form or an action on a [workflow transition](https://faldaro.com/docs/workflows) delivers named objects to the submission. Delivery is by object, not by URL, and a form cannot be published naming an object that does not exist in your organization.
Delivering the same object twice does not duplicate it, and re-running the rules on an edit does not mint a second claim: the submitter's link is created once and stays stable for the life of the record — the same discipline as a reference number.
Previews, drafts and read-only evaluations deliver nothing. A claim exists only when a submission is really saved.
### The claim link
Delivery produces one link per submission, carrying an unguessable token. Anyone holding it can download the delivered files — there is no account, no password and no session involved, which is what makes it work for an anonymous submitter.
Put it in a [notification](https://faldaro.com/docs/notifications) with the `download_link` merge value, and send that notification to the submitter — a recipient can be a field on the form itself, which is how an anonymous filler receives their own files.
Downloads are rate-limited per link rather than per visitor, which bounds what a link that spread too far can extract. Files are served as attachments with a checked content type, so nothing delivered can execute in a browser.
### Gating on payment
If the submission's rules priced a [payment](https://faldaro.com/docs/payments), its delivery is held until that payment succeeds; the link works, the files are simply not released yet. Once Stripe confirms settlement, the same link starts working — nothing has to be re-sent.
The gate is decided per submission from what its own rules actually priced, not from the form in the abstract. So a conditional charge that priced nothing for this submitter — a free tier, a waived fee — does not gate their delivery forever.
### Sharing and revocation
Delivery works on forms [shared with a partner organization](https://faldaro.com/docs/sharing): their submitters receive your objects, and a claim already handed out keeps working even if the share is later withdrawn. Possession of the claim is the grant — revoking a share must not break a promise already made to somebody's customer.
Deleting an object does revoke past deliveries, deliberately: the alternative is a claim page promising a file whose bytes are gone. An object still delivered by a live form cannot be deleted until you remove it from those forms.
To change what an object contains — a corrected edition, or a file whose bytes were lost from a server's own disk — use Replace on the Deliverable files page rather than uploading again. The object keeps its id, so every rule that delivers it, every claim link already sent and every past delivery serves the new file; nothing has to be re-pointed. A download whose bytes are missing says so on the record, with Replace as the fix.
### What is not delivered
Only library objects an author chose to deliver. Files submitters uploaded and documents generated for internal use are never reachable through a claim, and nothing uploaded through a public form can be read back out of it.
[Previous E-signatures](https://faldaro.com/docs/esignatures) [Next Public forms](https://faldaro.com/docs/public-forms)
On this page
- Objects
- Delivering one
- The claim link
- Gating on payment
- Sharing and revocation
- What is not delivered
---
# Public forms
Source: https://faldaro.com/docs/public-forms
Tokenized public links: how anonymous submission works, what a public form deliberately withholds, link rotation, captcha, translations and branding.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Public forms
A form is never reachable anonymously just because it exists. A public link is an explicit act: an unguessable token that renders the form to whoever holds it — and deliberately nothing more.
### Links and rotation
Someone holding the publish privilege issues a link per form. The URL carries a 256-bit token rather than the form's id, so the space cannot be walked; rotating the link invalidates the old URL instantly, which is the recovery for a link that spread further than intended. Every refusal — revoked, rotated, never existed — is an identical 404, so probing learns nothing. A link is one of two ways into a form without an account; the other is the form's own email address — see [Email-to-form](https://faldaro.com/docs/inbound-email).
The share panel does more than copy the URL: it offers an iframe embed, a downloadable QR code (PNG for print, SVG for design tools — rotating the link orphans every printed code, which is exactly what rotation means), and two per-link switches, both off by default. Offer cloning puts a quiet "clone this design" line on the public page — shown only while the form also has a [published template](https://faldaro.com/docs/records-sharing). Response counter shows the form's response count on the page as social proof — a server-counted number, never a window into the records behind it. Pasted links also unfurl as a real preview card in chat and social apps: the form's name and description, which the page already shows every visitor.
### What a public form withholds
The anonymous payload is a sanitized schema: computed fields are marked computed but their formulas are withheld, the logic and workflow documents are not sent at all, and settings are a curated subset. A public form must not become an oracle for the pricing or the decisioning behind it. A link's owner can opt in to live evaluation — computed values only, never the formulas — for forms that should show a running total.
### Submissions, uploads and spam
Anonymous submissions run the same engine and validation as any other. File upload exists only when the live schema declares a file field, and nothing uploaded is readable back through the public surface. A built-in per-instance throttle bounds runaway scripts, and the operator can require a captcha on submission — one that fails closed when its provider is unreachable, because a captcha that waves submissions through during an outage is decorative.
### After they submit: tracking and the portal
A public form can hand its submitters more than a thank-you. Mint a per-record status link — or merge `{{status_link}}` into the confirmation email — and they watch their own record move through your workflow. Switch on the submitter portal and the form page grows a “track my submissions” box: they type their email, and a secure link mailed to that address lists every record filed under it. Both are covered in [Records & sharing links](https://faldaro.com/docs/records-sharing).
### In your submitters' language
A form can carry a translation per language. In the builder's Public form tab, pick a language and fill in your wording beside each string: the form's own name and description, page titles, field labels with their help text, placeholders and tooltips, the labels on each choice, the submit button and the message after submitting. Choice values are never translated — translating a label must not change what a submission records.
Substitution happens on the server, one language at a time, chosen by the `?lang` in the URL or the visitor's own browser setting. The tables themselves never reach the browser, which keeps the rule the rest of this page describes: a translation can only restate something already public. Translations publish with the version, so an unfinished one cannot change a live form, and a string you leave blank falls back to your original — a half-finished translation degrades rather than breaking.
#### Translate it with AI
Rather than typing a hundred boxes, choose a language and press Translate. The whole form comes back translated, into the same editor, for you to read before you save — nothing reaches a submitter until you save and publish it yourself.
It fills gaps only. A string you wrote by hand is never sent to the model and never overwritten, so running it again after you add a field translates the new strings and leaves the rest exactly as you left them. The translation is prompted as form wording — short enough for a label or a button, keeping your punctuation and capitalization, leaving proper nouns and product names alone. It costs AI credits like any other AI feature, and it appears only where AI is configured. See [AI](https://faldaro.com/docs/ai).
#### Faldaro's own words, too
Where a form has any translation, the page offers a language picker naming each language in its own words; answers already typed survive the switch. Everything on that page that is ours rather than yours is translated with it, in twenty-four languages — the buttons and the step counter, the notice when answers are put back from a previous visit, the refusals, the sub-labels inside an address or contact field, the file chooser, and the payment step — including Stripe's own card form, wherever Stripe carries that language. A date picker is localized properly rather than merely worded: month and weekday names in the reader's language, dates written in their own order, and the week starting on the column their country starts it on.
The list is Czech, Danish, Dutch, English, Finnish, French, German, Greek, Hindi, Indonesian, Italian, Japanese, Korean, Norwegian, Polish, Portuguese, Romanian, Russian, Simplified Chinese, Spanish, Swedish, Turkish, Ukrainian and Vietnamese. You can still type any language code by hand to translate a form into something outside that list; Faldaro's own words around it stay English rather than showing blanks. Right-to-left languages are not offered yet: the public page does not lay out right-to-left, and we would rather say so than ship a picker that promises it.
### How it looks
Unstyled, a public form is a sheet on a desk: the form's name in the display face, the fields on a card that floats on a soft shadow rather than inside a drawn border, and one pool of the accent colour falling from the top of the page. The pool is painted from whatever accent the form has — the organization's, or its own — so a brand colour reaches the page without any further setting, and it steps aside the moment you choose a page colour or write your own CSS.
### Your branding
Under Settings → Branding, set an accent colour and a logo; public forms wear them. A form's own appearance — colours, corner radius and CSS scoped to the form page, all in the builder's Style view on the Design tab — always wins, and the organization brand fills in when a form styles nothing. On paid plans the "Powered by Faldaro" attribution disappears.
[Previous Digital products](https://faldaro.com/docs/objects) [Next Partner sharing](https://faldaro.com/docs/sharing)
On this page
- Links and rotation
- What a public form withholds
- Submissions, uploads and spam
- After they submit: tracking and the portal
- In your submitters' language
- How it looks
- Your branding
---
# Partner sharing
Source: https://faldaro.com/docs/sharing
Share a folder or a single form with another organization: access levels, what a recipient can and cannot do, and why submissions never cross.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Sharing with partner organizations
Let another organization on Faldaro see and use your form, without merging accounts and without either side seeing the other's submissions. Sharing is deliberately narrow: you share a definition, never data.
### Two grains
Share a folder when a partner should work with everything in it, or a single form when a folder holds ten forms and only one is theirs. Both are found on the thing being shared — a folder's under its list of forms, a form's under its list of submissions, each as a Partner organizations row that says whom it is shared with — and both target a partner by their organization's short name.
Where both apply, the stronger level wins. Folder sharing needs `folder:share`; form sharing needs `form:share`.
### Access levels
| Level | The partner may |
| --- | --- |
| View | Open the form and see how it is built. They cannot submit against it. |
| Submit | Everything View allows, plus filing submissions of their own. |
There is no “manage” level. Cross-organization editing is blocked in the database itself, so a level that promised it would be a promise the platform could not keep — it is refused when you try to grant it rather than accepted and quietly ignored.
### What the partner sees
A recipient sees the folder shell and exactly the form shared with them — never its siblings. They can read the definition, because they must in order to render it, and that is the limit:
- They cannot edit it. Only the owner writes the definition.
- They cannot share it onward, or create public links for it.
- They never see your submissions, and you never see theirs.
### Submissions stay with whoever made them
This is the asymmetry worth understanding before you share anything: definitions cross organizations, submitted data does not. A partner filing against your form owns those records; they are stored in their organization, count against their allowances, and are invisible to you.
Two consequences follow. Their submissions trigger their integrations, resolved in their organization — a form you shared fires their CRM, and your hook URL is never reachable from it. But [payments](https://faldaro.com/docs/payments) resolve the other way, in the organization that owns the form: you authored the price, so you are paid. Each rule follows from whose thing it actually is.
[Digital delivery](https://faldaro.com/docs/objects) also works across a share, and a claim already issued survives the share being withdrawn.
### Withdrawing a share
Remove the share and the partner immediately loses sight of the form. Submissions they already made remain entirely theirs — withdrawing your form does not reach into another organization's records.
### Not the same as child organizations
Sharing connects two independent organizations. If instead you run several entities that you administer — branches, subsidiaries, chapters — use child organizations, where a role on the parent grants its privileges throughout the subtree. See [administration](https://faldaro.com/docs/admin).
[Previous Public forms](https://faldaro.com/docs/public-forms) [Next Users & roles](https://faldaro.com/docs/admin)
On this page
- Two grains
- Access levels
- What the partner sees
- Submissions stay with whoever made them
- Withdrawing a share
- Not the same as child organizations
---
# Users, roles & organizations
Source: https://faldaro.com/docs/admin
Privileges and roles, how permissions inherit down the organization tree, inviting people, deactivating them, and the audit log that records it all.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Users, roles & organizations
Who can do what, and where. Permissions are named privileges collected into roles, roles are granted in an organization, and an organization's roles reach every organization beneath it — never above.
### Privileges and roles
A privilege is one named power: `form:write`, `submission:read`, `billing:write`. A role is a bundle of them that you grant to a person in an organization. The privilege list is defined once by the platform and served to the interface, so what a screen offers and what the server enforces can never disagree.
Four built-in roles ship with every organization and cover most needs:
| Role | Holds |
| --- | --- |
| Administrator | Full access, including users, roles, billing and organizations. |
| Editor | Builds and publishes forms, manages submissions, datasets, documents and notifications. |
| Contributor | Reads forms; creates and edits submissions. |
| Viewer | Read-only: forms, submissions, datasets. |
Built-in roles cannot be edited — they are shared by every organization on the platform. Create your own role when you need a different shape; it belongs to your organization and can be assigned throughout its subtree.
### You cannot grant what you do not hold
Creating a role, editing one, or assigning one is refused unless you hold every privilege involved. The refusal names exactly which privileges you are missing. In the roles screen, privileges you do not hold appear locked rather than hidden, so the boundary is visible rather than mysterious.
This is what stops an administrator of one corner of the tree minting a role that reaches further than they do. It applies to removal too: you cannot revoke a role wider than your own.
### The organization tree
Organizations nest. A role granted on an organization grants its privileges there and in every organization beneath it — which is what lets one administrator run a whole group without a separate assignment per entity. Nothing inherits upward or sideways: a role in a subsidiary says nothing about the parent.
Consequences worth knowing:
- A person can appear in a child organization's user list via a role on an ancestor. Those grants are labelled with where they came from and can only be revoked there.
- Roles defined on a parent can be assigned in a child, but only edited where they were defined.
- Newly created child organizations become reachable after a session refresh — privileges are resolved when a session is issued.
- A person switches between the organizations they can reach from the account menu, or with Switch to on the Organizations page. Switching to somewhere unreachable is refused outright rather than quietly landing elsewhere.
The Organizations page shows the tree beside whichever organization is open: its short name (what a partner types to share with it), who holds a role there and where each role came from, its recent history, and the verbs — rename, add a child beneath it, invite someone into it, switch to it. The Users page can likewise show another organization's members when the tree has more than one, and everything done there — invite, grant, revoke — lands in the organization on screen. Neither needs you to switch first.
Child organizations require the Business plan. Renaming an organization never changes its short name, so partner shares and links keep working.
### Inviting people
Invite by email address from Users (needs `user:write`), choosing the role they should hold — or from Organizations, straight into a child organization. Two things happen depending on who the address belongs to:
- A new address gets an account with no password and an invitation link. Their role is granted immediately, so they arrive already able to work.
- An address that already has a Faldaro account is simply added, and told so. No password link is ever sent to a working account — a message inviting somebody to set a password on an account they already use is indistinguishable from a phishing attempt.
Invitation links last seven days, and issuing a new one invalidates any earlier unused link. Accepting sets a password of at least twelve characters, marks the address verified — following the link is the same evidence verification asks for — and ends any other sessions. An account showing as Invited is one nobody has accepted yet.
Seats are counted from the invitation, not the acceptance. An invited person occupies a seat while their link is outstanding.
### Deactivating someone
Deactivating an account (`user:write`) does four things at once: sign-in stops working, every live session ends immediately, every API key that person created in this organization is revoked, and their seat is freed. The account is archived rather than deleted, so the audit log keeps naming them accurately.
Keys they created in a different organization are that organization's to revoke — deactivation reaches only where you administer. Reactivating runs a seat check, so it can be refused if the organization is now at its limit.
You cannot deactivate yourself, and you cannot remove your own last role in an organization. An organization whose only administrator locks themselves out has nobody left to undo it.
For a lost laptop or an offboarding checklist where the account should survive, ending sessions without deactivating is the lighter tool.
### The audit log
Audit log (`audit:read`) records who changed what and when. It is append-only at the database permission level: the application cannot rewrite or delete an entry, and neither can anyone using it. How much history remains visible depends on your plan.
The log is grouped by day and can be narrowed by who made the change, by action, by the kind of thing changed, by one thing's whole history, and by date. Every row is itself a filter: press the person to see everything they did, or the thing to see everything that happened to it. Machine actors are named for what they are — an API key by its prefix, an agent by its id, the anonymous public surface as such — and `api-key:` or `agent:` in the Who box finds every change made through any key or any agent. Filters live in the address, so a narrowed view can be bookmarked or sent to a colleague, and each entry's recorded details open in place.
Sign-in events — successful and failed logins, lockouts, session revocations, refresh-token reuse — are recorded alongside, which is what makes "who got into this account, and when" answerable after the fact.
[Previous Partner sharing](https://faldaro.com/docs/sharing) [Next Single sign-on](https://faldaro.com/docs/sso)
On this page
- Privileges and roles
- You cannot grant what you do not hold
- The organization tree
- Inviting people
- Deactivating someone
- The audit log
---
# Single sign-on
Source: https://faldaro.com/docs/sso
Set up OIDC single sign-on with your identity provider, and why a session it opens can only ever act in your own organization.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Single sign-on
Members sign in through your own identity provider over OIDC. Your directory decides who gets in, your policies decide what they prove, and a session your provider opens can only ever act in your organization.
### What you need
An OIDC application in your identity provider — Entra ID, Okta, Google Workspace, Auth0, Keycloak and anything else that speaks standard OIDC discovery. From it you need three things: the issuer URL, a client id and a client secret.
Your Faldaro operator supplies one thing in return: the redirect URI to register in that application. Ask for it before you start; the configuration page shows the sign-in link once SSO is enabled.
Single sign-on is an Enterprise capability, and the identity-provider host must be allowed by the deployment — a deliberate operator step, so that no organization can point this server at an arbitrary address on its own.
### Setting it up
1. In your identity provider, create an OIDC web application and register the redirect URI your operator gave you. Request the `openid` and `email` scopes.
2. In Faldaro, open Settings → Single sign-on and enter the issuer URL, client id and client secret. Requires `organization:write`.
3. Save with Enabled ticked. The page then shows the sign-in link to distribute — members can also use Use single sign-on on the sign-in page and enter your organization's short name.
The issuer must be an `https` URL with no query or fragment; a trailing slash is trimmed for you. The client secret is write-only: it is stored, used for the sign-in exchange, and never shown again — leave the field blank when editing to keep the one already saved.
### Who can sign in
Someone signing in through your provider must already have a Faldaro account with that email address, and must already be a member of your organization. There is no automatic account creation: an address your provider asserts that matches no member is refused, not provisioned. Invite people the normal way; SSO governs how they authenticate, not whether they exist.
That is a deliberate choice rather than a missing feature — auto-creating members on a directory's word raises real questions (which role, counted against which seats, deactivated when) that deserve a decision rather than a default.
### The session your provider opens
A session established through your identity provider is scoped to your organization and the organizations beneath it, and stays scoped for its whole life — including across every silent renewal.
This matters when a person belongs to more than one organization on Faldaro. Your provider is authoritative for your organization; it is not authoritative for a different company that the same person also works with. So an SSO session cannot see or switch into their other memberships, and an administrator of your identity provider cannot mint access to somebody else's tenant by asserting an address. The same person signing in with a password still sees everywhere they belong.
### Multi-factor, and what SSO delegates
Faldaro does not second-guess your provider. Whatever it enforces at sign-in — MFA, device posture, conditional access, IP restrictions — is what gates entry, and Faldaro trusts the result. This is usually the point of adopting SSO: the controls live in one place, applied to every application at once.
### When sign-in fails
Every failure returns to the sign-in page with a single, undifferentiated message. That is deliberate: a stranger probing the endpoint learns nothing about which organizations exist, which have SSO, or which addresses have accounts. Administrators diagnosing a real problem should check, in this order:
- The redirect URI registered in the provider matches the one your operator gave you, exactly.
- The issuer URL is the provider's own issuer — its discovery document must agree.
- The client secret is current (rotating it in the provider means re-entering it here).
- The person has a Faldaro account with that address, and is a member of your organization.
- The deployment allows your provider's host — ask your operator.
Turning Enabled off stops new SSO sign-ins immediately, including any that are mid-flight. Password and passkey sign-in continue to work throughout: enabling SSO adds a way in, it does not remove the others.
[Previous Users & roles](https://faldaro.com/docs/admin) [Next Integrations & webhooks](https://faldaro.com/docs/integrations)
On this page
- What you need
- Setting it up
- Who can sign in
- The session your provider opens
- Multi-factor, and what SSO delegates
- When sign-in fails
---
# Integrations & webhooks
Source: https://faldaro.com/docs/integrations
Connect Zapier, Slack or any HTTPS endpoint. How deliveries retry, what the payload carries, and how to verify the X-Faldaro-Signature header on your receiver.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Integrations & webhooks
A connection is where forms send data when something happens: a Zapier catch hook, a Slack channel, or any HTTPS endpoint you run. Deliveries are queued rows first and network calls second — retried with backoff, visible in a log, and impossible for a rolled-back save to have fired.
### Connections and slugs
Create a connection under Integrations in the sidebar, paste the destination URL, and reference the connection from rules and workflow actions by its slug — never by URL. The URL is a credential and is never echoed back by any API; a shared form resolves the slug in the submitting organization, so your partner's `crm` fires their connection, not yours.
### What a delivery carries
Zapier and webhook deliveries POST a JSON envelope: an `eventId` to deduplicate on (delivery is at-least-once), the `eventType` (`submission.created`, `submission.updated`, `submission.transitioned`), the form, the submission's data and computed values, and — for transitions — which state it left and entered. Slack deliveries fold the same envelope into a proper card at the last moment — the record's name, stage and leading fields, with an “Open record” button back into Faldaro — while the stored row keeps the full envelope either way.
### Verifying a webhook delivery
Zapier and webhook connections are signed. Each request carries:
```
X-Faldaro-Signature: t=1755600000,v1=
X-Faldaro-Event-Id: 4f6c…
X-Faldaro-Delivery-Attempt: 1
```
The signature is HMAC-SHA256, keyed with the signing secret shown once when the connection was created, over the string `. `. To verify: read `t` and `v1` from the header, compute `HMAC_SHA256(secret, t + "." + body)` over the raw bytes you received, and compare constant-time. Refuse a `t` more than a few minutes old — the timestamp is the replay defence.
```
# Node
const [t, v1] = sig.split(',').map(p => p.split('=')[1]);
const expect = crypto.createHmac('sha256', secret)
.update(`${t}.${rawBody}`).digest('hex');
crypto.timingSafeEqual(Buffer.from(v1), Buffer.from(expect));
```
### Retries and failure
A failed delivery retries on an exponential backoff with jitter, up to six attempts. A 4xx answer other than 408/429 is terminal — the endpoint said the request itself is wrong, and the row records the endpoint's own words. Every delivery, sent or failed, is a row on the connection's delivery log.
### Operator allow-lists
The server only ever connects to hosts an operator has allow-listed — `hooks.zapier.com` and `hooks.slack.com` by default, and nothing for generic webhooks until `WEBHOOK_ALLOWED_HOSTS` names your endpoints. HTTPS only, resolved addresses checked, redirects never followed: a form author must not be able to make the platform issue requests to arbitrary places.
Everything on this page is Faldaro calling out. For mail coming in — a forwarded message becoming a submission on a form's own address — see [Email-to-form](https://faldaro.com/docs/inbound-email); for an AI client calling in to operate your account, see the [MCP server](https://faldaro.com/docs/mcp).
[Previous Single sign-on](https://faldaro.com/docs/sso) [Next Email-to-form](https://faldaro.com/docs/inbound-email)
On this page
- Connections and slugs
- What a delivery carries
- Verifying a webhook delivery
- Retries and failure
- Operator allow-lists
---
# Email-to-form
Source: https://faldaro.com/docs/inbound-email
Give a form its own address: forward a message and it becomes a submission, attachments included. Sender verification, allowlists, AI extraction, review queue.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Email-to-form
Give a form its own email address. Forward a message to it and the message becomes a submission — attachments attached, sender verified, workflow fired — exactly as if someone had filled the form in.
### Minting an address
In the builder's Share tab, beside the public link, the Email a form panel mints an address of the shape `s-…@in.faldaro.com`. The local part is an unguessable token rather than the form's name, the public-link discipline applied to mail: the address space cannot be walked, and an address that has spread too far is retired by rotating it — the old one stops working immediately. Creating one takes the same permission as publishing a public link, because it is the same decision: opening the form to input from outside your organization. Email-to-form is included in the Team plan and above.
### Who may send — and the empty list
Every address carries an allowlist, and an empty allowlist refuses everyone. That is the deliberate starting state, not an oversight: an address that accepted mail the moment it existed would be an open relay into your forms. Add at least one sender before forwarding anything, and check the allowlist first whenever mail seems to vanish.
An entry containing `@` admits one mailbox; an entry without admits a whole domain. Either way the sender is checked against what their mail proved, never against the `From` header on its own — a `From` header is text anyone can type. A message qualifies when its sending domain passes SPF or carries a DKIM signature, and that authenticated domain matches the `From` address — the same alignment rule DMARC uses.
Practically: the sending domain must publish an SPF record, or sign its mail as itself. A personal Gmail account works by allowlisting the address or `gmail.com` — Google signs its users' mail as `gmail.com`. A company domain on Google Workspace or Microsoft 365 should publish SPF (one TXT record naming its provider) and ideally switch on DKIM in its admin console; until it does, its mail authenticates the provider rather than the company, and Faldaro will say exactly that in the review queue rather than accepting a claim nothing backed.
### Where the message lands
Each address maps the parts of a message onto the form's own fields: the subject, the message body and the sender's address onto text fields, the received date onto a date field, and attachments onto a file field — real files on the submission, same as an upload. Every mapping is optional, and the pickers only offer fields of the right type on the live version.
With AI switched on for the address — it is, unless you turn it off — the rest of the form is read out of the message itself: “new claim for the Henderson job, $4,200, needs doing by the 14th” lands on client, amount and due date. The model may only fill fields the form actually declares, values are coerced to each field's own type, choice fields only accept their published options, and anything it could not place is noted on the message for you to see. Your explicit mappings always win over the extraction — configuration is a statement of intent, an extraction is a guess. Extraction costs AI credits per message, like every AI feature; the deterministic mappings cost nothing.
The submission then behaves like any anonymous submission: validation runs, formulas are computed on the server, the workflow starts, notifications and integrations fire, and an on-submission agent triages it under the same guardrails a public submission gets.
### The review queue
Nothing is dropped silently. Inbound mail in the sidebar lists every message with what its sender proved — SPF, DKIM and the aligned domain — and what became of it. A message that could not be filed is held, with the reason in plain words: the sender was not on the allowlist, nothing authenticated the sending domain, the data failed the form's own validation, the organization ran out of AI credits. Fix the cause — add the sender, publish the SPF record, top up — and press Retry; the message is still there, and retrying can never file it twice. Discarding deletes the original for good. Until then, the original `.eml` can be downloaded from any message's detail view.
### What it deliberately will not do
Automated mail — auto-replies, out-of-office, bulk — is never processed, so two systems cannot mail each other in a loop. A form whose rules price a payment cannot be filed by email: nobody is present to pay, so the message is held and says so. AI extraction reads the subject, the body and the attachments — a PDF's or text file's words as text, and a scanned PDF or an image (PNG, JPEG, GIF, WebP) as the page itself. Up to five scans or images are read per message, each image up to 5 MB and each scanned PDF up to 100 pages or 10 MB; a scan or image left unread is named on the record. Other formats, such as Word documents, are kept but not read. A message it cannot understand is held visibly rather than guessed at. Messages are capped at 25 MB with up to twenty attachments.
[Previous Integrations & webhooks](https://faldaro.com/docs/integrations) [Next API keys](https://faldaro.com/docs/api-keys)
On this page
- Minting an address
- Who may send — and the empty list
- Where the message lands
- The review queue
- What it deliberately will not do
---
# API keys
Source: https://faldaro.com/docs/api-keys
Machine credentials with an explicit privilege grant: creating a key, what it may and may not do, and calling the API with it from curl or any HTTP client.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## API keys
A key is a machine credential with an explicit grant: it can do exactly what it was given when it was made — nothing inherits, nothing widens later — and it is walled into its organization the same way a signed-in person is.
### Creating a key
Under Settings → API keys, name the key and tick the privileges it should hold. You can only delegate privileges you hold yourself; the server refuses escalation regardless of what a client sends. The token — `ffk_…` — is shown exactly once: the server stores only a hash and cannot show it again.
### Using it
Send the token as a bearer credential to the same API the app itself uses:
```
curl https://faldaro.app/api/platform/folders \
-H "Authorization: Bearer ffk_your_token_here"
```
Every request a key makes passes the same privilege checks and the same database-enforced tenant isolation as a person's session. A key granted only `submission:read` receives a `403` from anything that writes; a key from one organization simply cannot see another's rows.
### Revocation
Revoking a key takes effect immediately — the next request answers `401`, the same anonymous refusal an invalid token gets. Deactivating a user also revokes the keys they created in that organization: a key is delegated authority, and the delegation ends with the account. Revoked keys stay listed as history; they are never deleted.
### The headless API
Two versioned endpoints exist specifically for machines, under `/v1`. Their response shapes are a frozen contract: fields are added, never renamed or removed, so a script written against them keeps working. Both require the `submission:write` privilege.
Evaluate runs a payload through a form's live rules — calculated values, hidden fields, outcomes, validation problems — and stores nothing. This is the rating call: price a quote or score an intake from another system without filing anything.
```
curl https://faldaro.app/api/platform/v1/forms/123/evaluate \
-H "Authorization: Bearer ffk_your_token_here" \
-H "Content-Type: application/json" \
-d '{"data": {"units": 4}}'
{"valid": false,
"calculatedData": {"total": 100},
"hiddenFields": [],
"outcomes": [],
"problems": [{"field": "applicant", "message": "Applicant is required"}]}
```
`valid` answers whether the payload as a whole would be accepted — a missing required value counts, unlike the in-app preview that runs while a form is still being filled in.
Create files a real submission against the live version, through the same engine the app uses: formulas re-run server-side, reference numbers allocate once, and every configured notification, integration and document fires as authored. Pass `"draft": true` to save a partial record.
```
curl https://faldaro.app/api/platform/v1/forms/123/submissions \
-H "Authorization: Bearer ffk_your_token_here" \
-H "Content-Type: application/json" \
-d '{"data": {"applicant": "Ada Lovelace", "units": 4}}'
```
Every caller has a request budget (120 per minute by default; deployments tune it). Going over answers `429` with a `Retry-After` header and `"code": "RATE_LIMITED"` — back off for that many seconds and continue. The budget is counted per key, so one integration exhausting its window never slows another.
### Practice worth copying
- One key per system, named for it — a leaked key should implicate one integration.
- Grant the read privilege alone wherever the system only reads.
- Rotate by creating the replacement first, then revoking the old key.
### Keys open the MCP server too
The same credential connects Claude and other MCP clients to your account: the [MCP server](https://faldaro.com/docs/mcp) authenticates with an `ffk_` key as its bearer header, under the same grant and the same isolation. Everything above about privileges, revocation and rotation applies unchanged.
[Previous Email-to-form](https://faldaro.com/docs/inbound-email) [Next API reference](https://faldaro.com/docs/api)
On this page
- Creating a key
- Using it
- Revocation
- The headless API
- Practice worth copying
- Keys open the MCP server too
---
# API reference
Source: https://faldaro.com/docs/api
The versioned HTTP API: evaluate a payload against a form’s rules without storing anything, file a submission, rate limits and error codes.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## API reference
A versioned HTTP API for the two things another system usually wants: evaluate a payload against a form's rules without storing anything, and file a submission. Authenticated by an API key, bounded by exactly the privileges that key was granted.
### Base URL and authentication
Every request carries an [API key](https://faldaro.com/docs/api-keys) as a bearer token. A session token from the app works identically — the server builds the same caller either way — but a key is what you want for a machine: it is created for one system, granted one explicit set of privileges, and revoked without disturbing anyone's login.
```
https://faldaro.app/api/platform/v1/…
Authorization: Bearer ffk_your_token_here
Content-Type: application/json
```
### The versioned promise
Everything under `/v1` is a frozen contract. Fields are added to responses, never renamed or removed; a change that would break your integration arrives as `/v2` instead. The shapes are deliberately narrower than what the app itself uses, so nothing you depend on moves when the interface does.
The service generates a machine-readable OpenAPI description of this surface at `/v3/api-docs`. A self-hosted deployment can reach it directly on the service; it is deliberately not published through the hosted application origin, so on Faldaro-hosted plans this page is the reference.
### Evaluate a payload
Runs the form's live rules over the values you send — computed fields, hidden fields, outcomes and validation problems — and stores nothing. This is the rating call: price a quote, score an intake, or check a payload before filing it.
```
POST /api/platform/v1/forms/{formId}/evaluate
{"data": {"units": 4}}
```
```
{
"valid": false,
"calculatedData": {"total": 100},
"hiddenFields": [],
"outcomes": [],
"problems": [{"field": "applicant", "message": "Applicant is required"}]
}
```
| Field | Meaning |
| --- | --- |
| valid | Whether this payload as a whole would be accepted as a complete submission. A missing required value counts — unlike the in-app preview, which is lenient because a form is still being filled in. |
| calculatedData | Every computed field, keyed by slug. |
| hiddenFields | Slugs the rules hid for this payload. |
| outcomes | Named flags the rules raised — id, message, severity. |
| problems | Validation failures — field and message. |
Requires `submission:write`. Evaluation always runs against the live version.
### File a submission
Creates a real submission through the same path the app uses: the engine re-runs server-side, a reference number allocates exactly once, and every configured effect — notifications, documents, integrations, delivery — fires as authored.
```
POST /api/platform/v1/forms/{formId}/submissions
{"data": {"applicant": "Ada Lovelace", "units": 4}}
```
Answers `201` with the stored submission: `id`, `formId`, `formVersionId`, `workflowState`, `data`, `calculatedData`, `hiddenFields` and `outcomes`. Send `"draft": true` alongside `data` to save a partial record that required-field validation does not yet bind.
Requires `submission:write`.
### Rate limits
Every caller has a request budget — 120 a minute by default, and deployments may tune it. Going over answers `429` with a `Retry-After` header and a stable code:
```
{"error": "Rate limit exceeded. Retry after 34 seconds.", "code": "RATE_LIMITED"}
```
The budget is counted per key, not per address, so one integration exhausting its window never slows another — and machine traffic sharing one IP is not punished for it. Honour `Retry-After` and continue.
### Errors
| Status | Means |
| --- | --- |
| 401 | Missing, malformed, expired or revoked credential. |
| 403 | The key authenticated but lacks the privilege this call needs. |
| 404 | No such form — including a form that exists but is not yours, and one never published. |
| 422 | The request was understood and refused; the body says why. |
| 429 | Over the request budget; wait Retry-After seconds. |
A form belonging to another organization is reported as missing rather than forbidden — whether it exists is not something an unauthorized caller gets to learn.
### Beyond /v1
The app's own API — folders, forms, reports, admin — is reachable with the same key and the same privilege rules, and is what the [API keys guide](https://faldaro.com/docs/api-keys) shows with `curl`. It is deliberately not versioned: it changes when the interface changes. Build integrations you intend to keep on `/v1`, and tell us what belongs there next.
If the caller is a model rather than a script, the [MCP server](https://faldaro.com/docs/mcp) wraps this surface as tools — same key, same privileges, with the schemas and annotations an MCP client expects.
[Previous API keys](https://faldaro.com/docs/api-keys) [Next MCP server](https://faldaro.com/docs/mcp)
On this page
- Base URL and authentication
- The versioned promise
- Evaluate a payload
- File a submission
- Rate limits
- Errors
- Beyond /v1
---
# MCP server
Source: https://faldaro.com/docs/mcp
Connect Claude and other MCP clients to your Faldaro account: the endpoint, API-key auth, the tool catalogue, prompt-injection guidance and rate limits.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## MCP server
Faldaro hosts a Model Context Protocol server, so Claude and other MCP clients can operate your account as tool calls — authenticated by an API key, bounded by that key's privileges, metered like ordinary API traffic.
### Connecting
The server speaks MCP's Streamable HTTP transport at `https://faldaro.app/api/mcp`. Authentication is an [API key](https://faldaro.com/docs/api-keys) sent as a bearer header — there is no separate MCP credential, no session to manage, and nothing to install for clients that can send a header.
```
# Claude Code
claude mcp add --transport http faldaro https://faldaro.app/api/mcp \
--header "Authorization: Bearer ffk_your_key_here"
```
Clients that only speak stdio can use a local bridge such as `mcp-remote`, which forwards a stdio session to a remote HTTP server and passes the header along:
```
npx mcp-remote https://faldaro.app/api/mcp \
--header "Authorization: Bearer ffk_your_key_here"
```
Connectors that require OAuth sign-in rather than a header — claude.ai's web connectors among them — are not supported yet.
### What the tools cover
The catalogue is the same one Faldaro's in-app agent uses — nearly sixty tools spanning the platform: folders and forms; reading and editing drafts, logic, workflow and appearance; publishing; submissions (create, update, evaluate, transition, assign); reports and datasets; document and notification templates; sequences; form test cases; the dashboard and the audit log. Two in-app tools do not exist here, because they cannot: navigation (no browser) and PDF import (no attachments ride an MCP call).
There are no delete or archive tools. That is a property of the catalogue, not a configuration: destructive actions stay in the app, where they carry their own confirmations and a person is present.
### Authorization
Every tool call is authorized as the key that made it — the same privilege checks and the same database-enforced tenant isolation as the raw API. The server holds no credential of its own and adds no authorization of its own, so connecting a model can never widen what the key could already do. A tool the key lacks the privilege for answers with the same refusal the API gives, returned as a readable tool result the model can relay.
### Tool annotations
Tools declare their behaviour in MCP's annotation vocabulary, honestly: read-only tools carry `readOnlyHint`; tools that replace a document (a draft save, a logic update) carry a destructive hint; creates and transitions are marked non-idempotent. A well-behaved client uses these to decide when to ask you before acting — which leads to the part worth reading twice:
### Submitter content and prompt injection
Reading submissions means reading text written by whoever filled in your forms. To a language model, sufficiently adversarial text can read like instructions. Every tool result carrying words from outside your organization — a submission that arrived through a public link, by email or over the API, a document a submitter uploaded — wraps them in an ` ` envelope, over MCP exactly as in the app. Inside Faldaro's own chat the platform also enforces a guard — once a turn reads that content, mutating tools are refused for the rest of it. Over MCP the loop belongs to your client, so that guard cannot exist on the server: confirmation of mutating actions is your MCP client's job, and the annotations above are what it decides with. Practical advice: connect read-only keys for analysis work, keep write-granting keys for authoring sessions, and treat "the model read a submission, then proposed an edit" as a moment to look before approving.
### Plans, and what is never charged
The MCP server is part of the Team plan and above. API keys and the raw API — `/v1` and the app's own endpoints — stay on every plan, Free included: what Team adds is the model-ready toolbox, not machine access itself. On a plan without it, requests answer `402` with `"code": "PLAN_LIMIT"` and the plan to ask for. (Self-hosted deployments with plan enforcement off are unaffected, as with every gate.)
The MCP surface itself never consumes AI credits, on any plan — a decided position, not an oversight: credits meter Faldaro's own model spend, and over MCP the model doing the thinking is yours. What meters this surface is the request budget below and your plan's ordinary allowances for whatever the tools do. That includes AI credits in exactly one case: a tool that asks Faldaro's own AI to work — `generate_form` and `analyze_form_insights` — spends the same credits it spends from the app or the raw API. The transport is never what you pay for.
### Budget
Requests are counted per key — 120 per minute by default; deployments tune it. Over the budget, calls answer `429` with a `Retry-After` header and `"code": "RATE_LIMITED"`.
### Revocation
Revoking the key severs the connection immediately: the next tool call answers `401`. Nothing about the MCP session survives on the server — there is no session — so there is nothing else to clean up.
[Previous API reference](https://faldaro.com/docs/api) [Next AI & agents](https://faldaro.com/docs/ai)
On this page
- Connecting
- What the tools cover
- Authorization
- Tool annotations
- Submitter content and prompt injection
- Plans, and what is never charged
- Budget
- Revocation
---
# AI & agents
Source: https://faldaro.com/docs/ai
The assistant, inline AI, insight reports with predictive models, and standing agents — what each can do, the limits on each, and how credits are metered.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## AI: assistant, inline help and agents
Three different things share one rule: AI acts with your permissions, never above them, and it proposes rather than commits. Nothing an assistant produces is stored until a person takes the normal save path.
### The assistant
Open the assistant from the top bar — or with ⌘J / Ctrl+J — and on a wide screen it docks beside the page rather than over it, so the record or form it is working on stays in view while it works; on a narrower one it slides in over the page. The panel travels with you through the app, so a conversation survives the navigation it performs. Ask it to build a form, wire logic, style the public form's page, edit a document or notification template, find submissions, or explain what a form does, and it works through the same product surface you would — showing each step it takes. A run of steps folds to one line once it succeeds and stays open while anything is still running or went wrong, so a long answer is not buried under the work that produced it.
A new conversation opens with three ways to begin that belong to the page you are on: a review of the form in the builder, the records still waiting on a form's list, a summary or the next step on a record. Drop a file anywhere on the panel to attach it. A turn that fails offers Try again, and a turn that finishes while the panel is closed leaves a mark on the button so the answer is not missed. The template editors have an Edit with AI button that opens the assistant on the template you have open; an edit it saves while you also have unsaved changes is raised for you to choose between, never silently overwritten either way.
It holds exactly your privileges. Every action it performs is an ordinary authenticated request made as you, so a tool it tries that you could not perform is refused for the same reason it would refuse you. It has no credential of its own and no way to name a tenant: an assistant cannot reach anything you cannot reach.
Deliberate limits, beyond your privileges:
- No deleting or archiving. Destructive actions stay in the interface, where they are deliberate.
- No administration. It cannot create users, grant roles or change billing.
- Navigation is allow-listed — it can only take you to known pages.
- It keeps no memory between turns. The conversation lives in your browser, which is what makes concurrent users safe.
Attach a PDF and it can both read it — rules, thresholds, questions — and turn it into a real, editable form.
### Inline AI
Beyond the panel, AI appears where the work is. Each of these is a single call with a structured result, validated against your real data before it can drive anything:
| Where | What it does |
| --- | --- |
| Filling a form | Prefill from an uploaded PDF or image — matching fields fill themselves for your review. |
| Submissions list | Plain English becomes a filter: “unpaid claims over $5,000”. |
| A submission | Summarize it. |
| Dashboard | Insights over what your submissions are doing. |
| Reports | Describe a report; it seeds the builder for you to refine. |
| Public form | Translate a form into another language — pick one, and every string comes back for your review. Fills gaps only; never overwrites your own wording. See public forms. |
| Template editors | Generate a document or notification template from a description, the picked form's fields, or a document to reproduce. A reproduced PDF keeps its layout, and its images and page setup carry over where a template can honestly hold them — an email cannot carry images, and the result says so rather than pretending. On an exact facsimile, one prompt binds the form's fields onto the reproduced pages, every proposed edit landing on the canvas for review. |
| Builder | Review form — an agentic check whose working you can watch. |
In every case the result lands in the page's own state — prefilled values, an applied filter, a seeded report — and nothing persists until you save it the usual way. The server still re-runs its own engine on save, so an AI suggestion can never become an authoritative number by itself.
### Insights
Every form has an Insights page: press Analyze — or set a daily or weekly refresh, at an hour in your own timezone — and you get a stored report on what that form's submissions are doing. The division of labour is strict. The server computes the statistics: submission trends, numeric profiles with outliers, category distributions, correlations between fields, and how long records sit in each workflow state. The AI then narrates those figures into ranked findings, each with a recommendation — and anything it claims about your data is checked before it is stored.
The check has teeth: when a finding targets a slice of submissions (“the West-region records still in Review”), that filter is validated against the form's real fields and then executed — the count on the finding is the query's answer, and View affected submissions opens the ordinary submissions list with exactly that filter, so the number on the card is the number the list shows. A finding whose filter named something the form does not have keeps its narrative but gets no count and no link. Reading reports needs the `insight:read` privilege; running an analysis or setting the schedule needs `insight:run`, separately, because analyzing spends credits and a schedule commits to spending them regularly.
The same page can also train predictive models on the form's own history: pick a field — or the workflow outcome — and the features to learn from (free-text answers included: what someone wrote in "What happened?" can carry as much signal as any number), and a model trains on past submissions to score the open ones. An outcome model trains only on records that actually reached a final state, and predicts the ones that have not. Its accuracy is measured on held-out data and shown with the fields that drove it, and every prediction appears as a clearly labelled estimate beside the record — never among its real values, never in a calculation, never in an export of the record's data. Training is deterministic compute and costs no AI credits.
Predictions are then held to account. As records close, each one's last prediction while open is compared to how it actually ended, and the model card shows live accuracy in plain words — "62% right on the last 34 closed records — 95% at training" — with drift called out when reality has moved away from the training history. Retraining is one click, or a weekly toggle: the model keeps its identity, the new version simply takes over, and a retrain that fails leaves the old model serving rather than a gap. A second kind of model flags unusual records: train it on what normal looks like and an arriving submission that doesn't fit wears an "Unusual record" mark with the fields that made it odd. And on any record, Test a change answers the what-if — nudge a value and watch the prediction move, with nothing saved.
### Agents
An agent is a standing job written in your own words against exactly one form: “when a claim arrives with an estimate over $10,000, summarize it and move it to Review”. Agents run on a schedule or when you start them, and every run is recorded with its outcome — a run in progress is visible while it works.
Three fences bound every agent, and they are enforced when a tool actually runs:
- An explicit privilege grant. An agent holds only the privileges you ticked when you created it — and you cannot grant an agent a privilege you do not hold yourself.
- One form is its whole world. A sibling form's submission is refused even when the underlying permissions would have allowed reading it.
- A run focused on one submission cannot write to another.
A run that has begun is never silently re-executed: its actions are not all reversible, so a run interrupted by a restart is marked failed for a person to look at rather than replayed.
### Credits
AI work is metered in credits. Translating a form, analyzing one into an insight report, filling one from a document, or turning a typical page into a template costs a handful — a dense multi-page reproduction spends more, at what it measurably cost; generating a whole form from a description costs more still; an agent spends credits as it works. Training a predictive model costs no credits at all: credits meter model reasoning, and training is deterministic compute. Credits reset monthly, and they are the one allowance that stops at the limit rather than degrading — a runaway loop should cost you nothing, and nothing here is ever billed as overage.
### Availability
Every AI affordance is gated on the deployment being configured for it: where AI is not configured, these features render nothing rather than failing when clicked — and predictive models additionally require the deployment to run the ML compute service, hiding the same way where it does not. Agents are available from the Team plan; see [billing](https://faldaro.com/docs/billing).
[Previous MCP server](https://faldaro.com/docs/mcp) [Next Plans & billing](https://faldaro.com/docs/billing)
On this page
- The assistant
- Inline AI
- Insights
- Agents
- Credits
- Availability
---
# Plans, seats & usage
Source: https://faldaro.com/docs/billing
What each plan includes, how seats are counted, exactly what happens at each allowance limit, and why nothing is ever billed as overage.
Search the documentation /
**All docs**
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
Start here
- [Getting started](https://faldaro.com/docs/getting-started)
- [Core concepts](https://faldaro.com/docs/concepts)
Building forms
- [Formulas & logic](https://faldaro.com/docs/formulas)
- [Workflows](https://faldaro.com/docs/workflows)
- [Field library](https://faldaro.com/docs/field-library)
- [Datasets](https://faldaro.com/docs/datasets)
- [Reference numbers](https://faldaro.com/docs/reference-numbers)
Working with data
- [Submissions](https://faldaro.com/docs/submissions)
- [Records & sharing links](https://faldaro.com/docs/records-sharing)
- [Reports](https://faldaro.com/docs/reports)
- [Data retention](https://faldaro.com/docs/retention)
Sending & delivering
- [Documents](https://faldaro.com/docs/documents)
- [Notifications](https://faldaro.com/docs/notifications)
- [Payments](https://faldaro.com/docs/payments)
- [E-signatures](https://faldaro.com/docs/esignatures)
- [Digital products](https://faldaro.com/docs/objects)
Access & sharing
- [Public forms](https://faldaro.com/docs/public-forms)
- [Partner sharing](https://faldaro.com/docs/sharing)
- [Users & roles](https://faldaro.com/docs/admin)
- [Single sign-on](https://faldaro.com/docs/sso)
Connecting & extending
- [Integrations & webhooks](https://faldaro.com/docs/integrations)
- [Email-to-form](https://faldaro.com/docs/inbound-email)
- [API keys](https://faldaro.com/docs/api-keys)
- [API reference](https://faldaro.com/docs/api)
- [MCP server](https://faldaro.com/docs/mcp)
- [AI & agents](https://faldaro.com/docs/ai)
Your account
- [Plans & billing](https://faldaro.com/docs/billing)
## Plans, seats & usage
What each plan includes, how seats are counted, and exactly what happens when an allowance runs out. The short version: submissions are never capped, nothing is ever billed as overage, and you pay for your team rather than your audience.
### Where it lives
Settings → Billing (`billing:read` to see it, `billing:write` to change it) shows your plan, live usage meters and the tier grid. Payment methods are added, removed and made default right there, in a card form Stripe hosts inside the page; invoices and receipts live in Stripe's own billing portal, reached from the same page. Either way, card details never touch Faldaro.
### What each allowance does at its limit
This is the part worth reading before you need it. Each limit behaves differently, on purpose:
| Allowance | At the limit |
| --- | --- |
| Submissions | Nothing happens — ever. Counted and shown, never refused. A public form that stopped accepting submissions would be an outage caused by our billing, inflicted on someone with no way to resolve it. |
| Storage | New uploads that no longer fit are refused. Everything already stored stays readable. A banner warns account holders as the cap nears. |
| Emails | Messages are held, never lost, and send when the month rolls over or the plan grows. Account email — invitations, password resets — is exempt and always sends. |
| AI credits | Refused at the limit — unless prepaid pack credits remain, which are drawn next. This stays the one hard stop: nothing is ever charged automatically, and a runaway loop should cost you nothing you did not prepay. |
| Seats | New people cannot be added until a seat frees or you buy more. Nobody is ever removed. |
There is no overage billing anywhere in Faldaro. Going over an allowance is never a charge — it is either counted, held, or refused. A prepaid credit pack does not change that: it is money you chose to spend up front, never a meter running behind your back. Allowances reset on the first of each calendar month.
### Prepaid AI credit packs
Paid plans can buy extra AI credits as one-time packs from the billing page — $10 for 300 credits, $30 for 1,000. Three rules, all deliberate:
- Packs never expire and never renew. A pack is a single purchase; unused pack credits carry forward indefinitely.
- Packs are drawn only after the monthly allowance is used — the allowance always spends first, and the meter says which pool an action draws from.
- One balance per billed group. Like the allowances themselves, pack credits are shared across your organization and the organizations beneath it.
A refund made from the Stripe dashboard does not remove credits already added — the balance never goes negative, and credits may already have been spent.
### Seats
A seat is a distinct active person holding any role in your organization or the organizations beneath it. Consequences:
- A second role costs nothing — the same person in two organizations of your tree is one seat.
- Invitations occupy a seat immediately, not when accepted.
- Deactivating frees a seat; reactivating needs one to be free.
- A lower seat count never evicts anybody — it stops new people joining until attrition catches up.
Starter and Team can buy extra seats at $15 each per month (ten months' price on annual billing, matching the two-months-free rule). They are capped where the next tier becomes the better deal, and the interface says so rather than selling you past it. Business does not sell extras — the next step there is a conversation.
### Changing plan
- Upgrades apply immediately, with the difference prorated and invoiced at once.
- Downgrades are scheduled for the end of the period you have paid for. Nothing changes today, and you keep your current allowances right up to the switch.
- Monthly → annual is an upgrade (it applies now, with unused monthly time credited); annual → monthly takes effect when the year you paid for ends.
- Cancelling always runs to the end of the period — service continues until what you paid for runs out, and you can resume before then. Nothing is deleted on cancellation.
Extra seats and plan changes are deliberately kept apart: remove purchased extras before changing plan, since seats are priced per plan. Two billing changes interacting silently is how billing surprises are made.
### Free, and the 3%
The Free plan is free forever, needs no card, and includes the same builder, logic engine and workflows as every paid plan — with unlimited forms and ten thousand submissions a month. Two things distinguish it: public forms carry a small "powered by Faldaro" line, and money collected through a form keeps 3% as a platform fee. Every paid plan is 0% and removes the attribution.
The fee is frozen onto each payment when it is taken, so upgrading later does not retroactively change what an old payment paid — and collecting nothing costs nothing, which is how Free pays for itself instead of charging you.
### Organizations, plans and inheritance
A child organization is covered by the nearest ancestor holding a subscription, and inherits any extra seats bought there. Storage, email and AI-credit allowances are measured across the whole billed group rather than per organization — so creating child organizations divides an allowance, it never multiplies it. The meters show the same figure the limits actually use.
### When a subscription lapses
Nothing anywhere refuses work because a payment failed. A past-due subscription keeps its entitlements, a banner tells the people who can act on it, and that is the whole enforcement story — turning a billing problem into a lockout is not something Faldaro does to your submitters.
### Self-hosted deployments
Plan enforcement is a deployment switch that is off by default. A self-hosted Faldaro has no limits at all unless its operator turns enforcement on. Usage is recorded either way, so the numbers are there to look at before anyone decides to enforce them.
[Previous AI & agents](https://faldaro.com/docs/ai)
On this page
- Where it lives
- What each allowance does at its limit
- Prepaid AI credit packs
- Seats
- Changing plan
- Free, and the 3%
- Organizations, plans and inheritance
- When a subscription lapses
- Self-hosted deployments