Forward it. Get it back reviewed.
Your organisation gets its own address. Anyone you've approved can forward a contract to it, no account, no login, no training session, and the review lands back in their inbox. The people who need Vern least often are the ones who need it easiest.
An open address would be an open door. This isn't one.
Five people forward the same contract to the same address. Only two of them get a review.
A member forwarding from their work address is the simplest case. The review runs, appears on the matter in the app, and the full analysis is emailed back to the address it came from.
“18 clauses reviewed. Overall 62 Negotiate, Vern Score Caution. Five clauses flagged, one to escalate: 8.1 Limitation of liability is uncapped and breaches L-04.
Full report and suggested wording attached, or open the matter in Vern.”
Priya is on the approved-senders list but has no login and costs you no seat. The review runs exactly as it would for a member, what differs is only what comes back to her, which your admin controls.
“Thanks, this has been submitted for review. A member of your team can view the results in Vern.
You’ll not receive the analysis by email; your organisation has chosen not to send clause-level findings to email-only senders.”
Authentication passed, the message genuinely came from that address, but the address maps to nobody in your organisation. The attachment is never opened, so nothing about the contract is processed at all.
“This address does not accept mail from unrecognised senders.
If you believe you should be able to send here, contact the person who gave you this address.”
A lookalike domain claiming to be Dan. It fails authentication before identity is even considered, so a convincing display name buys nothing. With the sender-domain allowlist on, it would have failed twice.
“This message could not be accepted.
No further detail is provided.”
Everything about the sender is fine; you have simply used the month. The message is turned away at the door rather than parked in a queue, so nothing runs later without you expecting it.
“This wasn’t reviewed: your organisation has used all 60 reviews for July.
Nothing has been queued and nothing has been charged. An admin can add credits, or resend after 1 August.”
Most of the people who need this shouldn't have a login.
A branch manager who forwards four contracts a year doesn't need an account, training, or a seat on your bill. So Vern has a second class of identity that exists only for email.
By default an approved sender gets a confirmation only, "received, a team member can view the results". Sending them the full analysis means putting clause-level risk findings in an inbox outside your app, so an admin has to switch that on deliberately, per organisation.
High-entropy, and yours to burn.
The alias isn't guessable from your company name, so it can't be found by trying. If it ever ends up somewhere it shouldn't, a forwarded thread, a supplier's address book, a mailing list, an admin regenerates it and the old one stops working immediately.
You can also restrict it to specific sender domains, so even a listed person can only send from a work address.
If a bounce said "you’re not on Brightwell’s approved sender list", anyone could learn who your organisation is, that you use Vern, and, by trying addresses, who works there. So it doesn’t.
A rejected message gets a plain, uninformative reply and nothing is echoed back, not the attachment, not the subject, not a word of the contract. Your admins see the real reason in the app.
If you’ve used your monthly reviews, the message is turned away at the door with a clear explanation to the sender and a notice to your admins. It isn’t parked in a queue to surprise you next month.
Give the address to the people who never log in.
We'll set up your alias on the call, add a couple of senders, and you can forward something from your phone before it ends.