Signing off locks this test against further edits and adds a hash-chained entry to the signature log. Sign-offs cannot be undone without breaking chain integrity.