Notifications & Gdpr Retention · How-to guide

Configure and run the Compliance Monitor cron

Use the protected cron endpoint for property/supplier sync, notification processing and GDPR retention execution.

Audience: Compliance administrators and authorised property staffPermission: Administrator / server operatorModule v1.0.0
Feature pathSystem cron → compliance-monitor-cron/{key}
Before you beginCron keys are secrets. Never place them in public documentation, screenshots, browser history shared with others or support tickets.

What this feature does

Use the protected cron endpoint for property/supplier sync, notification processing and GDPR retention execution. The supplied Compliance Monitor module keeps live operational records, source documents, generated evidence and audit history connected through shared section keys, compliance types and linked-entity references.

How the workflow fits together

This feature sits inside the Compliance Monitor lifecycle. Source evidence is attached to a linked entity, reviewed by authorised staff and converted into an approved record only when the required fields and evidence are complete.

Step-by-step workflow

  1. Set the module cron key or use the application cron key fallback where configured.
  2. Call the protected endpoint with the correct key.
  3. Confirm the JSON response reports the run time, sync status and engine status.
  4. Review the last GDPR retention summary separately.
  5. Treat a 401 response as a key mismatch, not as permission to expose the key.

Important fields and decisions

Linked recordConfirm the exact property, tenant, supplier or governance entity.
StatusUse the lifecycle state shown by the module.
Dates and referencesVerify dates and identifiers against source evidence.
Audit evidenceReview uploaded files, generated PDFs, notification logs and audit events.

Record lifecycle and audit

Reopen the relevant workspace after saving. Confirm the intake ID or record reference, linked entity, status, dates, evidence list, generated PDF and any notification or audit entry. Where the module offers separate source evidence and system PDF buttons, review both rather than assuming they contain the same information.

What happens after completion

The resulting status, evidence, PDF, notification or audit event remains available through the relevant Compliance Monitor register. A successful browser message confirms that the request was handled; the register and audit history confirm what was actually retained.

Controls, checks and common mistakes

  • Confirm the linked property, tenant, company or record ID before uploading, approving, sending, exporting or deleting.
  • Do not treat OCR, parsing, confidence or a success alert as a substitute for human evidence review.
  • Verify the saved record and audit history after every state-changing action.
  • Keep original uploaded evidence distinct from system-generated PDFs and notification evidence.
  • Use least privilege and avoid administrator-only actions unless the task genuinely requires them.
  • This module supports operational compliance records; it does not replace professional legal, regulatory or safety advice.
Compliance and data safetyUse the module as an operational evidence and workflow tool. Verify legal, safety, tax, licensing, data-protection and regulatory decisions with the organisation’s authorised professional process.
Browse connected topics:notificationsgdpr retention