Configure public verification security limits
Set e-sign form-token lifetime, failed-attempt threshold and rate-limit window without exposing controls that would bypass core privacy protections. The guide follows the Help Centre standard: exact route, prerequisites, ordered steps, verification and operational boundaries.
What you’ll accomplish
Set e-sign form-token lifetime, failed-attempt threshold and rate-limit window without exposing controls that would bypass core privacy protections. Bilty Management keeps drafts, issued records, public capability links, finance, integration events and audit evidence as connected but separately verifiable records.
How the workflow fits together
Configure tenant controls, preserve protected invariants and troubleshoot production workflows. Use the module's current status, permission checks, warnings and linked records to decide the next supported action. Where a downstream invoice, WhatsApp queue item, webhook, PDF, POD record or audit event applies, verify it separately.
Follow these steps
- Go to Bilty Management → Settings → QR verification & e-sign.
- Confirm the active tenant, intended Bilty record and your permission before entering or changing data.
- Complete the supported workflow: Set e-sign form-token lifetime, failed-attempt threshold and rate-limit window without exposing controls that would bypass core privacy protections.
- Review the displayed validation, dependent fields and any privacy, finance or integration warning before continuing.
- Save, submit or run the action once and wait for the module response.
- Reopen the relevant register or record and verify the final status, linked records and audit evidence.
Fields and decisions to review
Record, audit and evidence checks
Reopen the relevant Bilty record or register and confirm its identifier, current status, related parties, timestamps and connected evidence. Check the audit/compliance, payment, public-link, report, API, webhook or WhatsApp evidence that applies to this workflow rather than relying only on a success alert.
How to confirm it worked
Return to Bilty Management → Settings → QR verification & e-sign or the resulting register and verify that the stored state matches the intended action. For any downstream automation, confirm the downstream record or queue/log entry as a separate completion check.
Technical basis for this guidance
This guide was checked against views/admin/settings.php; bilty_management.php; controllers/Bilty_management.php; models/Bilty_management_model.php; docs/VALIDATION_REPORT.txt. It documents only behaviour exposed or enforced by the supplied module; internal secrets, raw signature payloads and unsupported future workflow assumptions are intentionally excluded.
Controls, checks and common mistakes
- Work only on the intended tenant and Bilty record.
- Do not bypass a missing permission, validation blocker or protected status by changing unrelated settings.
- Verify the stored record, downstream integration state and audit evidence after any material action.
