Security, storage and limitations

Understand HMO Manager automation limitations

Distinguish immediate controller/model hooks from scheduled cron behaviour.

Audience: CRM staffPermission: Administrator / technical reviewerModule v2.0.1
Exact navigationAdmin Area → HMO Manager
Before you begin
  • Use the exact navigation above and confirm the intended record, tenant, customer, property, document or date range.
  • Confirm module activation and the stated permission instead of using another staff member’s account.
  • For public, email, provider, finance, signature or destructive actions, use a controlled test record before production use.

What this guide covers

Distinguish immediate controller/model hooks from scheduled cron behaviour. These instructions follow the supplied module’s live menus, controller actions, form fields, model validation and downstream effects.

Exact step-by-step process

  1. Sign in to the staff admin area and open Admin Area → HMO Manager.
  2. Confirm that your account meets the access rule: Administrator / technical reviewer.
  3. Open the required record or configuration and review its current values before making a change.
  4. Complete the displayed fields or action exactly as described in this guide.
  5. Save, submit, download or confirm the action using the button presented by the module.
  6. Reopen the source record and verify the expected status, output, notification, file or linked record.

Fields, choices and supported possibilities

Registered main hooksAdmin init and admin-footer UI hooks
Module cron hookNone registered in the supplied hmo_manager.php
Category/help-centre/category/hmo-manager/
Topic/help-centre/topic/hmo-manager-security-lifecycle/

Code-backed validations and workflow rules

  • Bookings, KYC, agreements and terminations use immediate actions/emails.
  • Do not promise scheduled expiry reminders unless a separate deployment process is confirmed.

Expected result and verification

  • The understand hmo manager automation limitations workflow completes without bypassing the module’s permission and validation checks.
  • The saved value, generated file, status, notification or linked CRM record is visible from the same workspace.
  • Any validation message remains visible until the source data or setting is corrected.

Security, privacy and operational checks

  • Use least-privilege staff access and do not use another person’s account to reach a hidden action.
  • Review personal, financial, identity and compliance data before sending, exporting or exposing it through a public link.
  • Test configuration, email, public forms, accounting effects and provider connections with controlled records before production-wide use.