Security, storage and limitations

Understand HMO public-link security

Protect KYC, agreement and termination tokens and review stored signature/IP/user-agent evidence.

Audience: CRM staffPermission: Recipient with valid token / authorised reviewerModule v2.0.1
Exact navigationPublic secure HMO links
Before you begin
  • Use the exact navigation above and confirm the intended record, tenant, customer, property, document or date range.
  • Confirm module activation and the stated permission instead of using another staff member’s account.
  • For public, email, provider, finance, signature or destructive actions, use a controlled test record before production use.

What this guide covers

Protect KYC, agreement and termination tokens and review stored signature/IP/user-agent evidence. These instructions follow the supplied module’s live menus, controller actions, form fields, model validation and downstream effects.

Exact step-by-step process

  1. Sign in to the staff admin area and open Public secure HMO links.
  2. Confirm that your account meets the access rule: Recipient with valid token / authorised reviewer.
  3. Open the required record or configuration and review its current values before making a change.
  4. Complete the displayed fields or action exactly as described in this guide.
  5. Save, submit, download or confirm the action using the button presented by the module.
  6. Reopen the source record and verify the expected status, output, notification, file or linked record.

Fields, choices and supported possibilities

Public workflowsRoom enquiry, KYC, agreement signature, termination acknowledgement, property status
EvidenceToken, timestamps, signature data and selected request metadata
Category/help-centre/category/hmo-manager/
Topic/help-centre/topic/hmo-manager-security-lifecycle/

Code-backed validations and workflow rules

  • Public routes are intentionally reachable without staff authentication.
  • Treat tokens as bearer links and avoid publishing them in uncontrolled channels.

Expected result and verification

  • The understand hmo public-link security workflow completes without bypassing the module’s permission and validation checks.
  • The saved value, generated file, status, notification or linked CRM record is visible from the same workspace.
  • Any validation message remains visible until the source data or setting is corrected.

Security, privacy and operational checks

  • Use least-privilege staff access and do not use another person’s account to reach a hidden action.
  • Review personal, financial, identity and compliance data before sending, exporting or exposing it through a public link.
  • Test configuration, email, public forms, accounting effects and provider connections with controlled records before production-wide use.