Customer profile and client portal

Understand Letter Manager client data isolation

Confirm client history and view routes restrict records by the logged-in customer ID.

Audience: Administrators, clients and security teamsPermission: Authenticated staff accountModule v1.0.0
Exact navigationClient Area → Letter History / View
Before you begin
  • Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
  • Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.

What this guide covers

Confirm client history and view routes restrict records by the logged-in customer ID. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.

Exact step-by-step process

  1. Test with two controlled customer accounts.
  2. Confirm each account sees only records with its own client_id.
  3. Attempting a different numeric view ID should return 404.
  4. Report any exception immediately.

Fields, choices and supported possibilities

Action scopeConfirm client history and view routes restrict records by the logged-in customer ID.
Module version1.0.0
Exact routeClient Area → Letter History / View
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.

Code-backed validations and workflow rules

  • Both client controllers derive client_id from the session.
  • The single-letter view applies id and client_id in the database query.
  • External records are not shown because they have client_id=0.

Expected result and verification

  • The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
  • The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
  • Any warning, missing file or failed send is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify recipient identity before sending or exposing public links.
  • Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
  • Test configuration and deployment changes with controlled records before production-wide use.
  • Interpret email opens and e-signatures according to their documented technical limitations.