Security, privacy, limitations and troubleshooting

Understand Letter Manager identifiers and tokens

Distinguish database ID, reference, unique verification code, signature hash, visible verification code and email-open token.

Audience: Administrators and developersPermission: Authenticated staff accountModule v1.0.0
Exact navigationAdmin Area → Letter Manager → Internal Full View; code-backed reference
Before you begin
  • Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
  • Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.

What this guide covers

Distinguish database ID, reference, unique verification code, signature hash, visible verification code and email-open token. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.

Exact step-by-step process

  1. Use ID only as the internal numeric record key.
  2. Use reference_no for operational correspondence lookup.
  3. Use unique_code for public verification URL.
  4. Use hash for the public signature URL and signature filename.
  5. Use random_verification_code for visible barcode/evidence.
  6. Treat email_open_token as private tracking infrastructure.

Fields, choices and supported possibilities

Action scopeDistinguish database ID, reference, unique verification code, signature hash, visible verification code and email-open token.
Module version1.0.0
Exact routeAdmin Area → Letter Manager → Internal Full View; code-backed reference
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.

Code-backed validations and workflow rules

  • Each identifier has a separate purpose and should not be substituted.
  • Public links do not expire in this release.

Expected result and verification

  • The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
  • The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
  • Any warning, missing file or failed send is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify recipient identity before sending or exposing public links.
  • Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
  • Test configuration and deployment changes with controlled records before production-wide use.
  • Interpret email opens and e-signatures according to their documented technical limitations.