E-signature and public verification

Understand signature-link lifecycle limitations

Plan for public links that have no built-in expiry, revocation or resend-specific rotation.

Audience: Administrators and security teamsPermission: Authenticated staff accountModule v1.0.0
Exact navigationLetter Manager signature and verification links
Before you begin
  • Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
  • Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.

What this guide covers

Plan for public links that have no built-in expiry, revocation or resend-specific rotation. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.

Exact step-by-step process

  1. Record when the correspondence was sent.
  2. Revoke access through an approved code/data process only when legally and technically authorised.
  3. Do not assume Resend Email changes the public hash or unique code.
  4. Use a stronger signing platform when expiring links are mandatory.

Fields, choices and supported possibilities

Action scopePlan for public links that have no built-in expiry, revocation or resend-specific rotation.
Module version1.0.0
Exact routeLetter Manager signature and verification links
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.

Code-backed validations and workflow rules

  • The hash and unique_code are created once with the history row.
  • Resend Email reuses the stored values.
  • No expiry timestamp, revoked flag or token-rotation action is implemented.

Expected result and verification

  • The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
  • The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
  • Any warning, missing file or failed send is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify recipient identity before sending or exposing public links.
  • Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
  • Test configuration and deployment changes with controlled records before production-wide use.
  • Interpret email opens and e-signatures according to their documented technical limitations.