Security, privacy and operational boundaries

Run a security verification checklist

Test unauthorised Inbox access, media IDs, portal ownership, CSRF, account isolation, audit redaction and loopback-only connector binding.

Audience: Administrators, security engineers and data-protection staffPermission: Administrator and security/compliance rolesModule v1.0.0 · 2026.07.30-r20.5
Exact navigationAdmin Area → WhatsApp → Settings / Access Control / Audit Trail
Before you begin
  • Confirm the module is active and select the intended WhatsApp account before changing any operational record.
  • Use an account with the stated native CRM capability and per-account access.
  • Test with controlled customer/contact data before relying on live verification, email or CRM automation.

What this guide covers

Test unauthorised Inbox access, media IDs, portal ownership, CSRF, account isolation, audit redaction and loopback-only connector binding. These instructions follow the supplied r20.5 controller, model, view, installer, connector and automation flow.

Exact step-by-step process

  1. Open Admin Area → WhatsApp → Settings / Access Control / Audit Trail.
  2. Select the correct account, conversation, customer, staff member or session before you run a security verification checklist.
  3. Complete the visible fields and confirmation prompts exactly as described below.
  4. Select the available action once and wait for its success or validation response.
  5. Verify the result in the operational record and, where applicable, in Audit Trail or the linked native CRM record.

Fields, choices and supported possibilities

Encrypted connector tokensEncrypted connector tokens
Loopback-only endpointsLoopback-only endpoints
Isolated per-account sessionsIsolated per-account sessions
CSRF-protected state changesCSRF-protected state changes
Permission-scoped media and historyPermission-scoped media and history

Code-backed validations and workflow rules

  • The connector uses local linked-device WhatsApp Web and does not turn the CRM into a WhatsApp Business API client.
  • Normal administrators never need to reveal connector credentials or access authentication directories.
  • Account access, verified customer ownership and protected download checks are enforced server-side.
  • Test unauthorised Inbox access, media IDs, portal ownership, CSRF, account isolation, audit redaction and loopback-only connector binding.

Expected result and verification

  • The requested action completes without a permission, validation, connector or native CRM error.
  • The selected account or conversation shows the expected state without changing another account’s data.
  • Where the action creates evidence, confirm the message, native record, verification event, portal history or audit entry is present.

Security, privacy and troubleshooting checks

  • Never expose connector tokens, loopback ports, authentication directories or raw customer verification replies.
  • Use the supported Connections, Access Control, Settings and Audit Trail pages rather than editing runtime or database records directly.
  • If the expected control is missing, verify both native capability and per-account permission before treating it as an installation fault.