Protect public application tokens
Treat invite URLs as bearer links and revoke unused invitations. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goAdmin Area → Tenant Applications → Invitations
Before you start
- Use an account with Authorised reviewer and confirm the intended record or setting before making a change.
- Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
- Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.
What you’ll accomplish
Treat invite URLs as bearer links and revoke unused invitations. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.
Follow these steps
- Go to Admin Area → Tenant Applications → Invitations.
- Select the exact record or option described in this guide.
- Complete the displayed fields or action using the rules below.
- Save or submit once and resolve any validation response.
- Check the resulting record, status, file, notification or integration effect.
Fields and options to review
Exact actionProtect public application tokens
Exact navigationAdmin Area → Tenant Applications → Invitations
Module version1.0.0
Access ruleAuthorised reviewer
VerificationReopen the source record and confirm the expected status, linked record, file, notification, portal visibility or financial effect.
Tenant/applicantIdentity, contact, current address, employment/income, occupants, pets, smoker/benefits/children flags and right-to-rent data where exposed.
Tenancy termsProperty, tenant client, start/end/move-in dates, term, rent, frequency, deposit, holding deposit and deposit scheme.
Consent and workflowInvite mode, consents, review notes, agreement template/body, signature stage and workflow action.
Rules the system enforces
- Default invite TTL is 14 days; do not send links to unintended recipients.
- Public application and onboarding actions use token/record checks and explicit workflow states.
- Do not advance a workflow until the required party, property, dates, financial terms and consent/evidence are complete.
How to confirm it worked
- The supported protect public application tokens flow completes without bypassing permission or validation checks.
- The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
- Unexpected validation, provider or linked-record errors are investigated before retrying.
Security, privacy and operational checks
- Apply least privilege to purchasing, vendor, invoice, payment, return, contract and report permissions.
- Verify vendor identity, bank/payment details, tax, currency, totals and approvals before creating financial commitments.
- Treat public links, signatures, portal files, attachments and exported reports as controlled business records.
- Test settings and automated jobs with controlled records before production-wide use.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
