External-recipient correspondence

Understand external-letter field validation

This guide explains that which fields the supplied UI and controller actually require. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: CRM staffPermission: Authenticated staff accountModule v1.0.0
Jump to steps
Where to goAdmin Area → Letter Manager → Dashboard → Manual Entry (External)
Before you start
  • Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
  • Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.

What you’ll accomplish

Know which fields the supplied UI and controller actually require. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.

Follow these steps

  1. Treat recipient identity, address and email as operationally required when relevant even though labelled optional.
  2. Always enter Subject.
  3. Enter meaningful PDF content.
  4. Test the output before formal issue.

Fields and options to review

Action scopeKnow which fields the supplied UI and controller actually require.
Module version1.0.0
Exact routeAdmin Area → Letter Manager → Dashboard → Manual Entry (External)
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.

Rules the system enforces

  • Only Subject has an HTML required attribute in the external form.
  • Name, company, address, phone and email are optional in the view.
  • The controller does not add server-side required validation for those fields.

How to confirm it worked

  • The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
  • The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
  • Any warning, missing file or failed send is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify recipient identity before sending or exposing public links.
  • Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
  • Test configuration and deployment changes with controlled records before production-wide use.
  • Interpret email opens and e-signatures according to their documented technical limitations.
Important code-backed limitationA technically accepted record can still be operationally unusable. Apply organisational completeness checks before dispatch.