Core workflows

From an empty installation to a certificate a stranger can verify, in the order you will actually do it.

Everything below is done in the browser. The role that may do each step is named; the full matrix is on the roles and permissions page.

Review dashboard counts

Admin, Manager or Viewer. Choose an issue-date range on Dashboard, or leave both dates empty for all time. Counts include active records only, excluding archived and deleted records. Select a tile to open the exact filtered certificate list.

Issued includes verified and revoked records. Awaiting a decision includes submitted and assigned records. Verified includes expired records, while Expired counts verified, non-revoked certificates whose expiry date is before today. These groups overlap; adding their counts does not give the total. Needs attention counts returned and rejected records. The selected period follows issue dates, not decision timestamps.

System Admin. Email sent, pending and failed tiles use the same selected dates against queue creation time. Each row is one queued message, so a failed message and its later resend remain separate counts. Select an email tile to inspect its matching Email deliveries list.

1. Create a course

Manager or Admin. Courses, then Create course. A course is the programme itself, not a particular delivery of it: "Anti-Money Laundering Essentials", not "the March intake".

2. Add an occurrence

Admin. Open Course runs below Courses, then Add a run and choose the course. The list includes all courses; use its course filter to focus on one programme. An occurrence is one dated delivery, with its own start and end dates and its own description. Certificates are issued against an occurrence, which is how you can later report on a single intake or filter by a date range.

Each course may have as many occurrences as you like, and the same pair of dates cannot be recorded twice for one course.

An occurrence can be edited at any time, and deleted while nothing has been issued against it, which is how a test occurrence gets cleaned up. Delete asks for a reason and records it in the audit log. Once a single certificate references the occurrence the delete is refused and the message says how many certificates hold it, counting archived and deleted ones, because either can be restored.

3. Design a certificate template

Admin. Certificate templates, then Create. Choose the course, name the template, and upload the background as a PNG or JPEG. The designer opens empty: no fields are placed until you add them.

  1. Upload the background. Field controls stay disabled until it has loaded, because there is nothing to position against.
  2. Add the fields you want: surname, given name, course, a date, the expiry date, the certificate number, the issuing organisation, the verifier organisation, the QR code and the verification value.
  3. Drag each field into place and set its font, size, weight and alignment. Positions are stored as proportions of the background, so the layout survives a change of page size. Click a field or press Tab to select it, then use the arrow keys for 0.2% steps; hold Shift for 1% steps. Dragging snaps nearby edges and centres to red dashed guides. Hold Alt to drag freely. Font weights use the available regular or bold PDF face, so intermediate choices resolve to those faces.
  4. Save. Editing a saved template increases its version number. Already-issued PDFs use the current template appearance on their next authorised access; their approved business values stay fixed. See how stored PDFs are updated.

For a script-style name, select Great Vibes MN. This bundled font supports Mongolian Cyrillic, including barred O and straight U, in the editor and exported PDFs.

One course can own several named templates, for example one per language or one per partner body. The person issuing a certificate chooses which to use.

4. Issue a certificate

Manager or Admin. Certificates, then Create. Choose the course, then the occurrence and template belonging to it, and enter the participant. Two choices decide what happens next.

ChoiceEffect
Verification required, with a verifier chosenThe certificate is created as assigned and waits for that verifier. It is not public yet.
Verification not requiredThe certificate is verified immediately and is public at once.
Send notificationQueues an email to the participant with the verification link. Every certificate is issued to an address, so the only thing this needs beyond the tick is the email job to be running.

The certificate number is yours and must be unique across the installation. The unique ID is generated if you leave it empty. Both are values the public can verify with.

For more than a handful of people, use bulk import instead. It is the same workflow with a five-stage review in front of it.

5. Verifier approval

Verifier. The verifier signs in and lands on its own dashboard. It sees the certificates assigned to it and nothing else.

Any of the three can be applied to one record from its page, or to several at once by selecting them in the list and choosing a decision. Every decision is recorded with the account, the time and the note, and the note is visible to the Manager who submitted the record.

6. Delivery by email

A notification is queued, not sent, at the moment it is requested. The scheduled email job sends messages using the batch size, delay and hourly cap saved on Email settings. The message carries a link, never an attachment: the recipient opens the verification page and downloads the PDF from there, so a forwarded email cannot leak a document to someone who should not have it.

The wording of every message is editable on the email templates screen. See email and templates.

7. Public verification

No account, no registration, no email address. There are three ways in, and all three land on the same page.

RouteHow it is used
By identifierA visitor types the certificate number or the unique ID into the form on the home page.
By linkThe address /c/<token>, which is what the notification email contains. The token is 48 characters of randomness and cannot be guessed from a certificate number.
By QR codeThe QR printed on the certificate encodes that same link.

The page shows the participant name, the course, the certificate number, the issue date, the expiry date if there is one, the issuing organisation, the approving verifier organisation, and the PDF. It shows nothing else: no email address, no telephone number, no employer.

Only a verified, non-revoked certificate exposes certificate details. An unarchived revoked certificate shows a distinct revocation notice without participant details, dates, a reason or a PDF. Pending, rejected, deleted and archived revoked records remain not found. An expired certificate is marked as expired. Archiving a verified certificate does not revoke it.

8. Corrections, revocation and export

9. External certificate API

System Admin setup, external-system use. Open Integrations to create one API client per external system and environment. Map its stable course and run keys to a local occurrence and certificate template, then create a token with only the issue, read or revoke scopes it needs. The token is displayed once; copy it into the external system's secret store before leaving the page.

The external system supplies its own completion reference and certificate number. Every write carries an Idempotency-Key, so a timeout may be retried without creating a duplicate. The same key with changed content is rejected. A client can read and revoke only certificates it issued. The complete request and response contract is in /openapi.yaml on the installation.

Where the PDF comes from. Nothing is rendered when a certificate is created. The first authorised access renders and stores it privately with a hash, its approved business values and the template presentation used for that render. Those manually entered values remain frozen, including the wording, course, number, issue and expiry dates and verification link. The explicit name-correction action replaces the participant names and keeps the previous render as a version.

Appearance follows the current template: font, position, colour, canvas and background. The verification requirement, approving organisation and verification date follow the current certificate. The next authorised access regenerates the stored PDF when its appearance or verification has changed, or when the six-month cleanup job has removed the file. A renderer upgrade can also regenerate an older PDF once on its next access without changing approved business values, when the current template and background are usable. The recorded presentation is a fallback if the current template is unavailable; regeneration still needs its retained background assets. Keep those assets backed up.