The certificate operations checklist: from approved data to retained record
Reliable certificate operations are a chain of decisions, not one render button. Use this checklist to assign an owner and acceptance test to each stage. Follow the linked guides for implementation detail rather than copying one generic process into every programme.
1. Define authority and scope
- Name the organisation and workspace responsible for issuance.
- Define what event, completion or approval authorises a certificate.
- Separate corrections from genuinely new awards or recipients.
- Record who approves the template and final recipient list.
- Do not imply that FotoFit accredits the issuer or programme.
2. Prepare the minimum data
Keep one row per intended output and one stable header per dynamic field. Upload only the name, identifier, course or event details, dates, images and email values needed by the chosen workflow. Review duplicates, long values, scripts, image access and the applicable row and output limits before submission.
3. Choose managed or temporary output
| Decision | Choose managed | Choose temporary |
|---|---|---|
| Durable recipient record | Required | Owned by another system or unnecessary |
| QR verification | Required | Not required |
| Later correction | Expected | A new disposable job is acceptable |
| Availability | Current managed file remains with the record | Plan-based download window is acceptable |
4. Decide how recipients get the result
Choose download, eligible email delivery or a controlled lookup form according to the audience. Email requires accurate recipient addresses and configured delivery infrastructure; it does not guarantee inbox placement. Lookup should use minimal keys and must not expose the entire source dataset.
5. Define verification before adding a QR code
A QR code should resolve to an authoritative managed record with a clear current status and privacy-conscious public fields. It should not contain private spreadsheet data or imply that FotoFit independently verified the course, identity or issuer authority.
6. Reconcile generation and delivery
- Compare approved, completed and failed row counts.
- Review rendering failures separately from provider delivery failures.
- Inspect representative PNG or plan-supported PDF files.
- Do not rerun a whole cohort to repair one address or source image.
- Export the operational status your organisation is required to retain.
7. Test correction and retention
Before launch, correct one managed record and regenerate it. Confirm the current file, limited history and verification result are understandable. Document temporary-file expiry, managed-record retention, source-image handling, form submissions, provider copies and the separate controls required for permanent deletion.
Final launch gate
Launch only when the data owner, template owner, issuance authority, record model, recipient path, verification statement, correction owner and retention decision are explicit. Recheck the live pricing page for current plan allowances instead of copying a numeric limit into an operating promise.