FotoFit CSV Lookup Smart Forms match user-supplied lookup values against an organisation-controlled source and populate only the configured result. The template stays locked, the source remains owned by the workspace, and a successful generation consumes the workspace's normal output allowance.
Choose a lookup key that is useful but restrained
A lookup key should distinguish the intended row without turning the form into a public directory. A certificate identifier is often safer than asking only for a common name. Where the workflow requires more assurance, configure an additional matching value or supported email verification instead of exposing more result data.
- Use a stable identifier controlled by the issuing organisation.
- Avoid government identifiers or unrelated student and employee data.
- Do not reveal whether nearby or guessed records exist.
- Show only fields that belong on the resulting certificate or approved response.
Build the lookup workflow
- 1Approve the templateLock the certificate layout and expose only the fields the result needs.
- 2Configure the sourceUse the supported lookup source configured for the form, such as an uploaded CSV dataset or selected Google Sheets data.
- 3Select lookup fieldsChoose the minimum values a recipient must provide to match an allowed row.
- 4Test non-matchesConfirm that incorrect, incomplete and duplicate values fail without leaking source rows.
- 5Publish and monitorShare the form, review submissions and keep the source and workspace access current.
What happens after a match
The matched source values populate the approved template; the recipient does not receive spreadsheet access or an editor. A generated result and its submission belong to the active workspace. Repeated retrieval follows the saved record and source-freshness rules configured by the product rather than treating every visit as an unrelated new issuance.
Plan for corrections and deletion
Correct the organisation's source of truth first. A managed result can then follow the authorised correction and regeneration workflow. Deleting a form, source connection, submission and generated record are separate operations, so use the available dashboard controls or a verified deletion request when the whole workflow must be removed.
Common questions
Does a lookup form expose the CSV or Google Sheet?
No. A respondent supplies configured lookup values and receives only the allowed matched workflow; the source itself is not presented as a public table.
Is CSV Lookup a separate free generation pool?
No. Successful Smart Form generations use the active workspace's shared output allowance.
Can a recipient change matched certificate data?
Matched source values are controlled by the form owner. Corrections should be made through the authorised source and managed-record workflow.