Detailed guide

Client Portal

The external client flow for passwordless sign-in, a Client Documents list, and secure quote/invoice review links.

Client Portal is the external entry point where allowed client emails receive a one-time sign-in link, land on Client Documents, and open only shared quote/invoice records.

Quick summary

  • Add the client email to an allowed list from quote, invoice, or client detail before sign-in.
  • Use Email Sign-in Link from Client Portal Sign-in and confirm the client reaches Client Documents.
  • Verify quote and invoice rows, search behavior, and Open links on Client Documents.
  • Remove email access from shared lists when portal access should stop.

Put it into practice

  1. Start by granting access for the client email from one of the internal sharing cards. Use Add To Allowed List on quote/invoice pages or Add To Client Allowed List on client detail.

    InteractionsInternal pages: Client Review Access, Client Invoice Access, or Client Portal Access cards.
    Open workflow: Quote Workflow
  2. Open Client Portal Sign-in and submit the allowed email with Email Sign-in Link.

    InteractionsClient Portal Sign-in page (/demo/client): fill Client email and click Email Sign-in Link.
  3. Use the login URL from email (or Latest link for testing). A valid one-time token signs the client in and redirects to Client Documents.

    InteractionsClient Portal Sign-in: open Latest link, then verify Client Documents loads.
  4. On Client Documents, confirm Signed in as and Session expires, then use Search quotes... or Search invoices... to find the row and click Open.

    InteractionsClient Documents page: Quotes and Invoices cards with search inputs and Open buttons.
  5. Review the document page actions: Submit Note is available on both quote and invoice reviews; Accept Quote appears when quote status is Draft or Sent; invoice supporting-doc exports only show when enabled.

    InteractionsClient review page: Client Notes card and Document Preview action buttons.
  6. When access should end, click Sign Out in the portal and remove the email from allowed lists internally so future document access is blocked.

    InteractionsClient Documents Sign Out, then internal shared-email chips (x remove action).
    Open workflow: Invoice Workflow

What to review

Client Portal Sign-in card

The /client page shows Client Portal Sign-in, a Client email field, and an Email Sign-in Link action.

Latest link and Open My Documents actions

After submission, Latest link and Token expires details can be shown, plus Open My Documents and Sign Out when a portal session already exists.

Client Documents header

Shows Signed in as <email>, Session expires timestamp, and a Sign Out action.

Quotes and Invoices cards

Each card has a count badge, search input (Search quotes... / Search invoices...), and Open buttons for shared rows.

Review document page

Quote/Invoice review shows Signed in as, Document link expires, Session expires, Client Notes, and Document Preview.

Quote and invoice review actions

Quote review can show Accept Quote for draft/sent quotes; both quote and invoice review allow Submit Note; preview actions include Open in new tab and Download PDF, with Time Entries/Expenses exports on invoices when enabled.

Client access grant and revoke controls

Internal pages control sharing with Add To Allowed List or Add To Client Allowed List, and revoke via the x action next to listed emails.

See guide: Quote Workflow

Guardrails

  • Portal visibility should be tied to explicit allowed client emails and valid document access records.
  • One-time login and document review tokens should be consumed through intended flow and expire as expected.
  • Clients should only see authorized documents for their email and no unrelated internal records.
  • Grant/revoke controls are permission-gated to quote, invoice, or client managers.
  • Portal session and document review are scoped to allowed client email and token validity.

If it starts drifting

  • If client cannot sign in, verify email is granted access and token has not expired or already been consumed.
  • If client sees no documents, confirm allowed email matches exactly and document access grants still exist.
  • If client sees unexpected documents, review and tighten quote/invoice/client-level access grants immediately.