Detailed guide

Client Sign-in

The passwordless entry screen where an allowed client email requests a one-time sign-in link to the portal.

This is the front door of the client portal. Access is passwordless and allow-list based, so a client only gets in if their email was explicitly shared with them internally.

Quick summary

  • Send a sign-in link to a client who was just granted access.
  • Jump straight to documents when already signed in.
  • Sign out to hand the device back or reset access.

Put it into practice

  1. Make sure the client email was already added to an allowed list internally, otherwise no link is sent.

    InteractionsInternal quote/invoice/client sharing cards (done before this screen).
    Open workflow: Client Portal
  2. Enter the client email and request the link.

    InteractionsClient Portal Sign-in card: fill Client email and click Email Sign-in Link.
  3. Open the emailed link (or the Latest link shown for testing) to consume the one-time token and land on Client Documents.

    InteractionsEmail inbox or the Latest link info alert.
    Open workflow: Client Documents

What to review

Client Portal Sign-in card

Explains: 'Enter your client email. If it is on the allowed list, we email a one-time passwordless sign-in link.'

Client email field and Email Sign-in Link button

The email input and the primary 'Email Sign-in Link' action that sends the one-time link.

Latest link / Token expires info

For an already-requested email, an info alert can show the Client, the Latest link URL, and the 'Token expires' time (useful when testing).

Open My Documents and Sign Out

If the visitor already has a portal session, buttons appear to 'Open My Documents' or 'Sign Out'.

See guide: Client Documents

Guardrails

  • A link is only emailed if the address is on the allowed list, so unknown emails silently get nothing.
  • The sign-in token is one-time and time-limited; a consumed or expired token will not sign the client in.
  • Sharing the link forwards portal access, so treat it as sensitive.
  • No workspace login is required; access is entirely driven by the client allow-list.
  • Internal users grant or revoke that allow-list from quote, invoice, or client pages.

If it starts drifting

  • If no email arrives, confirm the address is on an allowed list and spelled exactly as shared.
  • If the link says invalid or expired, request a fresh one — tokens are single-use.
  • If the client is stuck signed in, use Sign Out and request a new link.