Skip to content
Breitloh

Client portals

Most firms are running a client portal already, and it is called email. Documents go out as attachments, versions multiply, and nobody is quite sure what a client has been sent or when. A portal fixes that by giving each client one place to look, and giving you one place to put things. If the people signing in are members rather than clients, that is [a membership system](/services/membership-system) instead.

Ten of my fifteen years were spent on enterprise platforms, mostly ServiceNow, for FTSE 100 companies, central government departments, and local authorities. Access control, audit trails, and who saw what are the everyday questions in that work.

Three clients, each seeing only their own documents, with every view recorded

Where it usually hurts

Nobody knows which version is current
A document goes out, gets amended, goes out again, and now three people are working from two versions. The portal makes the current one obvious, which is worth more than any feature on the list.
Sending sensitive things by email
Accounts, contracts, medical letters, and payroll all end up as attachments because it is the easy option. It is also the one that ages worst when somebody asks how you handle client data.
Passwords are the reason portals fail
Clients log in twice a year. They will not remember a password, and a forgotten password means a phone call to you. Anything built without solving that quietly goes unused.

What the job covers

  • A way in that clients can manage without ringing you
  • Documents organised by client, with the current version obvious
  • Access controlled per client, checked rather than assumed
  • A record of what was shared and when, for the day somebody asks
  • An upload route, so it works in both directions

What it has to talk to

Where the documents live now
Usually a shared drive with a folder per client and a naming convention that half the team follows. The portal reads from a structure your team already understands instead of asking them to learn a new one.
Signing in without a password
A link to their email, or their work account. Both remove the phone call about the forgotten password, which is the difference between a portal people use and one they do not.
Your practice or case management system
If client records already live somewhere, that stays the source of truth and the portal reads from it. A second list of clients is a problem you feel six months later.

A worked approach, not a client

How I would approach a firm sending documents by email

  1. 01

    Follow one document through

    Watch how a single report reaches a client today, in full: who writes it, who checks it, how it goes out, and what happens when it changes. The awkward parts are always in that trail.

  2. 02

    Solve the sign in before anything else

    If getting in is hard, nothing else matters. A link to their email is usually enough, and it removes the support calls that kill portals in month two.

  3. 03

    Start with one client type

    Launch for the group with the most documents and the least tolerance for email, learn from them, then widen. A portal nobody has used is not evidence of anything.

Questions I get asked about this

The ones that come up on almost every first call. If yours is not here, ask it and you will get a straight answer.

Do clients need to remember another password?

No, and that is deliberate. A link sent to their email, or signing in with their work account, gets them in. Clients who log in twice a year will never remember a password, and every forgotten one becomes a phone call to your team.

Can clients upload things to us?

Yes, and it is usually the half that saves the most time. Getting documents back from clients is normally worse than sending them out, because it happens by email attachment with no record of what arrived when.

Where do the documents actually live?

Wherever you want, and usually where they already are. If your team works from a shared drive with a folder per client, the portal can read that structure instead of asking anyone to change how they work.

Is it secure enough for client documents?

It is built to be: access checked on every request, sign in without shared passwords, and a record of who saw what and when. Whether that meets your professional body's requirements is a question worth asking them, and I am happy to answer the technical parts of their form.

Can different people at the same client see different things?

Yes. A finance contact and an operations contact rarely need the same documents, and access is set per person against the client record. Getting that right at the start avoids the awkward call about something visible that should not have been.

What happens when a client leaves?

Their access ends, and the documents do not disappear, because you usually have to keep them for years. The portal keeps the record and stops the login, which is a cleaner ending than an email trail that nobody can close. Where clients also book time with you, a booking system sits alongside it.

How do clients know a document is ready?

A notification by email, sent as transactional mail from your own domain with SPF, DKIM, and DMARC configured, so it lands in the inbox. That matters more here than anywhere else: a portal nobody is told about is a folder nobody opens.

Where is the data stored, and who can reach it?

In your own accounts, in the region you choose, with access checked on every request rather than assumed from a link. There is a record of who viewed what and when, which is the answer to the question your professional body will eventually ask.

What does it cost to run?

Hosting and storage, both small, and no per client or per seat licence. Portals bought off the shelf usually charge per user, which is fine at ten clients and painful at four hundred. The same is true of the WordPress plugins that bolt one on, which is often why people end up moving off WordPress at the same time.

Tell me what you have now

Half an hour on a call, and a straight answer about whether this is the right job and whether I am the right person for it.