Client Portals: What Clients Need to See (and What Not)
A client portal is a signed-in place where each client sees the status of their work, approves things, gets files and invoices, and sends messages. What belongs in one, what must stay out, how a portal compares with a shared board and with email updates, and the security basics that keep it safe.
8 min read
A client portal is a private, signed-in place where each client sees their own work and nothing else: where things stand, what needs their approval, the files you delivered, what they owe, and a message thread tied to the work. What they should not see is just as important: other clients, your internal notes and priorities, costs and margins, and anybody’s passwords. There are three common ways to give clients that view: dedicated client portal software, a shared project board with a client role, or disciplined email updates. Which one fits depends on how many clients you have, how much they approve, and whether you bill in the same place. Whichever you choose, it needs multifactor authentication, least-privilege access and an offboarding step for when a project ends.
What a client portal is, and is not
The defining feature is identity. Each person on the client side signs in as themselves and sees only their own organization’s work. A folder link anyone can forward is not a portal, and neither is a status page with no sign-in. Accounting firms, law firms, agencies, contractors and IT service companies all use portals, for the same reason: clients stop asking “where are we?” when they can look for themselves.
This page is about the whole place a client signs in to. The status view inside it, with columns written in the client’s words and a template to copy, is covered in the client project tracker post.
What clients actually need to see
- Status: each deliverable named the way they would name it, where it stands, and what was finished recently.
- Approvals: what is waiting on them, by when, and a clear way to say yes or no that records who approved what and when. This is the line that saves the most time, because clients often do not know they are the blocker.
- Files: the deliverables, the contract and the things you need from them, in one place, with the current version obvious.
- Invoices: what is due and what is paid, and a way to pay, if billing lives in the portal. If it lives in your accounting software, a link to it is enough.
- Messages: questions attached to the item they are about, so the answer stays with the work instead of getting lost in an inbox.
- Decisions: what was agreed, by whom and when, so nobody reopens it three months later.
What clients should not see
- Other clients: their names, their work, even in a dropdown or a filter. A single shared space with a client filter is the most common way this leaks.
- Internal notes and debate: rough drafts of opinions, guesses, and “we should push back on this.”
- Internal priority rankings. A client who sees their request ranked seventh will ask what is above it.
- Costs, rates, margins and supplier invoices, unless your contract is time and materials and they expect to see hours.
- Credentials of any kind. A password, an API key or a registrar login does not belong in a portal message, on either side; use a password manager’s sharing feature instead.
- Anything about your staff’s performance or who made a mistake. Report what happened and what changed.
A simple test: if you would not read it aloud on a call with the client, it does not belong anywhere they can see it.
Portal vs shared board vs email updates
- Dedicated client portal software. Typically a branded site with document requests, approvals, invoices and payments, and often e-signatures and a link to your accounting software. It fits firms with many clients and a lot of document exchange, such as accountants and law firms. The cost is another system to keep current: if the real work happens in a different tool, someone copies status across, and the portal goes stale the week they forget.
- A shared board with a client role. The client is added to the board your team actually works from, one board per client, with a role that can see and comment but not change anything. It fits agencies, developers and contractors whose clients mostly ask where things stand. Status is always live, because it is the same board. The cost: no invoicing, and your team writes every task knowing the client may read it.
- Email updates. A short written update every week: what finished, what is next, what you need from them and by when. It fits a handful of clients who will never sign in to anything. The cost is that approvals get buried in threads, files live in attachments, and there is no single current view. The weekly status report template has a client version.
Many small firms combine them: a shared board for status and questions, the accounting system’s own portal for invoices, and a weekly email pointing at both. If your board is in Trello, note that anyone added to a Trello board can see every card on it; how to use Trello covers what its plans allow for read-only access.
Security basics for any client portal
A portal holds client data and client trust, so the US government’s small-business security guidance applies to it directly.
- Turn on multifactor authentication. CISA’s guidance for businesses (opens in a new tab) says to require MFA wherever possible, starting with admin accounts and people who handle sensitive data, and to prefer phishing-resistant methods such as security keys over text-message codes. Require it for your staff; offer or require it for clients.
- Give the least access that does the job. NIST defines least privilege (opens in a new tab) as restricting each user’s access “to the minimum necessary to accomplish assigned tasks.” A client sees their own work; only the people who manage the portal hold admin rights.
- Limit who can see sensitive data. The FTC’s Start with Security (opens in a new tab) guide tells businesses to give employees access only on a “need to know” basis and to limit administrative access to the people whose job it is.
- Offboard on the last day. The FTC’s guide to protecting personal information (opens in a new tab) asks for a procedure that makes sure workers who leave no longer have access. Apply the same rule to contractors and to clients whose project has ended.
- Keep sensitive identifiers out of messages. Social Security numbers, bank details and tax documents go through a secure upload, never a comment.
- Review access every quarter: list who can see each client’s space and remove anyone who should not.
A checklist before you invite a client
[ ] One space per client. No shared space with a filter. [ ] Client role can see and comment. It cannot edit, move or delete your work. [ ] Only named people on the client side, each with their own sign-in. No shared logins. [ ] MFA on for every staff account; offered or required for clients. [ ] Internal notes, priorities and costs are somewhere the client role cannot reach. [ ] Every open item written in the client's words. [ ] "Waiting on you" items have a date and a named person. [ ] Decisions recorded with who decided and when. [ ] Invoices: in the portal, or a link to where they are. [ ] Offboarding step written down: remove access when the project ends or a contact leaves. [ ] Access review on the calendar, once a quarter.
A shared board as a client portal, on fenbs
fenbs is the shared-board option, not portal software. You make a team board for each client, because a role applies to the whole board, and add the client under People with a role. Roles are set per company, and two are suggested for exactly this:
- Client: sees the board live, To Do, Next Up, In Progress and Completed, and comments on any task. Cannot change anything; every refusal names the permission that was missing.
- Reporter: adds tasks and comments, and edits only their own. Useful for a client who sends a steady stream of requests or bug reports.
- Files live on the task they belong to. Download links are made per click and last about fifteen minutes, so someone removed from the board cannot use a link they were given earlier.
- History records who changed what. Someone with the suggested Client role sees what changed and when, but not who made each change.
- Decisions go on the Decisions and rules page with who decided and when, and a decision can be sent to named board members to approve or reject.
- Offboarding is taking the person’s role on the board away under People, and History records that too.
What it does not do: no invoices or payments, no branding, no due dates and no assignee you can set, so dates and owners go in the task note. There is no public or anonymous view either; a client sees the board only by being added by email and signing in. Priorities from 1 to 10 are visible to everyone on the board, so leave them off a client board if your ranking is private. fenbs for agencies and the client project board template show the setup.
Related
Recording what was agreed: decision log template. What each role can and cannot do: roles and permissions for humans and AI agents and what is a read-only board. The idea behind roles: role-based access control. For freelancers: fenbs for freelancers.