Skip to main content

Customer portal

A forwarded link should not open a customer's file.

Give each job one private link, and require the customer to confirm the email address you already have on file before it opens.

Get startedSee how it works
The email check is off until a business turns it on. A passcode proves control of the address on file, not the identity of the person holding it.

Customer portal

Harbor reroof

Code required
Link
One live per job
Email on file
a•••@example.com
Email check
Required
01
Passcode6 digits · expires in 10 minutes
Sent
02
SessionThis customer, this business
Revocable
03
Costs and marginNot part of this page
Excluded
Example dataAn example challenge. The address is never shown back to whoever opened the link.

How the work moves

The link addresses the job. The email check authorizes the person.

A link in an email thread is a bearer credential: forwarded, pasted into group chats, left in browser history on a shared machine. The passcode binds it to an address you already trusted enough to send the work to.

  1. Step 1

    Share one link for the job

    The office mints a private link from the job record. One live link at a time, and it can be rotated or revoked.

  2. Step 2

    The customer confirms their email

    With the email check on, opening the link asks for the address already on the customer record and sends a 6-digit passcode to it.

  3. Step 3

    The passcode opens a session

    A correct code opens a session scoped to that one customer, kept in a cookie the page cannot read and a record the office can end.

  4. Step 4

    They see the work, not the workings

    Job status, proposals, invoices, documents already emailed to them, and progress photos someone chose to share. Costs, margin, and internal notes are never part of the page.

What a visitor sees

Each state is recorded for exactly what it is.

Requesting a code answers the same way whether or not the address is on file, so a forwarded link cannot be used to discover who your customers are.

  1. 01
    OpenThe business has not turned the email check on. The link behaves as it always has.
    Link only
  2. 02
    Code requiredThe visitor is asked for the email on file. The answer is identical whether or not it matches.
    Challenge
  3. 03
    Open for this customerA correct code opened a session scoped to one customer of one business, and to nothing else.
    Verified
  4. 04
    EndedThe office ended portal access, or the session expired. The next visit is challenged again.
    Revoked
  5. 05
    Not readyThe check is on but no email is recorded for the job, so nobody could pass it. The page says so instead of opening or pretending.
    Review

What the portal shows

A nicer view of what you already sent.

LiveJob status, proposals, invoicesThe same records the customer already reaches by link, gathered in one place.
LiveDocuments you emailed themA document appears only after it was sent to that customer. Everything else filed against the job stays invisible.
ConditionalThe email checkOff until a business turns it on, and applies to every job in that business at once.
LiveProgress photos you chooseA photo reaches the customer only when someone shares it on purpose. The rest of the job's photo roll, including damage and adjuster shots, stays private.
Out of scopeCosts, margin, commission, internal notesNever part of the portal, at any point, for any customer.

Next step

Stop letting a forwarded link open a customer's file.

One private link for the job, and an email check that binds it to the customer you already recorded.

Available records, the email check, and portal access vary by environment, business settings, and current role capabilities.
Get started