Skip to content

Sharing a portal

A portal reaches the client as a share link, and the access level on that link decides whether they can act on it or only read it.

Get this wrong and the client can see their invoice but not pay it, so it is worth two minutes.


RouteWhat it does
Send by Email, on the Portal Created screenCreates a Can comment link and opens an email to the contact
Portals list → ShareCopy linkReuses an existing link, or creates one
Portals list → ShareOpen linkOpens the portal as the client sees it
Portal page → ActionsShareThe full share dialog, for expiry and email restriction
Client actions sheet → Send portal linkEmails the link to the contact's main address

The routes that create a link for you use Can comment, which is what a client needs.

Check it the way they will

Share → Open link shows you the real portal with the real access level. Use it before you send anything.


Access levels

LevelRead the page, hours and invoicesDownload invoice PDFsCommentApprove, upload, request changesPay an invoice
View onlyYesYesNoNoNo
Can commentYesYesYesYesYes
Can editYesYesYesYesYes

Can comment is the right level for almost every portal.

View only is a read-only window

A client on a view-only link sees the invoice and its amount, and has no Pay button and no way to approve anything. If a client says a button is missing, check the level on their link first.

Can edit adds nothing to the portal itself. The page body stays read-only for the client either way. It only matters if you have embedded a shared database you want them to write to.


From the portal page, Actions → Share → Create link.

OptionWhat it does
LabelA note to yourself, such as Acme review
Expiration DateThe link stops working after this moment
Authorize to specific emailThe visitor must enter that address and a code emailed to it
Send invite emailEmails the link on creation

Set the access level to Can comment unless you have a reason not to.

Email restriction is off by default

Portals created through the normal flow are shareable immediately, with no code step to read them. Turn Authorize to specific email on for a portal carrying something sensitive, and accept that the client has one more hoop.

A portal page can carry several links, each with its own label, expiry and restriction, which is how you give two people at a client their own link.


Open Actions → Share and click Revoke on the link.

Anyone using it loses access immediately and it cannot be undone. Create a fresh link and send that instead.

To end a whole engagement rather than one link, archive the portal. See Creating a portal.


The token opens that one page. Links to your other pages appear on it as plain text rather than something the client can follow, and an embedded database reference is shown the same way.


Last updated: