The client portal access plan

A printable worksheet that records who can see and do what in a client portal, filled in before anyone gets an invitation.

The client portal access plan is a printable worksheet: a people table for each client, a checklist run before each invitation, and a record of the quarterly checks. For everyone who works on a client's file, the completed plan records what they can do in each part of the portal and when their access ends.

How to use this worksheet

  1. Read the four access levels once. Every table below uses them.
  2. Fill in one people table for each client. The worked example shows a finished one.
  3. Run the invitation checklist before every invitation.
  4. Copy the client-facing labels into the portal, with the names filled in.
  5. Record the change in the people table whenever a piece of work ends.
  6. Put the quarterly check dates on the calendar.

The four access levels

LevelWhat the person can do
NoneCannot see that part of the portal at all
SeeCan read and save a copy
AddCan see, and can upload files or send messages
ApproveCan see and add, and can sign off on a deliverable or close a request

Each person gets a level for each of the five parts of a portal:

  • Status: where the work stands.
  • Documents: files in both directions.
  • Requests: what the firm still needs from the client.
  • Messages: questions and answers.
  • Deliverables: the finished work.

Who works on one client

A made-up example: a two-person bookkeeping practice and its client, a small plumbing company owned by two partners who have an office manager.

PersonSideWhy they need accessStatusDocumentsRequestsMessagesDeliverablesAccess ends
Firm ownerFirmChecks and signs offSeeApproveApproveAddApproveStays
Staff bookkeeperFirmCloses the books each monthSeeAddAddAddAddWhen reassigned
First partnerClientSends statements, approves reportsSeeAddAddAddApproveEnd of engagement
Second partnerClientReads monthly reportsSeeSeeNoneAddSeeEnd of engagement
Office managerClientUploads receipts and billsNoneAddAddAddNoneEnd of engagement
Outside attorneyGuestReads the year-end report for a loanNoneNoneNoneNoneSee30 days after the invitation

Client name: ____________________

PersonSideWhy they need accessStatusDocumentsRequestsMessagesDeliverablesAccess ends

Two checks close each client's table:

  • Nobody outside the firm can open more than this client's space, unless the reason is written here: ____________________
  • Every guest has a date in the last column.

Before each invitation

  • The person is on this client's people table, with a level for all five parts.
  • They have their own email address and get their own sign-in. Nobody shares a password.
  • They are invited to this client's space only.
  • A guest's end date is in the table, and the same date is set in the portal, or on a calendar if the portal cannot expire access.
  • No file for this client is shared by an open link that works without signing in.
  • Every account on this client, at the firm and at the client, uses a second sign-in step, or the firm's written approval of an equally secure control is on file. For a firm the Safeguards Rule covers, that is the rule's own test, set out in who sees what in a client portal.
  • The invitation names the person and the one thing waiting for them inside.
  • The labels on screen say who can see each folder, using the client-facing lines below.
  • A colleague has signed in with a test account at the same level and seen only what the table says.

Words the client sees

These labels go into the portal with the names filled in. Each one tells a client who reads what they upload.

  • On a client folder: "Visible to you and (your contact at the firm)."
  • On a folder a guest can open: "Visible to you, (firm contact) and (guest's name) until (end date)."
  • On an upload page: "Files you add here are read by (names or roles) only."
  • In an invitation: "(Firm contact's name) invited you to your client portal. The first thing waiting for you is (one item)."
  • When access ends: "Your access to (client name) ended on (date). Ask (firm contact) if you still need a file."

When access ends

What happensThe change, the same dayWritten in the people table
A guest's task is doneGuest removedDate removed
A client leavesClient gets an export of their files, then the space closesDate closed
A staff member leavesSign-in removed by the end of their last day; their clients move to someone elseNew staff name on each client
An engagement pausesEveryone on the client's side drops to SeeDate paused
A person on the client's side changes jobsThat person removed; the client names a replacementDate and replacement

Quarterly check dates

Two people from the firm read each client's access list in the portal against its people table, remove anything neither can explain, and correct whichever of the two is wrong. The Federal Trade Commission's Safeguards Rule guide, which covers tax preparation firms among others, tells covered businesses to reconsider regularly whether each person with access still has a legitimate business need for it.

Check dateDone byClient spaces checkedAccess removedTables corrected

The reasoning behind each choice on this worksheet is in who sees what in a client portal.

Talk through who sees which files

A 30-minute call about a client portal or a deal room, and about who should see which files. Bring the access plan if it is started.

Book a 30-minute callRead the guides

Booking opens Google Calendar in a new tab.