The client portal access plan
A printable worksheet that records who can see and do what in a client portal, filled in before anyone gets an invitation.
Published . Last verified .
This worksheet is complete on this page. Print it, or save it as a PDF from your browser's print menu. Nothing here asks for your email.
The client portal access plan is a printable worksheet: a people table for each client, a checklist run before each invitation, and a record of the quarterly checks. For everyone who works on a client's file, the completed plan records what they can do in each part of the portal and when their access ends.
How to use this worksheet
- Read the four access levels once. Every table below uses them.
- Fill in one people table for each client. The worked example shows a finished one.
- Run the invitation checklist before every invitation.
- Copy the client-facing labels into the portal, with the names filled in.
- Record the change in the people table whenever a piece of work ends.
- Put the quarterly check dates on the calendar.
The four access levels
| Level | What the person can do |
|---|---|
| None | Cannot see that part of the portal at all |
| See | Can read and save a copy |
| Add | Can see, and can upload files or send messages |
| Approve | Can see and add, and can sign off on a deliverable or close a request |
Each person gets a level for each of the five parts of a portal:
- Status: where the work stands.
- Documents: files in both directions.
- Requests: what the firm still needs from the client.
- Messages: questions and answers.
- Deliverables: the finished work.
Who works on one client
A made-up example: a two-person bookkeeping practice and its client, a small plumbing company owned by two partners who have an office manager.
| Person | Side | Why they need access | Status | Documents | Requests | Messages | Deliverables | Access ends |
|---|---|---|---|---|---|---|---|---|
| Firm owner | Firm | Checks and signs off | See | Approve | Approve | Add | Approve | Stays |
| Staff bookkeeper | Firm | Closes the books each month | See | Add | Add | Add | Add | When reassigned |
| First partner | Client | Sends statements, approves reports | See | Add | Add | Add | Approve | End of engagement |
| Second partner | Client | Reads monthly reports | See | See | None | Add | See | End of engagement |
| Office manager | Client | Uploads receipts and bills | None | Add | Add | Add | None | End of engagement |
| Outside attorney | Guest | Reads the year-end report for a loan | None | None | None | None | See | 30 days after the invitation |
Client name: ____________________
| Person | Side | Why they need access | Status | Documents | Requests | Messages | Deliverables | Access ends |
|---|---|---|---|---|---|---|---|---|
Two checks close each client's table:
- Nobody outside the firm can open more than this client's space, unless the reason is written here: ____________________
- Every guest has a date in the last column.
Before each invitation
- The person is on this client's people table, with a level for all five parts.
- They have their own email address and get their own sign-in. Nobody shares a password.
- They are invited to this client's space only.
- A guest's end date is in the table, and the same date is set in the portal, or on a calendar if the portal cannot expire access.
- No file for this client is shared by an open link that works without signing in.
- Every account on this client, at the firm and at the client, uses a second sign-in step, or the firm's written approval of an equally secure control is on file. For a firm the Safeguards Rule covers, that is the rule's own test, set out in who sees what in a client portal.
- The invitation names the person and the one thing waiting for them inside.
- The labels on screen say who can see each folder, using the client-facing lines below.
- A colleague has signed in with a test account at the same level and seen only what the table says.
Words the client sees
These labels go into the portal with the names filled in. Each one tells a client who reads what they upload.
- On a client folder: "Visible to you and (your contact at the firm)."
- On a folder a guest can open: "Visible to you, (firm contact) and (guest's name) until (end date)."
- On an upload page: "Files you add here are read by (names or roles) only."
- In an invitation: "(Firm contact's name) invited you to your client portal. The first thing waiting for you is (one item)."
- When access ends: "Your access to (client name) ended on (date). Ask (firm contact) if you still need a file."
When access ends
| What happens | The change, the same day | Written in the people table |
|---|---|---|
| A guest's task is done | Guest removed | Date removed |
| A client leaves | Client gets an export of their files, then the space closes | Date closed |
| A staff member leaves | Sign-in removed by the end of their last day; their clients move to someone else | New staff name on each client |
| An engagement pauses | Everyone on the client's side drops to See | Date paused |
| A person on the client's side changes jobs | That person removed; the client names a replacement | Date and replacement |
Quarterly check dates
Two people from the firm read each client's access list in the portal against its people table, remove anything neither can explain, and correct whichever of the two is wrong. The Federal Trade Commission's Safeguards Rule guide, which covers tax preparation firms among others, tells covered businesses to reconsider regularly whether each person with access still has a legitimate business need for it.
| Check date | Done by | Client spaces checked | Access removed | Tables corrected |
|---|---|---|---|---|
The reasoning behind each choice on this worksheet is in who sees what in a client portal.