A client portal is the private page where a firm's clients check on their work, send documents, answer requests, send messages and collect what the firm finished. A small firm gets one by buying portal software, assembling one from tools it already pays for, or building its own, and a first-year count that includes the firm's own hours decides between them. Tax preparers also carry a legal duty here: the Federal Trade Commission's Safeguards Rule guide lists tax preparation firms among the businesses the rule covers.
The five jobs a portal does
The table sets each job beside what it looks like while it still runs through email.
| Job | What the client wants to know | What happens when it stays in email |
|---|---|---|
| Status | Where the work stands | The client emails to ask, and the firm answers the same question many times a season |
| Documents | Where files go, in both directions | Attachments scatter across threads and nobody knows which copy is current |
| Requests | What the firm still needs | The list lives in one person's head or in a spreadsheet the client never sees |
| Messages | Who to ask, and where | Questions land in one inbox and wait when that person is out |
| Deliverables | Where the finished work is | The final return, report or contract is attached to a message and then buried |
At a bookkeeping practice, requests are monthly bank statements and receipts. A law practice asks for signed engagement letters and the documents a matter needs, while a consultant may ask for data exports and interview times. One line per job, written for the firm's own clients, becomes the list each setup is priced against.
Open links, and the duty to protect client files
Google's Drive help page says a file shared as "anyone with the link" can be used by anyone who has the link, without signing in. Once such a link is forwarded or pasted into another thread, the firm can no longer say who opened the file.
In December 2020 the Federal Trade Commission settled with Ascension Data & Analytics, a mortgage analytics company whose vendor had stored the contents of scanned mortgage documents on a cloud server in plain text, with no password or other block on access (the commission's release of December 15, 2020). The documents held names, dates of birth, Social Security numbers and loan information, and the server was accessed dozens of times. The commission charged Ascension under the Safeguards Rule with failing to make sure its vendor protected the data. The settlement requires a data security program, an independent assessment every two years and closer checks on vendors.
The duty differs by profession. An Internal Revenue Service news release of August 18, 2026 reminds tax professionals that federal law requires them to keep a written information security plan. Under the Safeguards Rule, as the commission's guide explains it, a covered firm uses multi-factor authentication for anyone who accesses customer information on its system, unless the person the rule calls its Qualified Individual approves an equally secure control in writing. The guide draws no line between staff and clients, so whether a client's own sign-in falls under the rule is a question for the firm's counsel. For lawyers, North Carolina's Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to information relating to a client's representation.
A portal covers only part of that duty, and the Safeguards Rule also asks for a written security program. The portal is where the firm sets each person's access and later checks it, and that part is what this guide covers. The rules above are United States rules, described here as general information, not legal advice.
Three ways to get a portal
| Setup | What it is | It fits when | Watch for |
|---|---|---|---|
| Buy | Portal software made for client work, paid monthly | All five jobs have to work within weeks | Fees that rise with each client or seat, and how hard it is to leave with the files |
| Assemble | Tools the firm already pays for, arranged as a portal: one shared folder per client, a request form, a status note | A handful of clients and a person who keeps the setup in order | Every folder is shared one at a time, and one wrong setting shows one client's files to another |
| Build | Custom software written for the firm | The work has a shape no product fits, and upkeep is budgeted for every year | The firm owns the bugs, the security updates and the sign-in system for as long as it runs |
A portal vendor spreads sign-in, security updates and backups across all its customers.
A first-year cost count
The firm and every figure in this example are invented. A four-person firm counts three costs for each path in its first year:
- Setup: the hours to configure the portal and move clients in, times the value of an hour, plus a developer's bill for a build.
- Running: the monthly fees, times twelve.
- Upkeep: the hours each month someone spends keeping it working, times twelve, times the same hourly value.
| Line | Buy | Assemble | Build |
|---|---|---|---|
| Setup hours, the firm's or a developer's | 20 | 30 | 200 |
| Value of one hour | $100 | $100 | $100 |
| Setup cost | $2,000 | $3,000 | $20,000 |
| Monthly fees | $150 | $40 | $60 for hosting |
| Running cost for twelve months | $1,800 | $480 | $720 |
| Upkeep hours each month | 1 | 4 | 6 |
| Upkeep cost for twelve months | $1,200 | $4,800 | $7,200 |
| First-year total | $5,000 | $8,280 | $27,920 |
The assembled portal costs more than the bought one, because four hours a month of the firm's time outweigh its lower fees. On the assemble and build paths, upkeep costs more than fees: $4,800 against $480, and $7,200 against $720.
A trial with one client
The trial is one full cycle with one organized client willing to say what confused them: a month of closing the books, one phase of a legal matter, or one project milestone. Each time that client emails instead of using the portal, a note records why. Each reason points at one of the five jobs the setup is missing, and the rest of the clients move in small groups once those gaps close.
The first sign-in
What a client meets at the first sign-in:
- The invitation comes from the firm, with the client's name and the one item waiting inside.
- The first task is small, such as one statement to upload or one item to approve.
- A second sign-in step, which a covered firm's accounts carry under the Safeguards Rule as described above. Who sees what in a client portal covers which accounts get it first.
- A screen that works on a phone, because someone at the firm opened the portal on one before any client saw it. Success criterion 2.5.8 of the Web Content Accessibility Guidelines 2.2 sets a minimum of 24 by 24 CSS pixels for pointer targets such as buttons and links, with exceptions such as enough space around a smaller target (Level AA).
- Short scheduling notes stay in email. Anything with a document or a decision goes through the portal.
The order of work
- Write the five jobs on a page, with a line for what each means at the firm.
- Price the three setups with the firm's own hours and fees. For a bought portal, get written answers on how every file and message leaves with the firm if it switches, and on the price as the client list grows.
- Fill in the client portal access plan before the first invitation. The companion guide, who sees what in a client portal, explains each choice on it.
- Run one client through a full cycle.
- Move everyone else in small groups.
Sources
- Federal Trade Commission, business guide to the Safeguards Rule, "What Your Business Needs to Know", December 2024: ftc.gov
- Google, Drive Help, "Share files from Google Drive", undated help page: support.google.com
- Federal Trade Commission, "Mortgage Analytics Company Settles FTC Allegations It Failed to Ensure Vendor Was Adequately Protecting Consumer Data", press release, December 15, 2020: ftc.gov
- Internal Revenue Service, "IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data", news release IR-2026-92, August 18, 2026: irs.gov
- North Carolina State Bar, Rules of Professional Conduct, Rule 1.6, Confidentiality of Information, undated rule page: ncbar.gov
- W3C, "Understanding Success Criterion 2.5.8, Target Size (Minimum)", Web Content Accessibility Guidelines 2.2, updated May 11, 2026: w3.org