Who sees what in a client portal

How a small firm sets each person's access before the first invitation goes out, so each client opens only their own files.

Least privilege, in the National Institute of Standards and Technology's glossary, means a system gives each user only the access their assigned tasks need. In a client portal that becomes three decisions per person, made before the first invitation: which client spaces they open, which parts of those spaces they see, and what they can do there. The client portal access plan is the worksheet that records the answers.

Four levels of access

LevelWhat the person can do
NoneCannot see that part of the portal at all
SeeCan read and save a copy
AddCan see, and can upload files or send messages
ApproveCan see and add, and can sign off on a deliverable or close a request

The worksheet stops at four. Each added level is one more setting to check at every quarterly review.

One space per client

Each client gets a separate space, and nobody outside the firm opens more than one unless the firm wrote down why.

Inside the firm, staff get the clients on their list and the owner gets all of them. Giving every staff member every client takes one setting, and it hands each of them files they never work on. When someone covers for a colleague on leave, the extra access comes with dates and goes away when the cover ends.

A separate sign-in for every person

Clients often come with more than one person: a married couple filing jointly, two business partners, an office manager who handles the paperwork. Each gets a separate sign-in. A shared password leaves no record of who uploaded a file or approved a report.

In October 2022 the Federal Trade Commission brought an action against Chegg, an education technology company. According to the commission's release of October 31, 2022, Chegg let employees and contractors use a single login to reach its third-party cloud databases and did not require employees to use multi-factor authentication to log in to them. The commission's complaint says that in or around April 2018 a former contractor used those shared credentials to take a database with personal information on about 40 million users. The proposed order required Chegg to offer its users multi-factor authentication and to set schedules for deleting the data it holds.

Each second person also gets a level of their own. An office manager may need requests and documents and have no reason to open the owner's personal return, while a spouse may need everything. The answer goes on each client's row, because it changes from one client to the next.

Contractors on the firm's side

A contract bookkeeper or seasonal preparer works for the firm and still gets what a guest gets: a separate sign-in, only the client spaces the work needs, and an end date. In the access plan each contractor sits on every client table they touch, with the contract's end date.

End dates for guests

Guests are people outside both the firm and the client: the client's attorney, a lender, an insurance agent, a buyer's accountant. Made up for the worksheet: the outside attorney gets one folder at the See level for 30 days after the invitation.

Google Drive sets an expiry date on shared access only for eligible work or school accounts, according to its help page. On other accounts the firm's contact for that client removes the guest on the end date written in the plan. A file sent out through an open link behaves differently: the same page says anyone holding that link can use the file without signing in, so a forwarded link reaches people the plan never listed.

A second sign-in step

Staff accounts open every client space they are assigned, so they are the first to get the step. Under the Safeguards Rule, as the commission's guide explains it, a covered firm uses multi-factor authentication for anyone who accesses customer information on its system, unless its Qualified Individual approves an equally secure control in writing. Tax preparation firms are on the guide's list of covered businesses, and the guide draws no line between staff and clients, so a covered firm asks its counsel whether client sign-ins fall under the rule. The Cybersecurity and Infrastructure Security Agency's page on the step says people who turn it on are much less likely to be hacked. At a firm the rule does not cover, clients are offered the same step, with one sentence on why it is there. These are United States rules, and this page describes them as general information, not legal advice.

Labels that say who can see it

The access set in the plan also shows on the screen. Next to each folder and message thread, a label names who can see it.

A made-up example:

  • "Visible to you and your bookkeeper."
  • "Visible to you, Dana and your attorney until March 31."
  • "Files you add here are read by your preparer only."

A client deciding whether to upload a bank statement can read who will see it, and staff catch a wrong setting sooner when a label does not match what they expected. A padlock icon says something is protected without saying from whom.

When the work ends

The Safeguards Rule guide tells covered businesses to reconsider regularly whether each person with access still has a legitimate business need for it. Chegg's 2018 breach came through a former contractor's login. The closing steps:

  1. Remove each guest on the day their task ends, and note the date.
  2. Give a departing client an export of their files, then close their space.
  3. Remove a departing staff member's sign-in by the end of their last day, and reassign their clients.
  4. Once a quarter, read the access list for every client space with a colleague, and remove anything neither of you can explain.

The plan as a worksheet

The client portal access plan holds all of this: a checklist run before each invitation and a people table for each client, with a worked example and blank rows. At each quarterly check, two people at the firm read it beside the portal's own settings. Firms still choosing a portal start with how to set up a client portal for a small firm.

Sources

  • National Institute of Standards and Technology, Computer Security Resource Center glossary, "least privilege" (definition from Special Publication 800-12 Rev. 1), undated glossary entry: csrc.nist.gov
  • Federal Trade Commission, "FTC Brings Action Against Ed Tech Provider Chegg for Careless Security that Exposed Personal Data of Millions of Customers", press release, October 31, 2022: ftc.gov
  • Federal Trade Commission, complaint, In the Matter of Chegg, Inc., file number 202-3151, released with the October 31, 2022 announcement (the document carries no date of its own): ftc.gov
  • Google, Drive Help, "Share files from Google Drive", undated help page: support.google.com
  • Federal Trade Commission, business guide to the Safeguards Rule, "What Your Business Needs to Know", December 2024: ftc.gov
  • Cybersecurity and Infrastructure Security Agency, "More than a Password", its page on multi-factor authentication, undated and marked as archived content: cisa.gov

Talk through who sees which files

A 30-minute call about a client portal or a deal room, and about who should see which files. Bring the access plan if it is started.

Book a 30-minute callRead the guides

Booking opens Google Calendar in a new tab.