Portal seat, status link, or external member: choosing client access
Client access is not one switch. Picking the wrong level is how internal notes end up in front of the client.
Most teams reach for the client portal and stop there. There are actually three levels, and the differences matter enough that it is worth deciding deliberately per relationship rather than defaulting.
The three levels
Ordered from most access to least:
- External member — a seat on a specific project, for a client-side counterpart who works alongside you day to day.
- Portal seat — a client-facing view of their work, scoped to what you publish. They sign in; they do not get an internal seat.
- Status link — a shareable page with no sign-in at all. Convenient, and therefore the one to be careful with.
How to choose
Use the shape of the relationship, not the size of the client. A long retainer where the client has an actual counterpart doing work benefits from external membership. A project where the client wants reassurance rather than involvement wants a portal seat. A one-off where somebody just needs to see whether it shipped wants a status link.
The question worth asking before each one: if this person forwarded everything they can see to a competitor, what would that cost you? Answer honestly and the level usually picks itself.
The status link deserves its own thought
A status link is unauthenticated by design. Anyone with the URL has it, which is exactly why it is useful and exactly why it needs scoping. Treat it as public, because functionally it is.
If you would not put the contents on a public page, it should be a portal seat instead.
What clients never see
Regardless of level, vault credentials are out of reach, and so is anything in projects they have not been given access to. Access is decided by workspace role and project role together — client access narrows that, it never widens it.
If you need the client-facing view to carry your brand rather than ours, that is white-label branding, and it applies everywhere clients look.