Invite clients & portal roles

You give a client access to the portal from their contact record, and the client receives a branded email to set a password and sign in at /my. Each portal user has a role, Viewer, Member, or Admin, that decides which portal apps they see. A client whose role is Admin can run their own team from the Team page without coming back to you: they invite their coworkers, set roles, and revoke access, all scoped to their own company. This page covers both paths, the staff grant and the client's self-service.

Grant a client their first login

The first person at a client company gets access from your side.

  1. Open Contacts and go to the client's contact record.
  2. Use the Action menu and choose Grant portal access.
  3. Confirm the email address and send the invitation.
  4. The client gets a branded email that says "Welcome to your portal", sets a password, and lands on their home screen at /my.

Before you send

The invite goes out only when the contact has a valid, unique email that is not already a login in your workspace, the contact is a client and not one of your staff, and your workspace's outgoing mail is working. If the client does not receive it, use Re-send Invitation on the contact.

To take access away, deactivate (archive) the portal user. This is reversible: reactivate the user to let them back in.

Set a client's role

Roles are set on the user record and only affect external portal users. Your own staff are never limited by them.

  1. Open the portal user (from the contact, or from Settings → Users & Companies → Users).
  2. Go to the Portal Role tab, shown for external users only.
  3. Pick Viewer, Member, or Admin. New portal users default to Member.
Role What it does
Viewer The lowest rank. Sees the apps you made visible at Viewer level.
Member The default. Sees the apps you made visible to members.
Admin Sees everything a member sees, plus the Team page to manage their own company's people.

What roles do and do not control

Roles decide which portal apps a person sees, not which records. Everyone in the same client company sees that company's shared records; the role raises or lowers which app cards and links are available to a given person. Viewer is the lowest visibility rank, not a read-only mode. Admin is the only role that adds the Team page. To gate a specific app to a minimum role, see Choose what clients see.

Let a client admin run their own team

Once a client has an Admin, they manage their coworkers themselves from the Team page at /my/team. The card and the page show for Admins only.

  1. The client admin opens Team in their portal.
  2. To add someone, they enter a name and email and pick a role. The new teammate is created under the client's company and gets the same branded invite email. A duplicate login is blocked.
  3. To change a role, they pick a new role on the teammate's row. They cannot demote themselves.
  4. To remove access, they revoke the teammate, which archives that user. They cannot revoke themselves.

Each teammate shows a status: Active once they have signed in, Invited before their first sign-in, or Revoked after access is removed. A client admin only ever manages their own organization, never another client's.

Last reviewed: 2026-07-19

Need a hand with this? company@everjust.co — a human answers.