Invite clients & portal roles
You give a client access to the portal from their contact record, and the
client receives a branded email to set a password and sign in at /my. Each
portal user has a role, Viewer, Member, or Admin, that decides which portal
apps they see. A client whose role is Admin can run their own team from the
Team page without coming back to you: they invite their coworkers, set roles,
and revoke access, all scoped to their own company. This page covers both
paths, the staff grant and the client's self-service.
Grant a client their first login
The first person at a client company gets access from your side.
- Open Contacts and go to the client's contact record.
- Use the Action menu and choose Grant portal access.
- Confirm the email address and send the invitation.
- The client gets a branded email that says "Welcome to your portal", sets a
password, and lands on their home screen at
/my.
Before you send
The invite goes out only when the contact has a valid, unique email that is not already a login in your workspace, the contact is a client and not one of your staff, and your workspace's outgoing mail is working. If the client does not receive it, use Re-send Invitation on the contact.
To take access away, deactivate (archive) the portal user. This is reversible: reactivate the user to let them back in.
Set a client's role
Roles are set on the user record and only affect external portal users. Your own staff are never limited by them.
- Open the portal user (from the contact, or from Settings → Users & Companies → Users).
- Go to the Portal Role tab, shown for external users only.
- Pick Viewer, Member, or Admin. New portal users default to Member.
| Role | What it does |
|---|---|
| Viewer | The lowest rank. Sees the apps you made visible at Viewer level. |
| Member | The default. Sees the apps you made visible to members. |
| Admin | Sees everything a member sees, plus the Team page to manage their own company's people. |
What roles do and do not control
Roles decide which portal apps a person sees, not which records. Everyone in the same client company sees that company's shared records; the role raises or lowers which app cards and links are available to a given person. Viewer is the lowest visibility rank, not a read-only mode. Admin is the only role that adds the Team page. To gate a specific app to a minimum role, see Choose what clients see.
Let a client admin run their own team
Once a client has an Admin, they manage their coworkers themselves from the
Team page at /my/team. The card and the page show for Admins only.
- The client admin opens Team in their portal.
- To add someone, they enter a name and email and pick a role. The new teammate is created under the client's company and gets the same branded invite email. A duplicate login is blocked.
- To change a role, they pick a new role on the teammate's row. They cannot demote themselves.
- To remove access, they revoke the teammate, which archives that user. They cannot revoke themselves.
Each teammate shows a status: Active once they have signed in, Invited before their first sign-in, or Revoked after access is removed. A client admin only ever manages their own organization, never another client's.
Related
Last reviewed: 2026-07-19
Need a hand with this? company@everjust.co — a human answers.