Atlas
  • All-in-one
  • Solutions
  • Compare
  • Pricing
PricingGet started
  1. Atlas
  2. Guides
  3. A Client Portal for Professional Services: What To Show, and What To Never Show
August 19, 2026·10 min read·Client Portal, Client Delivery, Security

A Client Portal for Professional Services: What To Show, and What To Never Show

The hard part of a client portal is not what it shows. It is being certain, on every screen and every query, about what it does not.

A client portal looks like a presentation problem and is really an authorisation problem. The moment a firm exposes its delivery system to the people it is delivering to, every record in that system has to answer a question it never had to answer before: may this particular outsider see this?

Get it wrong in the generous direction and a client reads an internal risk entry describing their own sponsor as the project risk. There is no version of that conversation that ends well.

A filter is not a boundary

The tempting design is a flag on each record and a where clause on each query. It works, until somebody adds the fortieth query and forgets. The failure is silent: nothing errors, a screen simply shows one row too many.

The stronger design is a separate read path. Atlas gives the portal its own controllers, its own request shapes and its own read repository, and that repository never imports the internal query builders. There is no code path from a client session to the internal ones, which is a property somebody can check rather than a habit somebody has to keep.

Everything is internal until somebody says otherwise

Every exposable object defaults to internal. The only way something becomes client-visible is an explicit act that writes an audit row and a timeline entry, and that act cannot be performed through a generic update: an audience field settable in a normal edit form will eventually be set by accident.

The default is the whole safeguard. A system where objects start visible and get hidden leaks by omission; one where they start hidden and get shared leaks only by decision.

Scope a client to their own part

A client sponsor on a programme with four workstreams may be entitled to one of them. Portal access therefore needs a workstream scope as well as an engagement, and an empty scope has to mean the whole engagement rather than nothing, or every existing seat breaks the day the column ships.

What a client should be able to do, not just read

A read-only portal gets opened twice and then ignored. The portal earns its place when the client can complete something in it: sign off a deliverable, approve minutes, answer an information request, reply to a thread, upload the document the firm has been chasing.

Each of those is a write from an outsider, so each needs its own rate limit, its own audit row, and its own notification back to the firm side. In Atlas the portal mutations carry all three, and the download path is a signed, expiring URL rather than a permanent one.

The invitation is part of the security model

Portal access usually begins with an emailed link, which makes the invitation a credential. It should default to the narrowest role rather than the most useful one, expire, be revocable, and be rate limited on acceptance, because an unthrottled acceptance endpoint is a free guessing oracle against whatever token space it uses.

Keep reading

  • Client Portal Security: The Questions to Ask Before You Buy
  • Engagement Change Control That Actually Protects Margin
  • The Engagement Closure Checklist: What Good Actually Looks Like
  • Engagement Management Software: What It Actually Has To Do
  • A RAID Log People Actually Use
  • Build Versus Buy a Client Portal: The Honest Arithmetic
  • Free PDF tools
  • The all-in-one work OS

FAQ

Questions, answered.

What should a client portal never show?
Internal risk entries and their commentary, margin and rate data, internal working papers, other clients, and anything about the firm own staffing decisions. The safe rule is that everything defaults to internal and becomes visible only through an explicit share that leaves an audit row, rather than everything being visible unless somebody remembers to hide it.
Is a where clause enough to keep a client portal safe?
No. A filter has to be remembered at every query site and eventually will not be, and the failure is silent because nothing errors when one row too many is returned. A separate read path that cannot reach the internal query builders turns the guarantee into something a reviewer can verify rather than something a developer has to remember.
What makes clients actually use a portal?
Being able to finish something in it. Signing off a deliverable, approving minutes, answering an information request, uploading a document. A portal that only displays status gets opened twice and then replaced by email, because email is where the client can actually reply.
How should portal invitations be secured?
Treat the invitation as a credential. Default it to the narrowest access level rather than the most convenient, expire it, allow revocation, store only a hash of the token, and rate limit acceptance per remote address, because an unthrottled acceptance endpoint is a free guessing oracle against the token space.

Ready when you are

One workspace, not ten.

Atlas replaces the stack with one platform for tasks, projects, CRM, contracts, e-signature, PDF tools, and analytics. Start free.

Get started freeSee pricing
AtlasWork, planned itself.

The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

All systems operational
  • SOC 2 II
  • ISO 27001
  • HIPAA
  • GDPR

Product

  • Overview
  • PDF tools
  • Diagram tools
  • People & HR
  • Integrations
  • Marketplace
  • Pricing

Resources

  • Guides
  • Glossary
  • Compare
  • Docs
  • API reference
  • Support
  • Changelog
  • Status

Company

  • About
  • Careers
  • Press
  • Contact

Legal & trust

  • Trust center
  • Security
  • Privacy
  • Terms
  • DPA
  • GDPR
  • SLA
  • Refunds
  • Google API data
Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
PrivacyTermsSecurityStatus