The portal is default-deny: a client starts able to do nothing, and gains only the specific capabilities you grant, scoped tightly to their own data. Understanding this model is how you open the portal precisely.

Capabilities you grant#
Access is a set of granular capabilities you tick on per contact:
- Tickets — view, create, reply, and close/reopen (status).
- Projects — view, change status, and the organization grains: create tasks, edit tasks, complete tasks, plus manage buckets, move tasks, checklist, files, and comments.
- An own-only toggle that further narrows a client to records where they're the named contact.
Everything not granted is refused. The write capabilities (status changes, task actions, checklist/file/comment management) are the ones that make the portal a working surface — and every one is off until you turn it on.
Scoping — clients only ever see their own data#
Beyond capabilities, every portal request is filtered so a client can only reach their own data:
- Company scope — a client sees only their portal-enabled companies' records, always.
- Ticket boards — access is limited to the boards you allowlist. An empty allowlist means no ticket access at all — a client reaches tickets only on boards you explicitly grant.
- Projects — by default a client sees all their companies' projects; you can narrow that to a specific list. Archived projects are excluded.
- Own-only — with this on, a client sees only the tickets and projects where they're the named contact.
These scopes are applied to every query, and tasks are always re-resolved through their project — so a client can never reach another company's data by guessing an ID (unknown records simply return "not found," never confirming they exist).
Why it's safe to open#
Because access is default-deny, company-scoped, board-allowlisted, and re-checked on every request, you can extend the portal to a client with confidence: they will only ever see their own tickets and projects, on the boards you chose, with the capabilities you granted — and nothing about your internal operation, other clients, or the numbers behind the work.
The mental model: grant nothing, then add exactly what this client should do, for their own work only. The system enforces the rest — company scoping, board allowlists, and per-request re-checks mean a generous grant is still a safe one.