What clients can see

The default-deny capability model — clients start with nothing and get only the specific abilities you grant, scoped to their own companies, boards, and projects.

Updated 2 min read

The portal is default-deny: a client starts able to do nothing, and gains only the specific capabilities you grant, scoped tightly to their own data. Understanding this model is how you open the portal precisely.

A client's project organization — only what you shared

Capabilities you grant#

Access is a set of granular capabilities you tick on per contact:

  • Tickets — view, create, reply, and close/reopen (status).
  • Projects — view, change status, and the organization grains: create tasks, edit tasks, complete tasks, plus manage buckets, move tasks, checklist, files, and comments.
  • An own-only toggle that further narrows a client to records where they're the named contact.

Everything not granted is refused. The write capabilities (status changes, task actions, checklist/file/comment management) are the ones that make the portal a working surface — and every one is off until you turn it on.

Scoping — clients only ever see their own data#

Beyond capabilities, every portal request is filtered so a client can only reach their own data:

  • Company scope — a client sees only their portal-enabled companies' records, always.
  • Ticket boards — access is limited to the boards you allowlist. An empty allowlist means no ticket access at all — a client reaches tickets only on boards you explicitly grant.
  • Projects — by default a client sees all their companies' projects; you can narrow that to a specific list. Archived projects are excluded.
  • Own-only — with this on, a client sees only the tickets and projects where they're the named contact.

These scopes are applied to every query, and tasks are always re-resolved through their project — so a client can never reach another company's data by guessing an ID (unknown records simply return "not found," never confirming they exist).

Why it's safe to open#

Because access is default-deny, company-scoped, board-allowlisted, and re-checked on every request, you can extend the portal to a client with confidence: they will only ever see their own tickets and projects, on the boards you chose, with the capabilities you granted — and nothing about your internal operation, other clients, or the numbers behind the work.

The mental model: grant nothing, then add exactly what this client should do, for their own work only. The system enforces the rest — company scoping, board allowlists, and per-request re-checks mean a generous grant is still a safe one.

Bring your whole services business together

Stop stitching together five tools. Run sales, delivery, support, and billing from one organization — with an AI assistant on every page.