Portal user hub
Goal
Use the customer or supplier portal to view your documents, statements, and related self-service screens — without a staff login.
Who it is for
Invited portal users bound to a party. Auth uses a portal token ability portal:{tenant}:{party} (not staff RBAC). Staff invite/admin needs portal.manage / customer_portal.admin or supplier_portal.admin and the matching module.
Preconditions
- You accepted an invite or reset password via portal links.
- Customer portal and/or supplier portal module enabled for the tenant.
Steps
- Open the portal URL and sign in (
/portal/login) with workspace slug + password, a passkey, or a magic link, or accept invite / reset password flows. If you enrolled an authenticator app, password/magic-link sign-in may ask for a TOTP code. Manage passkeys and TOTP under portal Settings. - Use the portal shell: dashboard, invoices, bills, orders, statement, and other enabled areas (projects, payslips, tickets, KB, surveys, quotes) as entitled.
- Download or view documents and attachments shared with portal scope.
- Sign out when finished on a shared device.
Result
You see only documents for your party; staff data stays in the staff SPA.
Hard stops
Wrong/expired invite; disabled portal module; attachment over portal max size (10 MB); staff trying to use portal routes without a portal principal.