The Client Portal gives your clients a dedicated, secure interface to view evidence requests, upload files, and communicate with assessors — without needing a full Kliper account. Clients authenticate via magic link (passwordless email), so there are no credentials to manage.
Inviting a Client
Assessors invite clients to the portal from the Engagement Hub → client detail page, in the Invited clients panel.
Open the Invite Dialog
Click the Invite client button on the client detail page. The invite dialog appears.
Enter Client Details
Fill in the required fields:
| Field | Description |
|---|---|
| The client’s email address (required) | |
| Name | Full name of the contact person |
| Company | Company name — auto-filled and read-only when inviting from within a client engagement |
| Job Title | Role at the company (e.g., Security Engineer, IT Manager) |
Choose delivery and send
The invite modal shows a scope strip — the assessment and how many evidence requests are pending — so you know exactly what you’re granting access to. Pick a delivery mode:
- Send email invite — the client receives the link by email (button: Send invite)
- Copy invite link — generate the link and share it yourself, e.g. Slack or a ticket (button: Generate link)
The invite link is reusable, locked to the invitee’s email address, and valid for 30 days. The new invite appears in the Invited Clients section.
Managing Invites
Active invites are listed with the client’s name, email, job title, and last-seen time. You can:
- Resend invite email to send the magic link again
- Revoke access to immediately remove the client’s portal access
Client Authentication
The Client Portal uses magic link authentication — no passwords required.
Enter Email
The client visits the portal login page and enters their email address.
Click the Magic Link
A one-time login link is sent to their email. Clicking the link authenticates the client and redirects to the portal dashboard.
Session Persistence
The session persists across browser refreshes. If the session expires, the client re-enters their email to receive a new magic link.
Portal Dashboard
After authentication, the client sees a dashboard summarizing their evidence request status across all assessments they have been invited to.
Summary Cards
Four cards at the top provide an at-a-glance overview:
| Card | Description |
|---|---|
| Total Requests | Number of evidence requests assigned to the client |
| Open | Requests that still need attention |
| Accepted | Requests the assessor has approved |
| Changes Requested | Requests that need revisions |
A progress bar shows overall completion percentage (accepted / total).
Assessment List
Each assessment the client has been invited to appears as a card showing:
- Assessment name, type, and organization
- Per-assessment request counts (open, submitted, accepted, changes requested)
- Invitation date
Click an assessment card to view its evidence requests.
Evidence Requests List
The requests page shows all evidence requests for a specific assessment in a sortable, filterable table.
Table Columns
| Column | Description |
|---|---|
| Req # | PCI DSS requirement number (e.g., 1.2.1) |
| Title | Evidence request title |
| Priority | Color-coded badge (Critical, High, Medium, Low) |
| Status | Current workflow status (Open, Submitted, Under Review, Changes Requested, Accepted, Waived) |
| Due Date | Deadline with overdue highlighting |
| Files | Number of uploaded files |
Filtering and Sorting
- Status filter — filter requests by status using the filter dropdown
- Sort by requirement — click the sort button to cycle through default order, ascending by requirement number (1.1 → 12.10), or descending. Uses natural numeric sorting so 1.10 comes after 1.9
Request Detail Page
Clicking a request opens the detail page where the client can:
View Request Details
- Full description of what evidence is needed
- Priority level and due date
- Requirement number and tags
- Assessor’s reviewer notes (if any)
Upload Evidence Files
Clients have several ways to attach evidence to a request:
Select Files
Click the upload area or drag and drop files. Multiple files can be uploaded at once.
Upload
Files are uploaded with a progress indicator. Once complete, they appear in the files list below.
Submit for Review
After uploading all required files, click Submit to mark the request as submitted. The assessor is notified that evidence is ready for review.
Clients can attach files directly from Google Drive without downloading and re-uploading.
Connect Google Drive
Click Attach from Google Drive. On first use, you’ll be redirected to Google for one-time OAuth authorization. Kliper requests read-only access to files you explicitly select.
Pick files
The native Google Drive picker opens. Filter by file type, search, or browse shared drives. Select one or more files and click Select.
Import
Files are imported into Kliper with their original metadata preserved. Submit when ready.
Clients can import evidence straight from their Microsoft 365 — OneDrive for Business or a SharePoint site’s document library.
Connect Microsoft
Under Cloud Storage, choose SharePoint, then Sign in with Microsoft. On first use, Microsoft asks the client to consent to read-only access to their files.
Browse
Switch between My OneDrive and SharePoint sites (search a site by name), open folders, and search within a drive.
Import
Select one or more files and click Import to request. Imported files run through the same virus scan as uploads. Submit when ready.
Clients can attach Confluence pages directly as evidence. Pages are imported as PDFs.
Connect Atlassian
Click Attach from Confluence. On first use, OAuth authorizes Kliper to read your Confluence spaces and pages.
Select a space
Browse your available Confluence spaces.
Pick pages
Search by title or browse recently modified pages. Each selected page is exported from Confluence and imported into Kliper as a PDF.
Managing Uploaded Files
- Clients can delete any unsubmitted file on their request — not just files they uploaded themselves. This helps when multiple client-side contributors upload to the same request.
- Files render inline where possible:
- PDF — preview via blob URL (works cross-origin with the portal domain)
- CSV/spreadsheets — rendered as a formatted table with column headers
- Images — inline preview
- Other file types — downloadable with a file icon
Messaging
A built-in messaging thread allows the client and assessor to communicate about the specific request:
- View messages from the assessor with timestamps
- Send replies with context about the uploaded evidence
- Messages are scoped to the individual request
Dark Mode Support
The Client Portal fully supports dark mode, matching the user’s system preference. All pages — login, verification, dashboard, request list, and request detail — use semantic color tokens for consistent appearance in both light and dark themes.
The theme can be toggled via the theme switch in the portal navigation bar.
Mobile Responsive
The full portal works on mobile screens. Specifically:
- Tables collapse to stacked cards on the requests list so each request remains fully readable without horizontal scrolling
- Action bars move to overflow menus on narrow viewports to keep primary content visible
- Touch targets meet accessibility minimums for tap precision
- Messaging and file upload flows work the same on mobile and desktop — drag-and-drop still works on touch devices that support it
Clients can submit evidence end-to-end from a phone without needing a desktop session.
Recurring Tasks
When the assessing firm activates a BAU program for the client, a third nav item — Recurring tasks — appears in the portal. Client team members see the recurring PCI obligations assigned to them (daily log reviews, quarterly scans, annual training, and so on), bucketed by urgency, and mark them done with a date, note, and evidence reference that land directly in the firm’s view. Owners with a portal email also receive a daily digest when tasks become due or overdue.
See BAU & Recurring Compliance for the full program model.