Skip to content

Client Portal

How clients access and respond to evidence requests through the secure Client Portal.

Updated View as Markdown

The Client Portal gives your clients a dedicated, secure interface to view evidence requests, upload files, and communicate with assessors — without needing a full Kliper account. Clients authenticate via magic link (passwordless email), so there are no credentials to manage.

Inviting a Client

Assessors invite clients to the portal from the Engagement Hub → client detail page, in the Invited clients panel.

Open the Invite Dialog

Click the Invite client button on the client detail page. The invite dialog appears.

Enter Client Details

Fill in the required fields:

Field Description
Email The client’s email address (required)
Name Full name of the contact person
Company Company name — auto-filled and read-only when inviting from within a client engagement
Job Title Role at the company (e.g., Security Engineer, IT Manager)

Choose delivery and send

The invite modal shows a scope strip — the assessment and how many evidence requests are pending — so you know exactly what you’re granting access to. Pick a delivery mode:

  • Send email invite — the client receives the link by email (button: Send invite)
  • Copy invite link — generate the link and share it yourself, e.g. Slack or a ticket (button: Generate link)

The invite link is reusable, locked to the invitee’s email address, and valid for 30 days. The new invite appears in the Invited Clients section.

Managing Invites

Active invites are listed with the client’s name, email, job title, and last-seen time. You can:

  • Resend invite email to send the magic link again
  • Revoke access to immediately remove the client’s portal access

Client Authentication

The Client Portal uses magic link authentication — no passwords required.

Enter Email

The client visits the portal login page and enters their email address.

Click the Magic Link

A one-time login link is sent to their email. Clicking the link authenticates the client and redirects to the portal dashboard.

Session Persistence

The session persists across browser refreshes. If the session expires, the client re-enters their email to receive a new magic link.


Portal Dashboard

After authentication, the client sees a dashboard summarizing their evidence request status across all assessments they have been invited to.

Summary Cards

Four cards at the top provide an at-a-glance overview:

Card Description
Total Requests Number of evidence requests assigned to the client
Open Requests that still need attention
Accepted Requests the assessor has approved
Changes Requested Requests that need revisions

A progress bar shows overall completion percentage (accepted / total).

Assessment List

Each assessment the client has been invited to appears as a card showing:

  • Assessment name, type, and organization
  • Per-assessment request counts (open, submitted, accepted, changes requested)
  • Invitation date

Click an assessment card to view its evidence requests.


Evidence Requests List

The requests page shows all evidence requests for a specific assessment in a sortable, filterable table.

Table Columns

Column Description
Req # PCI DSS requirement number (e.g., 1.2.1)
Title Evidence request title
Priority Color-coded badge (Critical, High, Medium, Low)
Status Current workflow status (Open, Submitted, Under Review, Changes Requested, Accepted, Waived)
Due Date Deadline with overdue highlighting
Files Number of uploaded files

Filtering and Sorting

  • Status filter — filter requests by status using the filter dropdown
  • Sort by requirement — click the sort button to cycle through default order, ascending by requirement number (1.1 → 12.10), or descending. Uses natural numeric sorting so 1.10 comes after 1.9

Request Detail Page

Clicking a request opens the detail page where the client can:

View Request Details

  • Full description of what evidence is needed
  • Priority level and due date
  • Requirement number and tags
  • Assessor’s reviewer notes (if any)

Upload Evidence Files

Clients have several ways to attach evidence to a request:

Select Files

Click the upload area or drag and drop files. Multiple files can be uploaded at once.

Upload

Files are uploaded with a progress indicator. Once complete, they appear in the files list below.

Submit for Review

After uploading all required files, click Submit to mark the request as submitted. The assessor is notified that evidence is ready for review.

Clients can attach files directly from Google Drive without downloading and re-uploading.

Connect Google Drive

Click Attach from Google Drive. On first use, you’ll be redirected to Google for one-time OAuth authorization. Kliper requests read-only access to files you explicitly select.

Pick files

The native Google Drive picker opens. Filter by file type, search, or browse shared drives. Select one or more files and click Select.

Import

Files are imported into Kliper with their original metadata preserved. Submit when ready.

Clients can import evidence straight from their Microsoft 365 — OneDrive for Business or a SharePoint site’s document library.

Connect Microsoft

Under Cloud Storage, choose SharePoint, then Sign in with Microsoft. On first use, Microsoft asks the client to consent to read-only access to their files.

Browse

Switch between My OneDrive and SharePoint sites (search a site by name), open folders, and search within a drive.

Import

Select one or more files and click Import to request. Imported files run through the same virus scan as uploads. Submit when ready.

Clients can attach Confluence pages directly as evidence. Pages are imported as PDFs.

Connect Atlassian

Click Attach from Confluence. On first use, OAuth authorizes Kliper to read your Confluence spaces and pages.

Select a space

Browse your available Confluence spaces.

Pick pages

Search by title or browse recently modified pages. Each selected page is exported from Confluence and imported into Kliper as a PDF.

Managing Uploaded Files

  • Clients can delete any unsubmitted file on their request — not just files they uploaded themselves. This helps when multiple client-side contributors upload to the same request.
  • Files render inline where possible:
    • PDF — preview via blob URL (works cross-origin with the portal domain)
    • CSV/spreadsheets — rendered as a formatted table with column headers
    • Images — inline preview
    • Other file types — downloadable with a file icon

Messaging

A built-in messaging thread allows the client and assessor to communicate about the specific request:

  • View messages from the assessor with timestamps
  • Send replies with context about the uploaded evidence
  • Messages are scoped to the individual request

Dark Mode Support

The Client Portal fully supports dark mode, matching the user’s system preference. All pages — login, verification, dashboard, request list, and request detail — use semantic color tokens for consistent appearance in both light and dark themes.

The theme can be toggled via the theme switch in the portal navigation bar.


Mobile Responsive

The full portal works on mobile screens. Specifically:

  • Tables collapse to stacked cards on the requests list so each request remains fully readable without horizontal scrolling
  • Action bars move to overflow menus on narrow viewports to keep primary content visible
  • Touch targets meet accessibility minimums for tap precision
  • Messaging and file upload flows work the same on mobile and desktop — drag-and-drop still works on touch devices that support it

Clients can submit evidence end-to-end from a phone without needing a desktop session.


Recurring Tasks

When the assessing firm activates a BAU program for the client, a third nav item — Recurring tasks — appears in the portal. Client team members see the recurring PCI obligations assigned to them (daily log reviews, quarterly scans, annual training, and so on), bucketed by urgency, and mark them done with a date, note, and evidence reference that land directly in the firm’s view. Owners with a portal email also receive a daily digest when tasks become due or overdue.

See BAU & Recurring Compliance for the full program model.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close