---
title: "Client Portal"
description: "How clients access and respond to evidence requests through the secure Client Portal."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Client Portal

The Client Portal gives your clients a dedicated, secure interface to view evidence requests, upload files, and communicate with assessors — without needing a full Kliper account. Clients authenticate via magic link (passwordless email), so there are no credentials to manage.

> **Note**
>
> The portal lives at its own address — **`https://portal.kliper.dev`** — kept separate from your internal workspace. Clients open it directly from their invite link, and inside Kliper the **Client portal** sidebar entry opens `portal.kliper.dev` in a **new tab**. (Under the hood it's the same Kliper app answering on the portal hostname — visiting `portal.kliper.dev` serves the portal login page — so the client experience stays fully isolated from your workspace.)

## Inviting a Client

Assessors invite clients to the portal from the **Engagement Hub → client detail page**, in the **Invited clients** panel.

1. **Open the Invite Dialog**

   Click the **Invite client** button on the client detail page. The invite dialog appears.
2. **Enter Client Details**

   Fill in the required fields:

   | Field | Description |
   |---|---|
   | **Email** | The client's email address (required) |
   | **Name** | Full name of the contact person |
   | **Company** | Company name — auto-filled and read-only when inviting from within a client engagement |
   | **Job Title** | Role at the company (e.g., Security Engineer, IT Manager) |

   > **Note**
   >
   > When inviting from a client engagement page, the **Company** field is pre-filled with the client's name and cannot be changed.
3. **Choose delivery and send**

   The invite modal shows a **scope strip** — the assessment and how many evidence requests are pending — so you know exactly what you're granting access to. Pick a delivery mode:

- **Send email invite** — the client receives the link by email (button: **Send invite**)
- **Copy invite link** — generate the link and share it yourself, e.g. Slack or a ticket (button: **Generate link**)

   The invite link is **reusable, locked to the invitee's email address, and valid for 30 days**. The new invite appears in the **Invited Clients** section.

> **Note**
>
> Invited clients can **upload evidence files and comment** on their own requests — they **cannot** see other clients, other assessments, or any of your assessment answers.

### Managing Invites

Active invites are listed with the client's name, email, job title, and last-seen time. You can:

- **Resend invite email** to send the magic link again
- **Revoke access** to immediately remove the client's portal access

---

## Client Authentication

The Client Portal uses **magic link authentication** — no passwords required.

1. **Enter Email**

   The client visits the portal login page and enters their email address.
2. **Click the Magic Link**

   A one-time login link is sent to their email. Clicking the link authenticates the client and redirects to the portal dashboard.
3. **Session Persistence**

   The session persists across browser refreshes. If the session expires, the client re-enters their email to receive a new magic link.

> **Caution**
>
> Login magic links expire after **15 minutes** and can only be used once. If a link has expired, the client should request a new one from the login page. (This is separate from the 30-day **invite** link.)

---

## Portal Dashboard

After authentication, the client sees a dashboard summarizing their evidence request status across all assessments they have been invited to.

### Summary Cards

Four cards at the top provide an at-a-glance overview:

| Card | Description |
|---|---|
| **Total Requests** | Number of evidence requests assigned to the client |
| **Open** | Requests that still need attention |
| **Accepted** | Requests the assessor has approved |
| **Changes Requested** | Requests that need revisions |

A **progress bar** shows overall completion percentage (accepted / total).

### Assessment List

Each assessment the client has been invited to appears as a card showing:

- Assessment name, type, and organization
- Per-assessment request counts (open, submitted, accepted, changes requested)
- Invitation date

Click an assessment card to view its evidence requests.

---

## Evidence Requests List

The requests page shows all evidence requests for a specific assessment in a sortable, filterable table.

### Table Columns

| Column | Description |
|---|---|
| **Req #** | PCI DSS requirement number (e.g., 1.2.1) |
| **Title** | Evidence request title |
| **Priority** | Color-coded badge (Critical, High, Medium, Low) |
| **Status** | Current workflow status (Open, Submitted, Under Review, Changes Requested, Accepted, Waived) |
| **Due Date** | Deadline with overdue highlighting |
| **Files** | Number of uploaded files |

### Filtering and Sorting

- **Status filter** — filter requests by status using the filter dropdown
- **Sort by requirement** — click the sort button to cycle through default order, ascending by requirement number (1.1 → 12.10), or descending. Uses natural numeric sorting so 1.10 comes after 1.9

---

## Request Detail Page

Clicking a request opens the detail page where the client can:

### View Request Details

- Full description of what evidence is needed
- Priority level and due date
- Requirement number and tags
- Assessor's reviewer notes (if any)

### Upload Evidence Files

Clients have several ways to attach evidence to a request:

### Local file upload

1. **Select Files**

Click the upload area or drag and drop files. Multiple files can be uploaded at once.
2. **Upload**

Files are uploaded with a progress indicator. Once complete, they appear in the files list below.
3. **Submit for Review**

After uploading all required files, click **Submit** to mark the request as submitted. The assessor is notified that evidence is ready for review.
### Google Drive

Clients can attach files directly from Google Drive without downloading and re-uploading.

1. **Connect Google Drive**

Click **Attach from Google Drive**. On first use, you'll be redirected to Google for one-time OAuth authorization. Kliper requests read-only access to files you explicitly select.
2. **Pick files**

The native Google Drive picker opens. Filter by file type, search, or browse shared drives. Select one or more files and click **Select**.
3. **Import**

Files are imported into Kliper with their original metadata preserved. Submit when ready.

> **Note**
>
> Your Google Drive authorization can be revoked at any time from the Integrations page in Kliper or from your Google account security settings.
### SharePoint / OneDrive

Clients can import evidence straight from their Microsoft 365 — **OneDrive for Business** or a **SharePoint site's** document library.

1. **Connect Microsoft**

Under **Cloud Storage**, choose **SharePoint**, then **Sign in with Microsoft**. On first use, Microsoft asks the client to consent to **read-only** access to their files.
2. **Browse**

Switch between **My OneDrive** and **SharePoint sites** (search a site by name), open folders, and search within a drive.
3. **Import**

Select one or more files and click **Import to request**. Imported files run through the same virus scan as uploads. Submit when ready.

> **Note**
>
> Kliper requests **read-only** access and never stores the client's Microsoft credentials — the connection is scoped to the portal session and expires automatically.
### Confluence

Clients can attach Confluence pages directly as evidence. Pages are imported as PDFs.

1. **Connect Atlassian**

Click **Attach from Confluence**. On first use, OAuth authorizes Kliper to read your Confluence spaces and pages.
2. **Select a space**

Browse your available Confluence spaces.
3. **Pick pages**

Search by title or browse recently modified pages. Each selected page is exported from Confluence and imported into Kliper as a PDF.

> **Note**
>
> Confluence must be activated on your Atlassian site. If only Jira is enabled, the Confluence picker will show an activation prompt.

### Managing Uploaded Files

- Clients can **delete any unsubmitted file** on their request — not just files they uploaded themselves. This helps when multiple client-side contributors upload to the same request.
- Files render inline where possible:
- **PDF** — preview via blob URL (works cross-origin with the portal domain)
- **CSV/spreadsheets** — rendered as a formatted table with column headers
- **Images** — inline preview
  - Other file types — downloadable with a file icon

### Messaging

A built-in messaging thread allows the client and assessor to communicate about the specific request:

- View messages from the assessor with timestamps
- Send replies with context about the uploaded evidence
- Messages are scoped to the individual request

> **Tip**
>
> Use the messaging thread to ask clarifying questions about what evidence is needed rather than uploading incorrect files.

---

## Dark Mode Support

The Client Portal fully supports dark mode, matching the user's system preference. All pages — login, verification, dashboard, request list, and request detail — use semantic color tokens for consistent appearance in both light and dark themes.

The theme can be toggled via the theme switch in the portal navigation bar.

---

## Mobile Responsive

The full portal works on mobile screens. Specifically:

- **Tables collapse to stacked cards** on the requests list so each request remains fully readable without horizontal scrolling
- **Action bars move to overflow menus** on narrow viewports to keep primary content visible
- **Touch targets** meet accessibility minimums for tap precision
- **Messaging and file upload** flows work the same on mobile and desktop — drag-and-drop still works on touch devices that support it

Clients can submit evidence end-to-end from a phone without needing a desktop session.

---

## Recurring Tasks

When the assessing firm activates a **BAU program** for the client, a third nav item — **Recurring tasks** — appears in the portal. Client team members see the recurring PCI obligations assigned to them (daily log reviews, quarterly scans, annual training, and so on), bucketed by urgency, and mark them done with a date, note, and evidence reference that land directly in the firm's view. Owners with a portal email also receive a daily digest when tasks become due or overdue.

See [BAU & Recurring Compliance](/operations/bau-recurring-compliance) for the full program model.

Source: https://docs.kliper.dev/operations/client-portal/index.mdx
