
Jul 18, 2026
Updated
Written by Gregory Shein, CEO & Founder
Client Project Portal: What Clients Should See and How to Check It
Decide what a client needs to see, then verify the account can access exactly those records. A practical visibility matrix for tasks, reports, invoices and scope decisions.
A client portal should help a client understand delivery, find their billing records and make the decisions needed to move the work forward. Start with those needs, then check what the product actually exposes to the intended account.
A desired visibility policy is not the same as an implemented permission. “Internal” in a task title, a Draft invoice status, or a role called viewer does not by itself prove that information is hidden or that the account cannot make changes.
Build a visibility matrix for the engagement
| Information | Useful client view | What to verify |
|---|---|---|
| Delivery progress | Completed deliverables, remaining work and agreed dates | Which projects and tasks the account can open |
| Time and activity | The detail agreed for hourly work | The actual report filters, date range and visible fields |
| Invoices | Invoice details, payment status and amount due | Which client association supplies the invoice list; whether drafts appear |
| Decisions | The exact scope, price and date proposal awaiting a response | Where approval is recorded and what counts as acceptance |
| Files and comments | Material deliberately prepared for the client | Whether each specific record or link is available to them |
| Internal operations | Kept outside the intended client material | That costs, unrelated work and private commentary have not been included |
Use the client portal requirements checklist to record expected access and actual results. An untested row remains untested; it is not a pass.
Example: a website launch with a pending change
For Northstar Studio (Demo), the useful update on 28 September 2026 is:
- Four of six baseline tasks complete: 67% by task count.
- Test enquiry form, due 2 October, and Approve launch, due 9 October, remain open.
- The current launch baseline is 9 October.
- CR-001: newsletter signup is a pending proposal for 4 hours × $125 = $500. The proposed launch becomes 12 October only if approved; a decision is requested by 2 October.
The client needs that decision context. They do not need an internal cost rate or a staff-only discussion to understand it. A prepared weekly client report can communicate the same facts even when a suitable signed-in client view has not been configured.
The 67% measure describes six baseline tasks. Keep proposed extra work separate until the change is approved and the plan is revised. Adding an unapproved proposal to the denominator would change the percentage without changing delivery of the agreed scope.
How Corcava access is organized
Corcava separates assigned projects from associated client records. The viewer setup asks you to choose a client and projects; review both before issuing access.
Project assignments scope the board list. Client associations supply client-portal invoices and reports. In report selectors, projects belonging to an associated client can cover a broader set than the separately assigned boards. Therefore, checking that the board list looks right is not enough: check the invoice and report areas too.
The setup path is Users → Add viewer → Create viewer. Selecting Copy from client fills client details and can add that client's projects to the selection. Review the selected projects explicitly. Saving creates an invitation and sends an email; it is an invitation action, not an account preview.
Do not use an administrator's screen as evidence of the client's view. For a release check, sign in through the intended viewer account and test the records and actions agreed for that engagement.
Three assumptions to avoid
“Viewer means read-only”
Do not promise this. Project and task permissions can allow an assigned viewer to make changes or comments. Check the actions available to that account, not just whether it can open the board. If the engagement requires strictly read-only access, establish that requirement before giving access and verify it explicitly.
“Draft invoices stay private”
Corcava's client-portal Open invoice filter includes Draft and Sent invoices for associated clients. Treat that visibility as part of your invoice-preparation process. An unsent invoice is not automatically a private staff note.
“An internal comment is automatically hidden”
Do not rely on a comment's wording or location as a privacy control. Keep confidential discussion outside material accessible to the client unless the specific access rule has been verified. The same applies to attachments and public links.
Choose the level of reporting the contract needs
For hourly work, the client may need time by task and period to understand an invoice. For a fixed fee, deliverables and acceptance dates may be more useful than every time entry. This is a communication choice; it does not imply that every desired panel has an independent per-client switch.
Staff and client reports also differ. The ordinary client report interface hides staff financial totals such as Spent and Billed, while a staff spreadsheet export can contain them. Review any exported document before sharing it; an export does not inherit the recipient's screen permissions.
A public invoice link shows a particular invoice. It does not demonstrate the surrounding signed-in portal. Likewise, a task marked done records task status; it is not a version-specific client acceptance record for a scope change.
Record the access check before rollout
For each intended account, write down the expected projects and client records, then test the following:
- Open the intended board, invoice and report areas. Compare the actual records with the expected list.
- Check whether the account can create, edit or comment where you expected it only to view.
- Inspect invoice drafts, report fields and attachments, rather than testing only the main dashboard.
- Open shared links using the intended access method. A public invoice link and a signed-in portal link have different purposes.
- Record failures and unresolved tests. Fix them or choose a narrower sharing method before inviting the client to rely on the portal.
Repeat the check when client associations, project membership or the engagement's sharing requirements change. For practical setup expectations, see the client portal feature overview; for handling new work, see change requests without scope creep.