Client portal requirements checklist
Updated
Define the records and actions a client needs, then compare those requirements with the actual account. Record evidence before calling the setup ready.
Download the blank access-review sheet
A printable English PDF with scope fields, expected and observed access, Pass / Fail / Not tested results, evidence and a release decision. Complete it separately; it does not change account permissions in Corcava.
Download checklist PDFBlank or Not tested is not a pass. No email required to download.
1. Define the account and scope
Record the client and project, intended recipient and role, reviewer and date, allowed project list and associated client records. Also identify the reporting channel, cadence and where written decisions will be retained.
Keep intended access precise: “Northstar website launch board” is testable; “client access” is not. State whether the account should view, comment or edit. Role names alone do not establish the permitted actions.
2. Compare expected access with evidence
Use one row per test. Record the expected result, what actually happened, the account used and the record or screen that supports the result.
| Area | Requirement to define | Evidence to record |
|---|---|---|
| Projects and tasks | Which boards and task records should be accessible? | Actual list and a direct-record check using the intended account |
| Reports | Which clients, projects, people and periods should appear? | Available filters and the resulting rows |
| Invoices, including drafts | Which invoices and preparation states may the recipient see? | Draft, sent and completed examples where available |
| Internal cost and commentary | Which fields and discussions should remain outside the shared material? | Visible fields, comments and attached content |
| Files and public links | Which documents can be opened and by which access method? | Specific link/file results; distinguish public from signed-in access |
| Write actions | Should the account be able to create, edit or comment? | Available actions and an authorized test where needed |
| Exports | Which fields are acceptable in the file you plan to share? | Review of the actual exported file and its columns |
| Access removal | What should happen when the engagement or access ends? | An authorized removal check and the remaining link behaviour |
Corcava-specific checks
- Review both selected projects and associated clients. Board assignments and report or invoice client associations are separate.
- Do not assume viewer is read-only; check project and task write or comment actions.
- The client-portal Open invoice filter includes Draft and Sent invoices. A draft is not automatically private.
- Inspect staff exports before sharing: financial columns can differ from the client report screen.
- Saving Create viewer sends an invitation. Reviewing an unsaved form does not prove the resulting account's visibility.
- A public invoice page and a signed-in portal are different views. Keep their evidence separate.
See Corcava's client portal overview for setup and the visibility guide for deciding what the engagement needs.
3. Separate readiness from delivery approval
Finish the sheet with Release or Hold, the decision owner, unresolved items and the next review date. A portal access check confirms the sharing setup; it does not accept project deliverables or a scope change.
In the fictional Northstar example, CR-001 proposes newsletter signup for $500 and a launch change from 9 to 12 October. It is still pending written approval, requested by 2 October. The current 9 October baseline remains unchanged regardless of whether the access checklist is complete.
Record that approval through the agreed decision process. A task status or portal comment should not be presented as a native acceptance workflow for every kind of document.
Checklist questions
What should a client portal requirements checklist cover?
Record the intended account, role, projects and client associations, then test visible records, available actions, report and invoice fields, shared links, exports and access removal.
Is a blank or untested item a pass?
No. Use Pass, Fail or Not tested and keep evidence for the result. Resolve required failures and untested checks before relying on the access setup.
Should clients see every task and time entry?
Choose the information needed for the agreement, then verify what the actual account can access. A desired sharing policy does not prove a matching product permission exists.
Can I use a public invoice screenshot as proof of portal permissions?
No. A public invoice page proves that specific view. Test signed-in portal access separately with the intended account.
Does the checklist save changes in Corcava?
No. The PDF is a blank printable review sheet. Complete it separately and record any resulting account or project changes through the normal app workflow.
Related working templates
- Client onboarding template— assign the setup work and responsible people.
- Weekly status report— prepare the recurring update separately from access setup.
- Change request form— retain the proposal, impact and written decision.