Client portal
Your clients get their own way in: a small, branded site where they see their appointments, the documents you have shared, their invoices, anything waiting for their signature, and a history of it all. They never see your dashboard, and they never create an account.
Giving a client access
Open the client, then Send portal link. They get an email with a sign-in link, and the confirmation tells you which address it went to — worth reading, because a client record often holds an address they no longer check.
The link works once and expires in 15 minutes. That is deliberate: it is a key to somebody's records, not a password. When they need to come back, they request a fresh one from the portal login page themselves.
If the button is greyed out, the client has no email address on their record.
You can send a client up to five links an hour. The button is one click and the inbox belongs to someone else.
Where the portal lives
At /portal/ followed by your organization slug — for example app.kordox.com/portal/acme. Your slug is on your organization in Settings.
Only an email that matches a client record in your organization can sign in, so the page is safe to link publicly. It does not reveal whether any particular address is one of your clients.
What clients see
| Section | Shows |
|---|---|
| Appointments | Upcoming and past bookings |
| Documents | Files you marked Shared, plus anything they uploaded |
| Requests | Open document requests, with a link to upload |
| Invoices | Sent and paid invoices, with a pay link where relevant |
| History | Everything above, on one timeline |
History is collapsed until they open it, so a client checking their next appointment does not pay for loading the rest.
What clients never see
This is the part worth trusting, so it is worth stating exactly.
The portal is built from a fixed list of client-safe sources, not by filtering your internal records down. Nothing reaches it unless it was explicitly built to. In particular:
- Your notes. Record notes, mentions, and anything your team wrote internally about the client.
- Internal files. Only files marked Shared appear. Everything else stays yours, including files attached to the same client.
- Unsent invoices. Drafts, and invoices voided before they were ever sent.
- Other clients. Every query is scoped to the one client who signed in.
Deleting a client also cuts off their access, including any link already in their inbox.
Branding it
The portal and its emails use your brand — logo, colours, and sending address — from Settings → Brand. See Brand & white-label.