Client portal
What your clients see when they log in.
Clients log into the same application you do, at the same address, and see a different thing. There is no separate portal to deploy or configure — a person's role decides what exists for them.
What a client gets
| Page | Contents |
|---|---|
| My Accounts | Their linked trading accounts and balances |
| My Performance | Their performance and equity over time |
| My Invoices Billing add on | Their invoices, viewable and downloadable |
| My Pools Pools add on | Their pool investments and proportional performance |
| My Transactions Pools add on | Their pool deposit and withdrawal history |
| My Profile | Their own name, email, and password |
That is the whole surface. No accounts but theirs, no copiers, no other client's anything.
"Their own" is enforced in the query rather than by hiding a menu entry. A client who deep-links to another client's invoice gets nothing back — and the routes are module-gated too, so a bookmark from when Billing was enabled fails closed after it is switched off.
It looks like you, not like us
The portal uses your branding throughout — your logo, your brand colour, your support address, your login heading. If you have added a custom domain, it is also at your address. Set all of it under Settings → Branding and Settings → Domains; see Set up your workspace.
Giving a client access
Creating a contact does not send anything. Access is granted by selecting the contacts and choosing Setup Account, which enables portal access and emails them a link to set their own password. The same action re-sends to anyone who has not logged in yet.
See Invite your team.
What clients receive by email
Digests — the periodic account summary, daily, weekly, or monthly. The monthly one is a full statement and sends even in a quiet month.
Transactional mail — welcome and password reset, and, with Billing on, invoice issued and payment received.
Clients do not receive operational alerts. A disconnected account or a failed copier goes to your notification feed, not to their inbox — which is deliberate, and worth knowing before a client asks why they were not told.
Impersonation
Admins can impersonate a user to see exactly what they see, which is far quicker than reconstructing a support question from a description.
Three things constrain it:
- Superadmins cannot be impersonated.
- Every session is logged as an activity on the target's own record, naming the impersonator.
- Sessions expire after 30 minutes and cannot be refreshed.
Payment actions are blocked while impersonating. An impersonator never makes a financial transaction on somebody else's behalf, however convenient it would be in the moment.