Skip to content
KudosCRM

Founding offer: we set up your CRM for you — free for the first 100 teams. Book your setup

Help · Projects and delivery

The client portal, explained

Give a client a secure, read-only window into their project. Generate a tokenized link, protect it with a password and expiry, and section-gate what they see — tasks, files, timeline, billing — independently. Rotate or revoke any time.

Updated August 2026

Clients want to know how their project is going; you don't want to send them a screenshot every week or hand them a login to your CRM. The KudosCRM client portal solves both — a secure public link that shows a curated, read-only view of just one project, with no account for the client to create.

This guide generates the portal, locks it down with a password and expiry, controls exactly which sections the client can see, and shows how to rotate or revoke the link the moment an engagement ends. It never exposes budget figures or your team's email addresses.

Who this is for

Project managers and account owners who keep clients informed, plus admins setting the standard for what a client should and shouldn't see.

Before you start

  • A KudosCRM account with permission to manage the project you're sharing.
  • A project with something worth showing — tasks, files, or a timeline the client cares about.
  • A decision on which sections to expose (you can change this any time).

Read-only by design
The portal is a view, not an editor. Clients can see what you choose to share but cannot change tasks, upload files, or touch the project. The billing section, if you enable it, shows invoiced-to-date only — never the budget, your costs, or team email addresses.

Set up the client portal, step by step

  1. Generate the portal link
    On the project, generate the client portal. KudosCRM creates a secure tokenized public link — a unique URL the client opens with no login.
  2. Protect it with a password
    Set a password on the link so only people you've shared the password with can open it. Send the link and the password through separate channels for good measure.
  3. Set an expiry date
    Give the link an expiry so access ends on its own when the engagement wraps. After the date, the portal stops resolving without you having to remember to turn it off.
  4. Section-gate what the client sees
    Toggle tasks, files, timeline, and billing on or off independently. Show a client their task progress and files but keep the timeline private, for example — each section is its own switch.
  5. Share the link with the client
    Send the URL and password to your client contact. They open a clean, read-only view of just this project — no other customers, no internal notes, no budget figures, no team emails.
  6. Rotate or revoke when needed
    If a link leaks or the project ends, rotate it to invalidate the old URL, or revoke it entirely to cut off access immediately. You stay in control of the link for the life of the engagement.

What you get

  • A secure, password-protected, expiring portal link the client opens with no account.
  • Section-level control over tasks, files, timeline, and billing — show exactly what fits.
  • A read-only view that never leaks budget figures or your team's email addresses.
  • Rotate and revoke controls so you can cut or refresh access the instant you need to.

Frequently asked questions

Does the client need a login to see the portal?

No. The portal is a secure tokenized public link — the client opens it with the URL and the password you set, no account required. That keeps it frictionless for them while still being protected.

Can clients edit anything in the portal?

No. The portal is strictly read-only. Clients can view the sections you expose — tasks, files, timeline, billing — but they can't change tasks, upload files, or touch the project. It's a window into the work, not a shared workspace.

Will the client see our budget or internal costs?

Never. The portal doesn't expose the project budget, your costs, or team email addresses. If you enable the billing section, the client sees invoiced-to-date only — the amounts you've actually billed them — and nothing about how the project is funded internally.

What if the link gets shared with the wrong person?

Rotate it to invalidate the existing URL and issue a fresh one, or revoke it to cut off access entirely. Combined with the password and expiry date, that gives you full control over who can reach the portal for the life of the engagement.

Learn more

Related articles

Have an account issue this guide doesn't cover?

Open a ticket Track your requests

Start free today

Ready to give your team a CRM they'll actually use?

Start free. Bring your whole team. Cancel whenever (you won't).