Menu
Guides

The client portal checklist

Updated 25 September 2026, 7 minute read

Use these 24 checks to choose and launch a client portal. They cover how clients sign in, collecting documents, sharing files, approvals, security, branding, pricing, getting your data out, and the launch itself. Test each one during a free trial, as a client on your own phone, before committing your firm and clients to any tool.

Feature lists make every client portal look the same. This checklist is built around the things that decide whether a portal actually works for a small firm: whether clients use it, whether it saves your team time, and whether you can leave if it stops suiting you.

Run through it during a free trial. Most items take a minute to check if you do them in the product rather than on the vendor’s website. Where an item matters more for some kinds of firm, the note says so.

You can download this checklist as a plain text file to print or paste into your own notes.

Client sign-in and experience

The portal only works if clients open it. These five checks matter more than anything else on the list.

  1. Can a client sign in without creating a password? Look for sign-in by a one-time link sent to their email. Every password you ask a client to create is a reason for them to email you an attachment instead.
  2. How long does it take from invitation email to uploading a file? Time it on your phone, as a client. Under a minute is good. More than three and you’ll be walking clients through it by phone.
  3. Does the client see only what they need to act on? Open the client view. If it shows menus, dashboards or anything about your internal work, it’s built for you, not them.
  4. Does it work well in a phone browser? Many clients will photograph a document and upload it from their phone. Check the upload works without an app.
  5. Can several people at the same client use it? Businesses often have a finance contact, a decision-maker and an assistant. Each should sign in with their own email.

Collecting documents

If you spend time chasing clients for paperwork, this section is where a portal pays for itself.

  1. Can you send a checklist of documents, with one upload per item? One upload box for everything isn’t the same thing. You need to see which item is missing, not just that “some files arrived”.
  2. Are reminders automatic, and do they stop when everything’s in? Look for a schedule you can change, reminders sent at a sensible time in the client’s time zone, and no reminders for items already received.
  3. Can you reject one item and ask again, with a note? A wrong bank statement shouldn’t restart the whole request.
  4. Can you save your checklists as templates? Bookkeepers send the same month-end list every month; agencies send the same kickoff list for every new client.
  5. Can you see what’s outstanding across every client at once? Without opening each one.

The guide to stop chasing clients for documents covers how to write requests clients complete quickly.

Files, messages and approvals

  1. What’s the largest file you can upload, and does a big upload survive a flaky connection? Photographers, architects and video producers should test with a real file.
  2. Are file versions kept together? Uploading a revised document should create a new version, not a second file with a similar name.
  3. Can you keep some files internal? You’ll want working files in the same place as client files without showing them.
  4. Are messages kept per client, with files attached? So a colleague can pick up a conversation without being forwarded anything.
  5. Can clients approve something in writing, with a record? Look for a typed name, a timestamp and a copy of exactly what was approved. Architects and designers will use this at every stage.

Security

  1. Are files encrypted in transit and at rest? This should be a clear yes.
  2. Is each client’s data separated, and how? Ask whether separation is enforced only in the interface or also in the database.
  3. Is there an audit log of views, downloads and changes? And can you export it?
  4. Does the vendor say plainly what they don’t have? A vendor that states it isn’t SOC 2 certified is more trustworthy than one that implies certifications it doesn’t hold. Denby’s security page is an example of the kind of statement to look for.

Branding, pricing and leaving

  1. Can clients see your firm’s name, logo and colours, not the vendor’s? At minimum on the portal and in emails.
  2. Can you use your own domain? Such as clients.yourfirm.com. Check which plan it needs.
  3. How does the price change when you grow? Per user, per client or flat per firm. Model your team and client numbers a year from now.
  4. Can you export everything, whenever you like? Every file, plus a structured record of clients, messages and requests.
  5. What happens if you stop paying? Your data should stay readable and downloadable, never locked away.

Launching the portal

Choosing the tool is half the job. The launch decides whether clients adopt it.

Start with two or three friendly clients. Pick clients who’ll tell you what confused them. Fix your templates and wording before inviting everyone.

Write one sentence explaining why. In the welcome message: “So nothing gets lost in email, and you can always see exactly what we need.” Clients accept change more readily when they understand what’s in it for them.

Send a real request on day one. An empty portal gives clients nothing to do. A short checklist with a due date gives them a reason to open it straight away.

Close the email back door, politely. When a client emails an attachment, upload it to their page and reply with a link. After two or three times, most clients switch.

Check the numbers after a month. How many clients have signed in? How long did requests take to complete? If sign-ins are low, the problem is almost always the invitation or the first request, not the client.

Questions to ask the vendor

Some things can’t be tested in a trial. Ask these directly, by email, so you have the answers in writing.

  • Where is our data stored, and who processes it? Look for a published list of sub-processors, like Denby’s sub-processor page, rather than a vague answer.
  • How is one customer’s data separated from another’s? The best answer describes more than one layer.
  • What happens to our data if we cancel, or if you close? You want a clear export and a stated deletion period.
  • How much notice do you give before price changes? Thirty days by email is a reasonable minimum.
  • Who do we contact when something goes wrong, and how quickly do you reply? Test it: send a support question during the trial and see.
  • What’s on the roadmap for the features we need? And whether anything you rely on is listed as “coming soon”. Buy for what exists today.

Checks that matter more for some firms

The 24 checks apply to everyone, but the weighting shifts by trade.

Bookkeepers and accountants should weight document requests and templates heavily (items 6 to 10), because the same packs go out every month. Test saving a month-end template and sending it to a second client.

Architects, photographers and video producers should test large uploads (item 11) with real files over a slow connection, and check version handling (item 12) with a revised drawing or edit.

Agencies and designers should test approvals (item 15) with a real piece of artwork and look at what the approval record contains. Check white labelling (items 20 and 21) closely, because clients see the portal as part of your service.

Immigration consultants, recruiters and anyone handling identity documents should weight the security section (items 16 to 19) most, ask the vendor questions above in writing, and confirm how to permanently delete a person’s data when a case closes.

Firms planning to grow should model item 22 carefully. A tool priced per internal user can cost several times more in two years if you add staff; one priced per client grows with your client list.

A two-week trial plan

Most portals offer a 14-day trial. Used well, that’s enough to answer every question on this list with real clients rather than guesses. Here’s a plan that fits around normal work.

Day 1: set up the basics. Add your logo and colour, write the welcome message clients will see, and invite one colleague. Note how long it took. If the basics take more than an hour, the full setup will take far longer.

Day 1 or 2: be your own client. Add yourself as a client using a personal email address. Open the invitation on your phone, upload a photo of a document, send a message and approve something. This covers items 1 to 5 and shows you exactly what your clients will experience.

Day 2: build your most common request. Recreate the checklist you send most often, with a note on any item clients usually get wrong. Save it as a template (item 9).

Days 3 to 5: invite two or three real clients. Pick clients with a live need, so the request is genuine, and who’ll tell you honestly what confused them. Send the request and let the reminder schedule run (item 7).

Days 6 to 10: work through the rest. Upload a large file, replace a file with a new version, try an approval with a colleague, and look at the audit log. Ask the vendor the written questions above, including one support question to test their response time.

Days 11 to 14: look at the results. Did the invited clients sign in? How many items arrived without you chasing? What did clients ask about? Score the tool, then decide.

If a tool can’t produce a single completed request from a real client in two weeks, it’s unlikely to do better once you’re paying for it.

Scoring your shortlist

Score each tool out of 24, but weight the first two sections double: a portal clients don’t open saves you nothing, however good its security or pricing. If two tools tie, choose the one you could set up and explain to a client in an afternoon.

For example, a tool that passes every security and pricing check but needs clients to create a password, and has no reminders, might score 17 of 24. Doubling the first two sections puts it at 20 of 34. A simpler tool that nails sign-in and document requests but lacks a feature you rarely need could score 30 of 34. The second tool will almost certainly save you more time, because clients will actually use it.

For an honest look at the main options, see the best client portal software in 2026. If you’re coming from shared folders, Google Drive vs a client portal explains what changes and what doesn’t.

Set up your first client portal in 20 minutes.

14 days free. No card. Unlimited team members on every plan.