# Manage Portal Access, Experience, Activity, and Retention

Help the right client access the portal, review customer-facing settings, follow activity, and use retention safeguards with proper authority.

Reviewed 2026-09-02

## Help a client access the portal

Open the intended client record and portal access area. Confirm identity and the destination before sending an invitation. Read the visible invitation state and send only once.

Use resend only when the prior invitation is still intended. Revoke access when it should end, then verify the client can no longer use the prior path. Stop immediately if the destination belongs to the wrong person.

## Edit the Client Portal experience

Open **Settings**, **CRM & Sales**, then **Client Portal**. Review the portal heading, introductory copy, action cards, support wording, branding, and available client experiences.

Use approved customer-facing language. Save, reopen, and inspect the portal preview at desktop and mobile sizes. Confirm that public sign-in wording contains no private record detail.

## Review portal activity

Use the client record and portal account view to distinguish invitation, identity verification, sign-in, submission, document, quote, and other client actions. Read the time and status of the exact event.

Create a follow-up task when staff action is required. A sent invitation is not proof of access, and access is not proof that a requested client action was completed.

## Manage retention and holds

Use the portal account retention controls only when your role permits them. Read the current storage status, recoverable period, quarantine, family access, recent activity, and hold state.

Use **Protect from cleanup** when an authorized hold is required. Use **Release storage hold** only when the reason has ended. Permanent deletion requires separate authorized approval and remains different from eligibility.

Reopen the account and verify the new hold, release, or approval state. Do not shorten mandatory safeguards or treat an eligible item as already removed.

## Stop conditions

Stop if identity, invitation destination, visible audience, activity meaning, retention status, hold reason, or deletion authority is uncertain.
