TR Start free
HomeBlog › Guide

How to set up a customer portal: the six questions to answer before you open one

O Ohana360 Team • September 16, 2026 • 12 min read
Illustration of a customer portal screen with order and invoice lists beside the rules that control access

The technical answer to how to set up a customer portal takes about three minutes: enable the add-on, send the invitation, let the customer choose a password. The hard part comes before that, and it is six questions. If you cannot answer them, do not open the portal yet, because a portal creates no new data. It moves the data you already have onto your customer's screen.

Our example is Thornbury Supply, an eighteen-person catering equipment distributor in Bristol serving fifty-two trade accounts. Last month they counted the customer emails in the shared inbox: 131 asked where an order had got to, 88 asked for an invoice to be resent, 54 asked what was owed this month, and 41 reported something broken. That is 314 emails, a serious slice of three people's week. (Demo data.)

This guide is about which of those 314 a portal can absorb, which one it cannot, and what the portal actually shows.

What does a portal user see after signing in?

The most useful thing you can do before opening a portal is look at one yourself. The drawing below puts a Thornbury customer's screen next to the boundary of what the portal will and will not show.

What exactly does a portal user see after signing in? Thornbury Supply customer portal, demo data, through the Harbour Kitchens account 3 tabs, one account My Orders My Cases Knowledge Base ORD-1184 Undercounter fridge, 6 units Approved 9,480 Draft Approved Invoiced ORD-1176 Stainless prep benches, 14 units Invoiced 5,220 Draft Approved Invoiced MY INVOICES, ON THE SAME TAB INV-2041 Sent due 28 Sep 2026 5,220 INV-2018 Paid due 2 Sep 2026 7,140 VISIBLE IN THE PORTAL Orders on their own account, with line items Invoices for that account, status and due date Cases they opened, with the resolution note Knowledge base articles in Published status NOT IN THE PORTAL Any record belonging to another customer Running balance, statement, invoice download Reports, dashboards, the team chat Contacts, opportunities, notes, the file library

The three tabs are fixed, and so is their order.

TabWhat it listsWhat the customer can do
My OrdersOrders on their account: number, name, amount, a status badge, a progress strip for Draft, Approved and Invoiced, with line items underneathRead it; the lines, the address and the amount are untouchable
My InvoicesA separate list on the same tab: invoice number, status, due date and amountRead it; there is no download, no PDF and no statement
My CasesOnly the cases this person opened, their status and the resolution note if there is oneOpen a case with New Case: a subject and a description
Knowledge BaseEvery Knowledge360 article in Published status, with a search boxSearch and read; the article opens as plain text

Back to Thornbury's four groups. The order status question (131 emails) and the resend-the-invoice question (88) are answered in the portal. The fault reports (41) turn into cases, which means they get recorded instead of buried. The money question (54) is not answered, because there is no summed balance anywhere in the portal. The honest arithmetic: roughly 260 of those 314 emails can move, and 54 stay with you.

Tip: Before you widen the invitations, press View portal on the Portal360 home page as an admin. The portal opens through that user's eyes with a purple strip across the top, and the link on the right takes you back to your own account. See the screen your customer will see before they do.

How does the portal filter what it shows?

The security of the portal rests on one field: the Account record the portal user is attached to. The filtering happens on the server, not in the browser, so another customer's data never reaches the portal user's machine at all. There are three rules, and all three are different.

WhatThe filterWhat it means in practice
Orders and invoicesThe Account record the user is attached toInvite two people from one company and both see the same orders
CasesThe portal user who opened the caseA colleague's case is invisible; purchasing and accounts do not see each other's
ArticlesArticle status: published ones onlyYou cannot pick article by article what reaches the portal

Nothing outside those three ever leaves the CRM: contacts, opportunities, notes, the file library, reports and dashboards all stay behind. Portal users sit on the Partner (Portal) profile, which has no access to CRM tabs, and portal accounts are excluded from the team chat.

The second rule has a consequence worth saying out loud when you invite people. Give three people at one customer their own accounts and all three see the same orders, but each of them tracks only their own cases. For a customer who wants a shared case inbox, one account creates less friction than one account per person.

Careful: When a portal case lands in the CRM, the screen does not show which portal user wrote it; the record carries the account link, and the name appears only in the notification text. If you want the author on the record, add your own field to the Case object in Object Manager and fill it on the first reply.

From invitation to sign-in

Invitations go out from one place: the Invite Portal User button on Portal360 > Home, which is visible to admins only. The same job can be done from Setup > Users, where the role is set to Portal and the field is called Portal Company.

Five steps from invite to sign-in, the filter rules, revoking access Thornbury Supply setup, demo data, 14 of 52 trade accounts opened up 1 Invite from the Portal360 home 2 Account which record they belong to 3 Email the link lasts 7 days 4 Password the user sets it themselves 5 Portal the same sign-in page A portal user goes to no separate address: they sign in at ohana360.com, and because the role is Partner the portal opens instead of the CRM. HOW THE PORTAL FILTERS DATA 1 Orders and invoices By the Account record the user is tied to 2 Cases Only the ones that user opened 3 Articles Every article in Published status Invite two people from one company and they share the orders but not the cases. REVOKING ACCESS 1 Open Setup, then the Users list 2 Find the row badged Portal 3 Switch Active off (Deactivate) 4 The next sign-in is refused, records stay An invite not yet accepted: press Cancel on the Portal360 home.

The invitation dialog has three fields: email, Company and Type. Type only changes titles and wording; pick Customer and the portal is called Customer Portal, pick Supplier and it becomes Partner Portal. The data is filtered by the same rule either way, so the type is a language setting rather than a permission setting. You can change it later from the list on the Portal360 home page.

Sent invitations sit on the same page as Pending Invites, with two links: Resend and Cancel. Expired ones are flagged. Invite the same address twice and the earlier invitation is deleted, so there is only ever one live link per person.

A portal user does not go to a separate address. They sign in on the same page with their email and password, and because their role is Partner the portal opens instead of the CRM. The practical result is that there is one address to give your customers, and your logo and company name appear in the portal header.

How do you revoke access?

Turning the add-on off does not revoke anything. Someone who already has a portal account can still sign in with the add-on disabled. The way to actually end access is the Active switch on that person's row in Setup > Users: a deactivated account is told the account has been deactivated and cannot get in, while records, past cases and links stay where they are. If you want to see who signed in and when, Setup > Audit Log > Login History keeps both successful and failed attempts.

Where does a portal case land in the CRM?

When a portal user presses New Case, a case record appears in Service360. It opens with status New, priority Medium, the account taken from the portal user's company, and the description the customer typed. Your team gets a "new case from the portal" notification at the same moment, and clicking it opens the record.

Two things do not happen by themselves, and both belong in your setup plan.

From there the case follows the normal service path: priority, SLA, resolution note, close. For that chain in detail from the service side, the complaint tracking guide covers how a report gets logged and closed.

How much does the Knowledge Base tab earn its place?

The cheapest improvement you can make before opening a portal is writing articles for your five most frequent questions. With the Knowledge360 add-on enabled, every article in Published status becomes searchable on the portal's Knowledge Base tab, and the customer finds the answer before opening a case.

The limit belongs here too: you cannot pick which articles reach the portal. Every published one does. So internal procedure, discount authority and exception notes have to live in separate articles kept in Draft or Archived. For a way to build that writing habit, the knowledge base guide lays out the steps.

How Portal360 works in Ohana360

Portal360 is an add-on, enabled from the Marketplace in one click. Here is what it does, without inflation, and what it does not do, without hiding it.

Not included: what Portal360 does not do

Want to see the flow in 69 seconds?

Getting a portal standing in seven days

DayWhat to doTime
1Count a week of customer emails under four headings: order status, invoice copy, money owed, fault report15 minutes
2Enable Portal360 from the Marketplace, choose the first three accounts and fix their order and invoice statuses60 minutes
3Write Knowledge360 articles for your five most frequent questions and publish them; leave internal notes in Draft90 minutes
4Send the three invitations: email, Company, Type. Then open all three screens yourself with View portal30 minutes
5Build a record-triggered flow that sets an owner on portal cases, then open a test case and confirm it fired40 minutes
6Write your customers one paragraph: where to sign in, what they will see, what they will not (say the money question still comes to you)20 minutes
7Give the revoke procedure to one person and write it down: Setup, Users, the Active switch15 minutes

From week two there is one habit to hold: invite two more accounts a week and watch the first response time on portal cases. If the order and invoice side is new ground, the invoice and payment tracking guide is the place to start, and if records, contacts and cases are new vocabulary, what is CRM covers the basics. You can request a demo to try it with one of your own customers.

Frequently asked questions

How do you set up a customer portal, and how many steps is it?
Three. You enable the Portal360 add-on from the Marketplace. You press Invite Portal User on the Portal360 home page, type the person's email, pick the Account record they belong to and set the type, Customer or Supplier. The third step is theirs: they follow the emailed link, set their own name and password, and the link is valid for seven days. That is the whole technical job. The long part happens before it, because if that account's orders and invoices are not in the right status in the CRM, the portal puts the mistake straight on the customer's screen.
Can a portal user see another customer's data?
No. Every portal user is tied to exactly one Account record, and the server filters what it sends to the portal by that link, so only orders and invoices belonging to that account are in the response. Cases are narrower still: a user sees only the cases they opened themselves. Portal users sit on the Partner (Portal) profile with no access to CRM tabs, reports, the file library or the team chat, and the write endpoints refuse that role outright. The one risky place is the link itself, because a user attached to the wrong account sees the wrong orders. Check the Account picker twice.
Does the portal show a running balance or a statement?
It does not, and that is the limit worth knowing before you open it. The portal lists invoices with their number, status, due date and amount. There is no summed balance line, no month-end statement and no ageing table, and there is no invoice PDF to download either, because the portal is built for reading. So the question of what is owed this month keeps arriving after you open the portal. Answer it on the CRM side instead: Finance360 holds invoice and payment status, and the statement goes out from there.
Do portal users count towards my user licences?
They do not; they are counted separately. When team users are counted, accounts with the Partner role or a portal account link are excluded, so putting a customer in the portal never eats a team licence. Portal users have their own package model: the add-on covers ten portal users, every additional ten adds one more package, and the Package Summary shows it as its own line. Current plans are on the pricing page.
Who picks up a case opened from the portal?
Nobody, which is why you plan for it. When a portal user presses New Case, a record appears in Service360 with status New, priority Medium and the account filled in from the portal user's company, and your team gets a notification. The owner field, though, stays empty, because assignment rules do not run on portal cases. That differs from a web form case, where the assignment rule does run, so either hand portal cases out by hand from the unowned cases on the home page, or set an owner with a record-triggered flow, which does run on a portal case.
Can a customer edit their own records or upload files in the portal?
No. The only write action in the portal is opening a case, and that is a subject and a description. There is no editing order lines, no updating an address, no approving a quote, no signing a contract and no file upload. Present that as a boundary rather than a gap: the portal exists to stop the where-is-my-order and resend-the-invoice traffic in your inbox. When something genuinely has to change, the route is still a case, and somebody on your team makes the change in the CRM.
If I turn the add-on off, do my customers lose access?
They do not, which is why access has to be revoked on the user. Switching the add-on off in the Marketplace does not stop a portal user who already has an account from signing in. The way to actually end access is the Users list under Setup: turn that person's Active switch off, and the next sign-in is refused while their records and history stay where they are. If the invitation has not been accepted yet, the Cancel link on the Portal360 home page removes it.

Close the same three questions in your inbox

Let your customer read the order stage, the invoice number and the due date on their own screen. And let the fault arrive as a record instead of an email.

Read next