Access control · Audit logs · Instant revoke

Secure client portal software with an audit log behind every file

Secure client portal software has to answer one question your shared Drive folder cannot: who opened that document, when, and from where. AgentUI gives every client their own logged-in view of only their records, with permissions set per client and per document type. When an engagement ends, you revoke access in one click and the trail stays.

Access Trail
LIVE
User
Action
Document
Time · IP
m.alvarez@northbay.co
Downloaded
Invoice-2091.pdf
14:02:11
m.alvarez@northbay.co
Viewed
Statement-Q3.xlsx
14:01:48
j.okafor@agentui.ai
Edited
Scope-of-Work.docx
13:47:02
t.reyes@harborline.com
Access revoked
All Harborline records
13:12:39
t.reyes@harborline.com
Denied — no permission
Payroll-Aug.csv
13:12:55
s.whitfield@northbay.co
Viewed
Contract-v4.pdf
11:26:03
j.okafor@agentui.ai
Invited user
s.whitfield@northbay.co
09:04:17
Append-only · 1,284 entries this monthExport CSV
Copy the prompt

The prompt that builds a secure client portal

Paste this into AgentUI and you get the security model described on this page: clients, portal users, documents typed by category and an access log — with each client scoped to their own records, staff and admin split apart, and revoked users kept in the history. Edit the document types and role names before you paste so they match your engagements. For more variants, see the client portal prompt hub.

The prompt stays in English — it is what the builder reads.

Prompt
Ready to paste
Build a secure client portal for my firm.

Create a shared database with four tables: clients (client name, contact email, engagement status of Active, Paused or Ended, account manager), portal users (linked to a client, name, email, client role of Client admin or Bookkeeper, access status of Active or Revoked, last sign-in), documents (linked to a client, title, file attachment, document type of Contract, Invoice, Report, Payroll or Internal note, uploaded by, which client roles may view it) and access log (linked to a document and a user, action of Viewed, Downloaded, Edited, Shared, Permission changed or Denied, timestamp, IP address).

Give every portal user their own login. They must only ever see documents where the client record is their own client, and never documents typed Payroll or Internal note. Give my team two internal roles: staff, who upload and edit documents for their assigned clients, and admin, who can also invite portal users, change document-type permissions and revoke access.

Build a client document view, an internal access review view listing every portal user with their client, role and access status, and an audit view filterable by user, document and date range.

When an engagement ends, set that client's portal users to Revoked so they cannot sign in or open anything, and keep their access log history intact.
Paste into AgentUI chat
01

Access is scoped to the record, not to the folder

Client portal security fails at the folder level: someone gets added to the wrong shared drive and sees six other clients' files. In AgentUI every record belongs to a client, and a portal user only ever queries rows tagged with their own client ID. There is no folder to mis-share, no link to forward, and nothing outside their scope is even loaded.

Northbay Co. · Client View
SIGNED IN
NB
m.alvarez@northbay.co
Client admin · 4 records visible
Invoice-2091.pdf
Due Sep 14 · $8,400
Unpaid
Statement-Q3.xlsx
Updated 2 hours ago
New
Contract-v4.pdf
Signed Jun 02
Signed
Onboarding-checklist
6 of 8 complete
In progress
Hidden from this user: Payroll, Internal notes, 2 other clients
02

A client portal with an audit log of every view, download and edit

Every action writes a line: user, action, document, timestamp, IP address. Viewed, downloaded, edited, invited, revoked. When a client asks whether their accountant ever opened the Q3 file, or your own auditor asks who exported the payroll export, you filter the log instead of reconstructing an email thread. Log entries are append-only — nobody edits history, including you.

user · action · document
timestamp · IP address
append-only, exportable
Permission Matrix
3 ROLES
Client · RoleInvoicesContractsReportsPayrollInternal notes
Northbay Co.
Client admin
viewviewview
Northbay Co.
Bookkeeper
editview
Harborline Ltd.
Client admin
viewview
Vesta Group
Client admin
viewviewview
Internal
Account manager
editediteditviewedit
Applied to every new client of this type automatically
03

Permissions per client and per document type

Roles are a matrix, not a switch. A client contact can view invoices but not the internal margin sheet. Their bookkeeper can upload receipts but never see the contract. Your account manager edits everything for their own clients and nothing for anyone else's. You set it once per role, apply it to every new client, and change it without touching a file.

04

Revoke access the moment an engagement ends

Secure document sharing with clients is mostly about the offboarding you never got around to. Deactivate a portal user and their session dies, their share links stop resolving, and downloads they no longer have rights to are refused — immediately, not at the next access review. Share links can be given an expiry date and can require sign-in, so a forwarded URL is worth nothing on its own.

Share Settings · Statement-Q3.xlsx
RESTRICTED
Require sign-inOn
Allow downloadOff
Link expiresSep 30, 2026
Max recipients2 of 2 used
t.reyes@harborline.comAccess revoked
Session ended · 3 links deactivated · logged 13:12:39
05

Shared Drive folders vs. a secure client portal

This is the honest comparison, because a shared folder plus a tracker spreadsheet is what most teams are actually replacing.

Shared folders & emailAgentUI client portal
Who can see whatWhoever holds the linkRole and client ID, checked per record
Record of who opened a fileNone you can defendAppend-only audit log with timestamp and IP
Removing an ex-contractorManual, folder by folderDeactivate the user once
Source of the numbersCopies of copies in spreadsheetsOne shared database, auto-refreshed
Who keeps it runningThe one person who built itYour team plus AgentUI onboarding
06

A human team configures your permission model with you

The reason most portals leak is that the access model lives in one person's head. AgentUI onboarding is white-glove: we map your client types, roles and document categories with you, build the portal from that model, and hand over something documented that your ops lead can change later. The infrastructure meets SOC 2 Type II standards, with data encrypted at rest and in transit.

White-glove onboarding
Documented offboarding
SOC 2 Type II infrastructure

Questions buyers ask

Can a client ever see another client's records?

No. Portal queries are filtered by the signed-in user's client ID before any data is returned, so there is no view in the product where two clients' records coexist.

How far back does the audit log go, and can it be exported?

Entries are retained for the life of the workspace and can be filtered by user, document or date range and exported for an audit or a client security questionnaire.

What happens to files a client already downloaded?

A downloaded copy is out of any portal's control — ours included. What the portal controls is future access: revoking a user stops new views, new downloads and any outstanding share links, and the whole sequence is logged.

Show your client the log, not a promise

Bring your client list, your document types and the roles you need. We build the permission model with you and you leave the call knowing exactly who can see what.