Before you begin
- Be signed in to the account that owns the client and the records being shared.
- Confirm each item belongs to the intended client before sharing it.
How portal access works
A client portal link uses a high-entropy access token. VoltMate stores only a SHA-256 hash of that token in the database. Access is checked for expiry, revocation and the owning account/client relationship.
Jobs, quotes, invoices and shared certificates are resolved inside the authorised client/account boundary. Certificate sharing also checks that the source inspection belongs to that same client.
Share safely
- 1
Open the intended Client record and review the client's details.
- 2
Create or manage portal access from that client context.
- 3
Select only the client-facing records that should be available through that portal.
- 4
Copy the portal link only to the intended recipient using an appropriate channel.
- 5
Revoke or replace access when the link is no longer needed or may have been disclosed to the wrong person.
Privacy and indexing
Portal pages are configured as private/no-store, no-referrer and noindex/nofollow/noarchive/nosnippet. Public Web Analytics is restricted to an explicit public-page allowlist and does not include private portal paths.
Common mistakes
- Sharing a portal URL in a public post or searchable document.
- Assuming a portal link is safe forever instead of revoking access when its purpose ends.
- Sharing a certificate before confirming it belongs to the correct client's inspection.
Troubleshooting
If a portal link no longer works, it may be expired, revoked or inconsistent with the owning client/account. Create or manage access from the correct Client record instead of weakening the access checks.