Client portal and member area development

Everything they need. Only what they may see.

Give each known client, member or trade customer one dependable place for current status, permitted files and next actions. A focused portal is usually £900 - £2,500.

For an existing WordPress site or a bespoke React, Node.js or PHP system. Identity provider, storage and other external fees remain separate.

Client areasynthetic example
AM
Signed in asAlex Morgan

North Street Kitchen

Project client
Next actionApprove the homepage by Friday
3documents2requests1project

This identity resolves to this account before any record is shown.

Specificone identity and current role
Usefulstatus, files and actions
Accessibleassisted login and recovery
Ownedinvite, change and removal

No login and no real account

Different customers. The right view for each.

Choose a synthetic portal and switch between its overview, documents and requests. The demonstration contains no login, download, upload or stored information.

Interactive example
01
Permitted client viewOverview
synthetic
Website project

Design review

Current status
Your next actionApprove the homepage by Friday
3documents2requests

What a password-protected page leaves unresolved

The login worked. The service still did not.

A password on a page does not create a useful portal. Clients still search old email threads for the current file, ask for progress and send approvals without a dependable project reference. Shared links remain live too long, staff cannot see who has access and account recovery becomes an improvised support problem.

Search

Current files hide in email

The portal should make the latest permitted version obvious.

Scope

A changed URL finds another account

Permission is checked on every record, not hidden by navigation alone.

Identity

A team shares one password

One person cannot be traced, changed or removed safely.

Recovery

Lost access becomes guesswork

Recovery needs an owned, tested and proportionate identity check.

An account has a complete life

Invite, verify, change, remove.

Each invited person receives a specific identity and role. After suitable authentication, the portal resolves that identity to the permitted account, project, membership or trade record. Current documents, status, requests and actions share one view, while invitations, recovery, role changes, expiry and removal follow an auditable owner process.

Authentication confirms an identity. Authorisation still decides what that identity may see or do now.

  1. 01
    Invite

    Name the person, account and role

    The invitation expires and cannot quietly become a shared credential.

  2. 02
    Verify

    Use authentication suited to the risk

    Recovery and accessible alternatives are part of the same design.

  3. 03
    Use

    Check permission for every record and action

    Sensitive changes can require a fresh high-confidence check.

  4. 04
    Remove

    End access, sessions and unfinished authority

    Project closure, role change or departure follows a named owner process.

Choose the smallest useful portal

Status area, membership or operational account.

Best for a business that repeatedly shares changing documents, approvals, project status, member resources, quotes or account actions with known clients. Start with a contained status-and-file area when self-service is simple; use membership or bespoke workflow only when roles, payments, several organisations or operational actions justify it.

01Known clients need files and progress

Client status area

Current documents, approvals, progress and account actions in one contained view.

Best when the service remains personal.
02Access follows an active plan or group

Membership portal

Resources, events, renewals and preferences follow the member’s current state.

Best for repeat access with clear expiry.
03Customers act inside business workflows

Bespoke operational portal

Quotes, orders, projects, several users and role-specific approvals connect to private systems.

Best when self-service changes real operations.

Strong access without hostile login design

Security follows risk. Accessibility stays in the route.

Passkeys, email links, passwords, single sign-on or multi-factor authentication can all be appropriate in different situations. High-impact actions and suspicious access need stronger verification without forcing every visitor through unnecessary friction.

01
AssistAllow password managers, paste and browser autofill
02
StrengthenOffer suitable MFA or passkeys where risk requires it
03
LimitEach role sees only the data needed for its task
04
RecoverTest lost-device, changed-email and support routes

Connections checked before the quote

The portal presents. The source system decides.

Ernest checks the CRM, project, membership, storage, invoice, payment and identity systems before promising a view or action. The portal should not create a second uncontrolled source of truth.

Identity and current roleCRM, project or membership recordPermitted client viewDocuments, requests and approvalsInvoices, payments and notifications

Every record request is authorised on the server

Uploads and downloads follow agreed type, size and retention rules

Provider failure keeps a recoverable support route

Authenticated application proof

Real accounts, roles and shared work.

Ernest built JoinedInbox, a React and Node application that brings several inboxes into one account with team tasks and labels. It demonstrates authenticated multi-user software used by small businesses; it is not presented as a client-portal case study.

Read the JoinedInbox record
JoinedInbox15small businesses using the platform

Multiple inboxes, team tasks and labels inside one authenticated application.

React · Node · multi-user product

Acceptance is the wrong user seeing nothing

Test the boundaries and the recovery.

01Changed URLAnother account remains inaccessible.
02Expired inviteIt cannot create a live session.
03Lost deviceRecovery does not reveal or transfer access casually.
04Role removedExisting sessions and actions lose authority.
05Wrong fileType, size and ownership checks reject it safely.
06Provider failureThe client sees a useful support route without data loss.

Client portal price

A range with visible reasons.

The proposal confirms users, roles, records, actions, authentication, recovery, storage, connections and acceptance tests. The timeline follows that access and workflow audit.

See all website and system prices
Typical one-off build£900 - £2,500timeline quoted after access and workflow audit
  • Identity, role and account lifecycle
  • Permitted status, documents and actions
  • Recovery, expiry and provider failure routes
  • Acceptance tests, launch and handover

Price rises with several organisations, many roles, sensitive data, uploads, memberships, payments, large migration, complex approvals, reports or external APIs.

Standalone support£30 - £40/moorRun Growthincluded in £199/mo

Support is optional. Identity, storage, email, payment or other providers may charge their own fees.

Before adding client logins

Client portal questions.

What can a client see inside the portal?

Only the account, project, membership, documents and actions permitted by their current role. The scope is designed from real examples and tested with two similar users to make sure one cannot reach the other’s records by changing a URL, search or file reference.

Do clients need to remember another password?

Not necessarily. The right method depends on risk and audience, and may include a password-manager-friendly login, email link, passkey, single sign-on or multi-factor authentication. The route must include safe recovery and an accessible alternative. I do not block paste, password managers or other browser assistance.

Can clients upload files and send approvals?

Yes, when file type, size, storage, malware handling, retention and notification rules are agreed. An approval records the person, item, version, decision and time. High-impact actions can require re-verification rather than treating an old browser session as permanent authority.

Can a portal connect to my CRM, projects, invoices or payments?

Yes, where the source system exposes a dependable API, event or export. The portal should present the permitted view and action while the operational system remains the source of truth. Product plans, provider fees and failure routes are checked before a connection is promised.

What happens when a client, member or staff user leaves?

An owner can suspend or remove the individual identity, end active sessions and reassign any unfinished work. Membership expiry and project closure can remove access automatically after an agreed review period. Shared team passwords are avoided because they cannot identify or remove one person safely.

Can existing users and documents be migrated?

Yes, after a sample proves the identity, ownership, permission and file mappings. Old links and duplicate accounts need explicit treatment, and unnecessary files should not be copied merely because they exist. Volume, sensitivity and source quality affect the quote.

Bring two clients who should see different things

Make self-service useful without making access vague.

Show Ernest what clients ask for, where the current record lives and what must happen when access changes. You will know whether a contained area, membership portal or bespoke operational account is the right build.

Discuss your client portalExplore every system and add-on Email or telephone only. No obligation and no membership-platform reseller pitch.