The four states of portal access
- Not issued — the customer has no link and no portal exists for them yet.
- Issued and active — the link works and shows the customer's current work.
- Deactivated — the business has switched the link off; it no longer opens.
- Expired — the link passed its end date and stops working on its own.
When to issue
The useful trigger is sold work. Before that, the customer has a quote and a conversation, and a portal showing an empty job list creates a worse impression than no portal at all. Once the job exists and has dates, the portal has something real to show and immediately starts absorbing status questions.
Introduce it in the same message that confirms the schedule. A link with no explanation gets ignored; a link attached to 'here is your start date, and here is where you can check it any time' gets used.
When to retire
- After close-out and final payment, when the customer no longer needs live status.
- Immediately, if the link was sent to the wrong contact.
- Immediately, on any dispute where access needs to be controlled deliberately.
- On a schedule, if you prefer every link to carry an expiry date from the start.
Why revocability is the whole design
A link that cannot be switched off is a permanent grant made by whoever forwarded it. A link that can be deactivated or expired keeps the decision with the business, which is what makes link-based access defensible in the first place.
The practical rule: one link per customer, issued deliberately, retired deliberately, reissued rather than shared around.