Clients sign in through the portal with a one-use email link. Their portal session is separate from a normal Magpie member login. Being a Contact or sharing a company name does not provide access.

Every client request checks the active portal, active client membership, enabled section, and a live grant for the requested item. Portal signing links require the same checks, including during signing and document downloads. A portal file is streamed only after these checks. Internal Contact notes, Issues, project comments, and other team work stay private unless a supported item is explicitly shared.

The portal address can be known publicly. Do not treat its slug as a secret. Disable a portal or revoke a member to cut off access.

For security concerns, Contact support.