Portal access, roles and security
Set up personal portal access with appropriate identity association, minimal role, and secure recovery path.
A portal should feel light without being frivolous. Good security doesn't stand in the way - it reliably guides the right people to the right task.
A simple moment for the user
Portal identity, employee or partner reference and role jointly determine which data and actions become visible. Separate login areas, strong passwords and – where provided – 2FA or passkeys increase protection and traceability.
This is how the process works
- Check whether the person already has an account or a partner/employee connection.
- Create a personal account with a unique email address.
- Link it to exactly the technically correct data set and the minimal portal role.
- Pass boot data separately and test password change or recovery.
- Check allowed and prohibited data with a test account.
- Specify expiration, deactivation and regular rights checks.
How you can recognize a good portal process
- Only your own or released processes are visible.
- Direct URL calls do not bypass any rights.
- Password reset reaches the verified person.
- Users who leave will be deactivated promptly.
When the path comes to a halt
- Several people share one access.
- Partner link shows data from a wrong company.
- A portal right is combined with an internal administration right.
This is what you take with you
Every portal action remains personally assignable, technically limited and can be safely restored.
Related topics
- For portal users – Unlimited user licenses for portal apps › Data flow between portal and X-ERP
Frequently asked questions
**Can portal access be shared?**
This should be avoided. Personal accounts allow individual rights, blocking and traceable actions.
**What to do if the data is viewed incorrectly?**
Limit access immediately and check partner/employee association and role; document the incident.