WorkOS by Befocusy WorkOS Help center

Who can see each document in the portal

In the client portal, access isn't all or nothing: each document has its own authorized people, and WorkOS checks it every time someone opens it.

The three ways to get access

A person sees a document if they sign in with an email that meets at least one of these conditions:

  1. They're a CRM contact linked directly to the document (the CRM link property).
  2. They're a CRM contact linked to the same Project as the document (the Relation to Projects property).
  3. They're on the team and appear as the document's Owner or a Participant (the Document owner (relation) and Participants (relation, multiple records) properties).

A team member with a WorkOS account who doesn't appear on the document doesn't get access for that reason. Linking a document only to a Company doesn't grant access either: that relation is used to fill in the recipient on your template's cover.

For this to work, map at least one of those properties in Settings → Notion databases → Documentation configuration. With none, nobody can get in.

Share a document

  1. Open the document and click Share with client. In the detail bar it looks like an icon.
  2. A panel opens with the Portal link and a button to copy it. When you open it, WorkOS activates that document's link.
  3. Below you see who has access. Linked via project or service are the contacts who arrive through the Project, each with a Send email button to send them the link. Under Other contacts are those linked directly to the document: here you can Add contact or remove one.

A document nobody has shared doesn't appear in the client's list or Desktop, and the contact needs a valid email in your CRM. If the document doesn't have anyone with access yet, the panel tells you so.

Remove access

Remove the contact from Other contacts, or delete the relation in Notion (for example, by changing the document's Project). The next time that person opens the document they'll see they no longer have access: WorkOS checks again on every opening, not just at sign-in.

Privacy

If someone asks for a code with an email that has no access, WorkOS doesn't tell them whether the email exists: it shows a generic message, "If the link is valid, we've sent a code to that email."