Members and access
Invite stakeholders, connect canonical client identity, and assign portal-specific roles.
Invite a member
- Open a portal and select Members.
- Search for and select an existing CRM contact when possible, or enter the person's email and optional display name.
- Choose a portal role.
- Send the invitation.
Workestra resolves the email through the shared business-party service. If the person already exists as a CRM contact, the portal identity links to that contact. Otherwise Workestra creates the canonical contact first. The portal does not create a separate client database.
The invitation contains a short-lived magic sign-in link. On first successful visit, the member changes from Invited to Active.
Invitations have a durable delivery generation. You can resend a fresh single-use link, change the member's role, or suspend/revoke access. The member list shows invitation, acceptance, and last-seen dates.
Portal roles
| Role | Intended use |
|---|---|
| Viewer | Read the portal and source-owned areas available to the person |
| Contributor | Participate in stakeholder workflows as supported by source areas |
| Approver | View and decide pending portal approvals |
| Billing | Billing stakeholder label for commercial workflows |
| Admin | Portal stakeholder with approval authority |
Only active Approver and Admin members can approve, request changes, or reject a portal approval.
Access model
The composed portal requires all of the following:
- A valid portal session.
- The same workspace as the portal.
- Membership in that exact portal.
- Member status of Invited or Active.
- Portal status of Published.
- A visible section and source policy for the member's portal role.
- An exact canonical record link for write/download actions.
The current release supports invitation-based access. Domain and anonymous share-link access are not active.

