Operating ProcedureExecution layer

Client Portal Security Review (QA)

A checklist with 7 steps: Inventory every active client portal and its data scope.

By InnovaAI ResearchPublished

checklist

Client Portal Security Review (QA)

  1. 01

    Inventory every active client portal and its data scope

    List all portals your agency runs, noting which client data categories each one stores, from creative assets to billing records. This baseline makes the rest of the review measurable.

  2. 02

    Map portal access against current client contracts

    Compare who can see what in each portal against the permissions your retainer or statement of work actually grants. Flag any client who has access to deliverables or files they have not paid for.

  3. 03

    Verify multi-factor authentication is enforced for all portal users

    Check that every portal, whether it is a bundled platform like SuiteDash or a standalone tool like Clinked, requires MFA for both agency staff and client logins. Disable any account that bypasses this control.

  4. 04

    Audit external sharing links and their expiration policies

    Review any public or unlisted share links that let clients or third parties view files without logging in. Confirm each link has an expiry date and revoke any that are older than 30 days.

  5. 05

    Confirm data residency and subprocessor disclosures for each portal vendor

    Check where each portal provider stores client data and whether they list subprocessors that handle that data. For clients under GDPR or sector rules, document this in your compliance file.

  6. 06

    Test the portal's activity log for completeness and tamper resistance

    Generate a test action in each portal and verify it appears in the audit log with a timestamp and user ID. If the log is editable by admins, note that limitation in your risk register.

  7. 07

    Review offboarding procedures for departed staff and former clients

    Confirm that when an employee leaves or a client contract ends, their portal access is revoked within 24 hours. Run a quarterly check to catch any orphaned accounts.