How do I set up and use a client portal in my accounting platform so clients can exchange and access their documents?
Applies to: United States · Updated 2026-09-27
First confirm in your platform's own U.S. help center whether a portal is built in, sold on certain plans only, or supplied by a separate connected product, and where it is switched on. Before inviting anyone, fix the portal name, branding, notifications and sign-in security. Invite each contact only to the client or entity they belong to and check their permissions, exchange documents only through the portal, keep your own copies, and remove access the day someone leaves.
What makes a portal different from email or a sharing link?
A client portal is a standing, signed-in space where each client's documents, requests and messages accumulate, visible only to the people you admit. Canopy's FAQ on secure links (updated August 17, 2026) shows the contrast inside one product: a secure link lets a non-portal user reach only the resource assigned to them, for a limited time, while the same files and tasks stay viewable in the client portal after the links expire.
What a portal adds is persistence, a permission for each person, and a visible record of what is exchanged and outstanding; the settings below protect those three.
Does your platform have a portal, and where is it switched on?
Search your accounting platform's U.S. help center, not its marketing pages, for "portal" or "client requests", and read the feature's help page for the plans that carry it and where it is switched on. Then place your platform in one of two branches:
- Built into the books. Zoho's undated overview of the Zoho Books customer portal lists it on the Free, Standard, Professional, Premium, Elite and Ultimate plans, says it is available for your organization by default, and says access must be configured for each contact person individually.
- A separate product connected to the books. Canopy runs its own client portal and connects to QuickBooks Online. Canopy's undated help on that connection says that once clients are synced, clients created in either product going forward sync to the other, and that duplicate and unmatched clients are not synced. You configure the portal in the connected product, not in the books.
If your plan lacks a portal, nothing below applies until it has one.
Who you are changes whom you admit. A practice admits people at each client: Canopy's guide to its client and contact structure (updated August 17, 2026) defines a client as an entity your firm provides services for and a contact as a person associated with a client. A business admits its own customers, and the documents are mostly its own transactions: Zoho's undated overview calls the portal a dedicated space for customers to view and manage all their transactions, with discussion over comments.
What should you decide before inviting the first client?
Settings made now apply to every client added later, and some are awkward to change once clients are live. Decide these first:
- Name and address. Zoho's undated portal preferences page says the portal name is unique to your organization and is used in the portal's URL. Canopy's help on customizing the domain name (updated August 17, 2026) says that after a change, clients are redirected from the old domain for 30 days, and the domain cannot be edited again during those 30 days.
- Branding and notifications. The same undated Zoho preferences page lets you show a message on the portal homepage and offers two emails: one to you for every portal activity, and one to the customer when you comment on a transaction. Zoho's overview says your notices go to your primary email address in Zoho Books, so make sure someone monitors it; Canopy's help on request templates (updated August 17, 2026) lets each template set a default team member to receive notifications.
- Sign-in security. Zoho's undated MFA page says that once multi-factor authentication is enabled for the customer portal it applies to all your customers and vendors, who set it up by scanning a QR code with an authenticator app. Canopy's help on firm-wide MFA settings (updated January 21, 2026) says clients are prompted to set up MFA only at new logins after the setting is applied, so switch it on before the first invitation.
- What clients can do. Zoho's undated preferences page has an option allowing customers to forward documents from the portal, and Zoho's undated overview says a person a customer forwards a transaction to is added as a contact person for that customer. Leave forwarding off unless customers may add contacts themselves.
- Who on your team can invite. Canopy's undated help on inviting contacts says any team member with access to a client can send that client's portal invitations, so settle staff assignments to clients first.
How do you invite a contact, and what does the client see?
Clean up client records first: one record per client or entity, and each person who needs access entered as a contact with their own email address. Where records sync between products, as clients do through Canopy's QuickBooks Online connection, merge duplicates before inviting so one client's documents do not split across two records.
In Zoho Books, the undated overview says the portal can be configured only for customers who have an email address; you select the customer or contact persons to admit, and Zoho Books emails them an invitation. The same overview says the customer opens that email and enters a password, and that the first screen they see is the Home dashboard. It also says transactions you create for a customer are visible to them in the portal, and the dashboard gives an overview of them.
Canopy's undated help on inviting contacts has you send invitations from the client record. Canopy's client login guide (updated August 17, 2026) says the client creates an account from the emailed invite and that all sign-ins need two-factor authentication, with a six-digit code sent to their email or phone; a device can be remembered for 30 days, after which, or on another device, the client authenticates again. Canopy's structure guide says invited contacts can view and download shared files, review invoices and complete assigned tasks.
Tell each client beforehand where the portal lives, that an invitation is coming from you, and that no one from your office will ask for their password.
How do you make sure each contact sees only what they should?
A portal fails silently: a contact admitted at the wrong scope sees another client's or entity's documents, and the wrong party is usually the one who notices. Know the controls your product offers, for example:
- Canopy's help on showing or hiding files (updated August 21, 2026) says files in a client's record are not automatically visible in the portal and that you switch visibility on per file or folder; it also says uploading a visible file into a folder marked invisible makes the folder appear in the portal, though the folder's visibility icon still shows as off until you switch it on.
- The same help lets you hide the Files tab from one contact without affecting others on that client record, and pick which contacts see each file or folder under Share > Client Portal Access; the permission to manage contact access is off by default for staff permission sets and on for admin sets.
- Canopy's undated invitation help puts portal visibility and permission options at the bottom of each contact's settings.
- Zoho's undated customer-hierarchy page describes parent and sub-customers and a setting that lets parent customers view and pay a sub-customer's transactions through the portal.
Check every contact before go-live, and again whenever a contact or entitlement changes:
- Agree in writing with the client who may see which client or entity and which documents.
- For each contact, list every client or entity it is linked to, its permission options, and the visible files and folders on each of those clients, reading each file's own visibility icon rather than its folder's.
- Compare the two lists and correct any difference before sending an invitation.
- Test the model once with a test client, as Canopy's portal troubleshooting guide (updated May 22, 2026) suggests, and a test contact at an email address you control: make one file visible, keep one hidden, sign in as the test contact, and confirm that only the visible file and only that client appear.
- In Canopy, also check each real client with the Client View icon on its Files tab, or by logging into the portal on the client's behalf where your permissions allow. The troubleshooting guide says practitioners cannot view the entire portal exactly as clients do, so keep the test contact as well.
What changes when a client has several contacts?
| If the client has | Then |
|---|---|
| One contact | Invite that person at their own address, not a shared mailbox others read. |
| Several contacts who should see the same documents | Invite each separately with identical permission options, and list each on the access record. |
| Several contacts who must see different documents | Do not rely on one client-level grant. In Canopy, set per-contact access on each file or folder and each contact's Files tab, and check each contact's permission options for invoice access too. In Zoho Books, or any product that cannot separate documents between contacts, keep the restricted documents off the portal. |
What if one client has several entities?
Give each entity its own client or customer record and link each person only to the entities they may see. Canopy's structure guide gives the example of one contact linked to both a personal tax account and a business, which is right only if that person is entitled to both. It also says a client group lets you share files across related clients; before sharing that way, establish from Canopy's help which contacts will see the file, and include group-shared files in every contact's check. In Zoho Books, leave the parent-customer view off for each sub-customer unless the parent's contacts may see every sub-customer's documents. Check each contact's entity list at every access review.
How do you publish documents and track requests?
Publishing places a document where the right contact can see it. In Canopy, you make the file or folder visible on the client record, as its show-or-hide help describes. In Zoho Books, you attach the document to a transaction with Display attachment(s) in customer portal and emails enabled; Zoho's undated Documents help says customers with portal access can then view it from their portal. As its name says, that option covers emails too.
Requesting creates a tracked item the client must answer. Canopy's help on sending a client request (updated January 28, 2026) says you choose which contact receives it, the client gets a notification email, and you can track the progress of each request; it also warns that your account may lack some features it shows, so check yours. Canopy's client guide to completing requests (updated August 17, 2026) says requests appear on the client's to-do list, files are attached with a paperclip icon, and the client ticks a checkbox to mark the request complete. Canopy's help on request templates says templates can automate a firm's client requests; build one for each recurring request. Zoho's overview says customers can upload documents in its portal; check Zoho's U.S. help first for a way to request and track them.
A request the client has ticked is not finished for you: open what was uploaded and confirm it answers the request before closing your own work. Review open requests on a fixed day each week and send anything missing back as a comment on the same request. A portal without a request feature can publish documents but cannot show what you are still waiting for.
Where do exchanged documents end up, and for how long?
This decides whether the portal is your record or only a transit channel:
- Built-in portal. In Zoho Books a published document is an attachment on the transaction itself, shown in the portal only with Display attachment(s) in customer portal and emails enabled, so it sits with the ledger record. Check Zoho's U.S. help for where customers' portal uploads are stored. Zoho's undated FAQ on cancelled subscriptions says your data remains after you cancel but can only be viewed, not modified, and is permanently deleted if the account stays inactive for more than 120 days.
- Connected product. Canopy's Files Inbox help (updated April 2, 2026) says the inbox collects files uploaded by clients or team members, and a file leaves the inbox once placed in a folder of the client record. Canopy's retention-rules help (updated August 21, 2026) says a rule on a folder applies to all its files, based on the date they were added, and that at the deadline Canopy archives them or, if you chose No action, reminds you to delete them. Get in writing from Canopy how long files stay without a rule and what happens to portal content if the subscription lapses. Unless your connected product attaches files to transactions in the books, attach any file that supports a transaction to that transaction yourself.
Do not treat the portal as your archive. Download everything you must be able to produce later into your own document system, filed by client and period. How long you must keep records is a separate legal question; the portal's behavior tells you only how long it will keep them.
How do you keep the portal the only channel?
Two channels produce two incomplete records, and the portal's list of open requests stops reflecting reality. Run one routine:
- Tell every client the date from which documents go through the portal only, and stop attaching client documents to your own emails from that date.
- When a document arrives by email anyway, file it in that client's portal record the same day and reply through the portal. Canopy's help on saving email attachments (updated July 29, 2026) describes saving an emailed attachment to a folder in the client record.
- Canopy's help on sending requests says a client who replies to a request's notification email, rather than inside the request, reaches the team member who sent it, not the assigned team member. Tell clients to answer inside the request, and have the sender file any emailed reply the same way and update the request that day.
- Update the open request the document answers, so the request list stays true.
What limits should you check before relying on it?
Establish these for your own product and plan before the first client:
- File size and type. Canopy's guide to uploading in the client portal (updated August 17, 2026) gives a maximum file size of 4.999342 GB, says any file type that passes a virus scan can be uploaded and stored, lists the types Canopy can open and edit, .pdf among them, says folders must be compressed or zipped, and gives clients 10 minutes after uploading to rename or delete a file. Zoho's undated help on invoice actions allows up to 5 files of 5 MB each on an invoice.
- Notifications. The same Canopy upload guide says the accountant is notified when a client adds a file.
- Availability and lapse. Find the vendor's statement of what happens to portal content if the subscription lapses, and ask the vendor in writing if none is published.
How do you change or remove access when people leave?
Portal access outlasts the person unless removal is routine. Run an access review whenever a client tells you a contact has left or changed role, an entity is sold or closed, or the relationship ends, and on a fixed calendar date as well. Start each review from the product's own record of portal users: in Zoho Books, each customer's Portal Status under Other Details; in Canopy, the Client List's portal users and each contact's Client Portal section. To remove access:
- In Canopy, first make another contact primary if the person is the primary contact; Canopy's help on archiving and deleting contacts (updated August 18, 2026) says a primary contact can be neither removed from a client record nor archived.
- Remove the person from every client or entity they should no longer see. Canopy's undated invitation help describes removing a contact's portal access, and Canopy's portal troubleshooting guide says removing someone as a contact removes their portal access and prevents them from logging in; for someone who has left, remove them as a contact too, and archive rather than delete if you may need the history, since the archiving help says deleting a contact is permanent. In Zoho Books, open Configure Portal Access for the customer and unselect the departed contact person; Zoho's overview describes this page for disabling a customer's access, and its invitation step lists contact persons separately.
- When the relationship ends, remove access for every contact of that client before closing or archiving its record.
- Confirm the removal. In Canopy, open every client record the person was linked to (the structure guide says the contact list shows each contact's assigned clients) and confirm they are no longer a contact on any of them. If an invitation was never accepted, remove the person as a contact rather than relying on Remove access, and ask Canopy in writing whether it stays usable. In Zoho Books, reopen the Configure Portal Access page and check the contact is unselected. Record the date and who checked.
Files a contact downloaded before removal stay with them; removal stops only further access.
What goes on the go-live checklist?
Work through these in order and keep the completed list with your setup records:
- Portal availability confirmed for your plan, and its switch-on location found
- Portal name or domain, branding and homepage message set
- Notification recipients on your side and client notification options set
- Multi-factor authentication switched on for portal users
- Client options decided, including forwarding and any parent-customer view
- Staff assignments to clients settled
- Test client and test contact created, and the visibility test passed
- One record per client or entity, duplicates merged, and each contact at their own email address
- Access list agreed with each client, and every contact's links, permissions and any files shared across a client group checked against it
- Request templates built for recurring requests
- Portal-only date announced to clients
- Own-copy routine set for documents you must keep
- Access review scheduled, plus the trigger events above
Sources
- Canopy — FAQ | Understanding Secure Links, updated August 17, 2026
- Zoho Corporation — Overview - Customer Portal (Zoho Books Help, U.S.), undated
- Canopy — Understanding the Client & Contact Structure, updated August 17, 2026
- Canopy — Connect Your Canopy Account with QBO, undated
- Zoho Corporation — Customer Portal Preferences (Zoho Books Help, U.S.), undated
- Canopy — Customize Your Domain Name, updated August 17, 2026
- Zoho Corporation — Multi-Factor Authentication for Customer and Vendor Portals (Zoho Books Help, U.S.), undated
- Canopy — How do I manage firm-wide MFA settings for team members and clients?, updated January 21, 2026
- Canopy — Invite Contacts to the Client Portal, undated
- Canopy — How-to Video: Login to the Client Portal, updated August 17, 2026
- Canopy — How Do I Show or Hide Files & Folders in the Client Portal?, updated August 21, 2026
- Zoho Corporation — Customer Hierarchy (Zoho Books Help, U.S.), undated
- Zoho Corporation — Documents (Zoho Books Help, U.S.), undated
- Canopy — Send a Client Request, updated January 28, 2026
- Canopy — Complete a Client Request in the Client Portal, updated August 17, 2026
- Canopy — Use Client Request Templates, updated August 17, 2026
- Zoho Corporation — What happens to the data in my Zoho Books organization if I cancel my subscription? (Zoho Books FAQ, U.S.), undated
- Canopy — How do I use the Files Inbox to Organize Uploaded Files?, updated April 2, 2026
- Canopy — Set Retention Rules, updated August 21, 2026
- Canopy — Save Email Attachments, updated July 29, 2026
- Canopy — Upload a File in the Client Portal, updated August 17, 2026
- Zoho Corporation — Other Actions in Invoices (Zoho Books Help, U.S.), undated
- Canopy — How can I troubleshoot and resolve common client portal access issues in Canopy?, updated May 22, 2026
- Canopy — Archive and Delete Contacts, updated August 18, 2026