Your customers
The customer portal
A place customers see their jobs with no account, two different links and why each is safe, and letting them raise a request if you switch that on.
Last updated 12 August 2026.
There is no account, and there never will be one
Your customers reach their jobs without signing up, without a password, and without installing anything. That is not a feature we have not built yet — it is a decision. A property manager checking whether someone turned up will not create an account to find out; they will ring the office instead, which is exactly the call the portal exists to save you from. Every credential a customer needs is something they already have: their own mailbox.
Two links, and why they are different
The portal hands out two different kinds of link, on purpose, because they grant very different things.
- A link to one job rides in every status email — booked in, in progress, completed. It is safe to forward, because it only ever opens the one job it already described. Nobody who receives a forwarded status email learns anything they were not already sent.
- A link to the whole job list is a magic link — a customer requests one, or you send one from their page — and it behaves like a credential rather than a receipt: it lasts 30 minutes, works once, and opens a session of a couple of hours once used.
The rule underneath both is one sentence: a credential that opens a list never travels in a forwardable email. Your customer is, routinely, a property manager who forwards your emails to the tenant who reported the fault, to the owner, to the caretaker — that is not misuse, it is their job. A link to one job survives being forwarded a hundred times because it discloses nothing new each time. A link to every job that customer has ever raised would not.
What a customer can do
From either link, a customer can see their jobs and where each one has got to — in their own words, not yours: Received, Booked in, In progress, or Completed. They can open a job to read the same summary your team sees, and they can attach a photo or video to it — useful when "it's still leaking" is easier to show than to describe.
They cannot comment or reply in the portal. There is no message box on a job page, on purpose — a caption on an upload would be one, and the portal does not accept them. If a customer has something to say about a job, the way back in is the same as it always was: they reply to the email, and that reply threads onto the job the same way any other reply does. See your own WorkOrders address for how replies find their way back.
Letting customers raise a request
A customer can also start a job from the portal — but only if you turn that on. It is off for every company until somebody switches it on under Settings → Your company, because a fourth way for work to arrive is not something we switch on for a firm just because we built it; plenty of firms want every request to come through a person who knows the customer.
It needs the stronger credential. A link to one job cannot start a request — only a customer who has signed in with the list session can see the form, which means they redeemed a single-use link emailed to an address you already hold a customer record for. A forwarded status email is not enough on its own.
A request becomes a work order immediately — there is no holding pen for triage, so nothing a customer raises sits invisible waiting for approval. It appears on your board badged as coming from the portal, and it uses the customer's own details: there is no name or email field on the form, because who is asking was already settled by the credential that let them in, and no urgency field, because a self-service urgency setting answers "emergency" every time. There are per-day limits on how often one customer can raise a request, so nobody can flood your board by accident or otherwise.
What a customer at a firm sees
One thing changes the answer to "whose jobs are in this list", and it is worth knowing before you hand a link out. If a customer belongs to an organisation — the firm they work for — their portal shows every job raised by anyone at that firm, not only their own. John and Andy at Building Co open the same list. A customer who belongs to no firm sees only their own jobs, which is what everybody did before organisations existed and is still what most people do.
That makes filing somebody under a firm a decision about who can see whose jobs. Two households that happen to share a property manager should not be one organisation. See organisations, customers and sites for how firms are put together and what else follows from one.
Managing access
From a customer's own page — Customers → the customer → Portal access — you can send a portal link by hand, for the phone call where someone cannot find the email, and you can revoke access outright. Revoking is checked on every single request that customer's session makes, not just at the door, so it takes effect at once: a two-hour session already granted stops the moment you revoke it, and any link still sitting unread in an inbox stops working too.
A firm's own page carries the same revoke, applied to everyone at it in one action. The two switches are independent on purpose: shutting off the firm shuts off all of its people, shutting off one person leaves their colleagues alone, and restoring the firm does not un-revoke somebody you revoked by name — the confirmation says so. "Portal access restored. Anyone revoked individually stays revoked."
Two addresses, same portal
Your customers can reach the portal at your own address —
yourfirm.workorders.nz — or at the main workorders.nz site. Both keep
working, and every link the system generates uses your firm's own address, because
it is the one you would put in front of a customer. The other stays live as a
fallback for anyone who has the email but has never noticed the subdomain.
Portal pages are marked so search engines leave them alone — there is no public link to your portal anywhere, and it is not meant to be found by searching.