Skip to content
WorkOrders

Your customers

The customer portal

A place customers see their jobs with no account, two different links and why each is safe, and letting them raise a request if you switch that on.

Last updated 12 August 2026.

There is no account, and there never will be one

Your customers reach their jobs without signing up, without a password, and without installing anything. That is not a feature we have not built yet — it is a decision. A property manager checking whether someone turned up will not create an account to find out; they will ring the office instead, which is exactly the call the portal exists to save you from. Every credential a customer needs is something they already have: their own mailbox.

The portal hands out two different kinds of link, on purpose, because they grant very different things.

  • A link to one job rides in every status email — booked in, in progress, completed. It is safe to forward, because it only ever opens the one job it already described. Nobody who receives a forwarded status email learns anything they were not already sent.
  • A link to the whole job list is a magic link — a customer requests one, or you send one from their page — and it behaves like a credential rather than a receipt: it lasts 30 minutes, works once, and opens a session of a couple of hours once used.

The rule underneath both is one sentence: a credential that opens a list never travels in a forwardable email. Your customer is, routinely, a property manager who forwards your emails to the tenant who reported the fault, to the owner, to the caretaker — that is not misuse, it is their job. A link to one job survives being forwarded a hundred times because it discloses nothing new each time. A link to every job that customer has ever raised would not.

What a customer can do

From either link, a customer can see their jobs and where each one has got to — in their own words, not yours: Received, Booked in, In progress, or Completed. They can open a job to read the same summary your team sees, and they can attach a photo or video to it — useful when "it's still leaking" is easier to show than to describe.

They cannot comment or reply in the portal. There is no message box on a job page, on purpose — a caption on an upload would be one, and the portal does not accept them. If a customer has something to say about a job, the way back in is the same as it always was: they reply to the email, and that reply threads onto the job the same way any other reply does. See your own WorkOrders address for how replies find their way back.

Letting customers raise a request

A customer can also start a job from the portal — but only if you turn that on. It is off for every company until somebody switches it on under Settings → Your company, because a fourth way for work to arrive is not something we switch on for a firm just because we built it; plenty of firms want every request to come through a person who knows the customer.

It needs the stronger credential. A link to one job cannot start a request — only a customer who has signed in with the list session can see the form, which means they redeemed a single-use link emailed to an address you already hold a customer record for. A forwarded status email is not enough on its own.

A request becomes a work order immediately — there is no holding pen for triage, so nothing a customer raises sits invisible waiting for approval. It appears on your board badged as coming from the portal, and it uses the customer's own details: there is no name or email field on the form, because who is asking was already settled by the credential that let them in, and no urgency field, because a self-service urgency setting answers "emergency" every time. There are per-day limits on how often one customer can raise a request, so nobody can flood your board by accident or otherwise.

What a customer at a firm sees

One thing changes the answer to "whose jobs are in this list", and it is worth knowing before you hand a link out. If a customer belongs to an organisation — the firm they work for — their portal shows every job raised by anyone at that firm, not only their own. John and Andy at Building Co open the same list. A customer who belongs to no firm sees only their own jobs, which is what everybody did before organisations existed and is still what most people do.

That makes filing somebody under a firm a decision about who can see whose jobs. Two households that happen to share a property manager should not be one organisation. See organisations, customers and sites for how firms are put together and what else follows from one.

Managing access

From a customer's own page — Customers → the customer → Portal access — you can send a portal link by hand, for the phone call where someone cannot find the email, and you can revoke access outright. Revoking is checked on every single request that customer's session makes, not just at the door, so it takes effect at once: a two-hour session already granted stops the moment you revoke it, and any link still sitting unread in an inbox stops working too.

A firm's own page carries the same revoke, applied to everyone at it in one action. The two switches are independent on purpose: shutting off the firm shuts off all of its people, shutting off one person leaves their colleagues alone, and restoring the firm does not un-revoke somebody you revoked by name — the confirmation says so. "Portal access restored. Anyone revoked individually stays revoked."

Two addresses, same portal

Your customers can reach the portal at your own address — yourfirm.workorders.nz — or at the main workorders.nz site. Both keep working, and every link the system generates uses your firm's own address, because it is the one you would put in front of a customer. The other stays live as a fallback for anyone who has the email but has never noticed the subdomain.

Portal pages are marked so search engines leave them alone — there is no public link to your portal anywhere, and it is not meant to be found by searching.

Questions people ask

Can a customer see another customer's jobs?
Only their colleagues', and only if you have said they are colleagues. Every link and every session is tied to one company and one customer at the point it is created; what that session can then read is that customer's jobs, or — if you have filed them under an organisation — the jobs of everyone at that firm. Nothing else, ever: a property manager who deals with two trades on WorkOrders gets two separate emails, from two separate companies, and neither session can see the other's jobs.
What if they forward the email to someone else?
A status email is designed to survive that. It carries a link to one job, which discloses nothing beyond what the email already said, so forwarding it is not a leak. The stronger link — the one that opens the whole job list — is never in a status email at all; it is requested separately, lasts thirty minutes, and only works once.
Can they see our internal notes, or what we're charging?
No. A customer sees a status, a short summary, and the note left when a job was completed — the same things a status email tells them. Internal notes, the job's full timeline, urgency, your own time estimate, and anything to do with cost never reach the portal. See the emails WorkOrders sends for the fuller list of what stays inside your team.

Still stuck? Ask a person.

Nobody here is going to route you through a phone tree. Tell us what you are trying to do and we will tell you whether the product does it.