The short answer
Portal access should follow the work people are authorized to do, not just the pages they can see. Define roles, record ownership, and approval powers before development. Hiding a button is a usability choice; server-side authorization is what protects the underlying action.
Make an access matrix
List roles such as client, account manager, reviewer, and administrator. For each, specify viewing, creating, editing, downloading, and deleting records. Add the organization or account boundary. Two clients with the same role should not automatically see each other's information. The business owner must approve these rules.
Enforce every request
OWASP recommends denying access by default and validating permissions on every request. A portal should apply its rules when information is retrieved or changed, including direct API requests and downloads. Do not rely on navigation visibility or a record identifier being hard to guess. Testing should include attempts outside a user's permitted account.
Handle role changes
Define what happens when a staff member changes responsibilities or a client relationship ends. Review invitations, shared accounts, password recovery, and administrative access. Keep access removal part of the operating process. A forgotten account can outlive the business relationship that originally justified it.
Test the boundaries
Create representative test users and verify allowed and denied actions. Include a reviewer who may approve but not edit, and a client who can see only their own records. Document expected results so later changes can be checked. Access controls reduce risk, but no implementation should be presented as an absolute security guarantee.
When to take the next step
Define access before real client information enters the system. Review it again whenever new roles, organizations, downloads, or administrative features are added. If nobody can confidently explain who may see a record, the issue is a missing business decision as well as a technical implementation risk.
- OwnerApproves matrix
- EngineerEnforces rules
- ReviewerTests boundaries
- AdminReviews access
Adapt these responsibilities to your team and project scope.
Before you start
- Define permissions by action and record.
- Test cross-account access attempts.
- Schedule access reviews and offboarding.
Questions clients ask
Is hiding admin buttons sufficient?
No. Permissions must be enforced where the underlying data and actions are handled.
Who should approve access rules?
A business owner familiar with responsibilities, with technical review of how those rules are enforced.
Sources & context
References checked October 6, 2026. The planning recommendations are VanKpa editorial guidance; individual project requirements vary.
A worked scenario
Consider a professional firm sharing documents with several client teams. The useful outcome is to grant appropriate access to each responsibility. This is a planning example, not a reported client result. The team needs a decision that can be checked against real work, rather than a feature list that looks complete during a presentation. The starting question is whether the proposed approach changes that particular task in a way the people doing it can recognize.
In this situation, a broad staff role exposing unrelated client information is the failure to guard against. Ask the responsible person to demonstrate an ordinary case and one difficult case using current records or safe test data. Record what they expect to happen, what actually happens, and where they need another person to intervene. Those observations establish the scope for this example; they do not justify an assumed improvement percentage or a guaranteed business result.
Decision checkpoints
| Checkpoint | Practical action | Evidence to retain |
|---|---|---|
| Prepare | Map roles to client-owned resources and actions. | The approved scope, relevant source records, and unresolved questions. |
| Verify | Test client separation and privileged administrator actions. | The test case, expected result, observed result, and correction needed. |
| Operate | Review permissions after staff and client changes. | The responsible owner, completion record, and next review trigger. |
Use these checkpoints to grant appropriate access to each responsibility; they are a sequence of decisions, not a promise of a particular schedule. A completed document or screen is not enough if the underlying action still fails. Keep unresolved items visible and describe which ones prevent progression. The evidence can be a small test record, an approved mapping, or a reviewed example. It should be understandable to someone who was not present when the work happened.
Measure the useful result
A useful check for this topic is permission tests matching the matrix divided by planned permission tests. The numerator is permission tests matching the matrix; the denominator is planned permission tests. Define the sampling window, exclusions, and source of each count before interpreting the result. If only selected examples can be reviewed, describe them as a sample. Do not present a small reviewed group as a complete picture of the business, and do not assign a target simply because a round number looks persuasive.
The measure helps reveal whether the team can grant appropriate access to each responsibility, but it does not explain every cause of success or failure. Inspect the underlying cases alongside the summary. If the count changes after test client separation and privileged administrator actions, check whether the operating result changed or the counting method changed. Retain enough context to explain the difference. When records are incomplete, state the limitation and use a direct task review instead of manufacturing a precise-looking estimate.
Step 1: Prepare the evidence
The first practical move is to map roles to client-owned resources and actions. Start with the smallest set of examples that covers the important variation in this scenario. Include an ordinary case, a case with missing information, and a case that requires intervention. Describe the intended result before reviewing the current behavior. This keeps the preparation focused on the outcome: grant appropriate access to each responsibility.
For a professional firm sharing documents with several client teams, the person responsible for the source information should take part in preparation. Ask that person to confirm which information is authoritative and which points still need a decision. Record those uncertainties beside the scope instead of hiding them in a general assumption. Preparation is complete when another team member can follow the agreed example and explain what evidence would allow the work to continue.
Step 2: Test the difficult case
The next move is to test client separation and privileged administrator actions. Compare expected behavior with observed behavior in the same test, rather than comparing two descriptions written at different times. Pay particular attention to a broad staff role exposing unrelated client information. A demonstration that works only for its author does not establish that the intended user can complete the task. Let the reviewer attempt the work with the instructions they would normally receive.
For this check, retain the input, the relevant condition, and the final disposition. A screenshot can illustrate the state, but the record also needs to explain what the team expected and why the result matters. If resource ownership is ambiguous, hold the decision open and send it to someone with the authority to resolve it. Retest the changed case after correction; an agreement to fix something is different from evidence that the correction works.
Step 3: Assign operating ownership
The operating move is to review permissions after staff and client changes. A successful initial test should lead to a repeatable responsibility, not a permanent dependency on the person who built the solution. Name the person who reviews the result, the person who can change the rule, and the person who responds when the task fails. In this scenario, each responsibility contributes to the same outcome: grant appropriate access to each responsibility.
Give the operator a short record of what healthy work looks like and what requires intervention. Include the warning case of a broad staff role exposing unrelated client information, together with the relevant records and support route. The procedure should be usable during normal work, not only during a formal review meeting. Check that an authorized backup person can follow it before treating the approach as ready for broader use.

