Skip to main content
The Access tab in Portal Studio decides who can sign in to a portal. From it (and from the Preview tab) you can also impersonate a customer: open a real signed-in session as them, so you see exactly what they see.

Prerequisites

  • A portal you’ve already created (see Creating a Portal)
  • The manage portals permission (admins and builders). Without it, the Access tab only shows whether the two switches are on or off, and impersonation isn’t available.

How Sign-In Is Decided

A portal has two audiences, each with its own switch at the top of the Access tab: Both audiences sign in with the same one-time email code (see Customer Sign-In).
Customers on doesn’t mean anyone can get in. A customer also needs a grant that matches them. A new portal has no grants, so no customer can sign in until you add one.
Keep these rules in mind:
  • A grant decides whether someone gets in, never which accounts they see. Everyone a grant admits sees every account they’re a contact of.
  • Grants never apply to teammates. The Your team switch alone decides whether your colleagues get in.
  • Only people with a contact record can sign in. A grant for an address that isn’t a contact on any account saves, but admits nobody until that person is added as a contact.
  • Switching Customers off suspends every grant without deleting it. Switch it back on and the same people are admitted again.
  • With both switches off, nobody can sign in. The published site still loads, but it turns every visitor away at sign-in. Preview and impersonation still work.

Adding Grants

Select Add grant and choose a type:
  • People — Type email addresses (one person each) or @domain.com (everyone at that domain), and press Enter after each one. A domain grant picks up new contacts at that domain as soon as they’re added. Public email providers such as @gmail.com are rejected; add those people by address instead.
  • Rule — Build a filter on people’s fields, for example Title contains VP. Everyone who matches is admitted, and the rule keeps up as your contacts change. A portal can have one rule; remove the existing one to write a new one.
While you type, the dialog warns about addresses that won’t work: someone with no contact record, a teammate (grants don’t apply to them), or someone on record who isn’t a customer contact. The Grants list shows each grant with who it admits: how many accounts an email grant’s person sees, or how many people a domain or rule matches. Anything that admits nobody is highlighted. If your rule matches nobody, a warning suggests loosening it or removing it. To remove a grant, select its trash icon and confirm. Anyone no other grant admits is signed out within the hour.

Seeing Who Can Sign In

The People list shows everyone your grants admit today, with their accounts and which grant types admit them. Search it by name or email. If Customers is switched off, the list shows who the grants would admit.

Checking an Address

Use Check an address (or Check an address that is not listed under People) to see whether a specific email would get in. It runs the same check sign-in uses, but starts no session. The answer is one of: An Admitted result lets you open the portal as that person straight from the dialog.

Impersonating a Customer

Impersonation opens the portal in a new tab, signed in as a specific customer contact. Use it to reproduce what a customer reports, or to check a change against their real data.
This is a real session, not a simulation. Anything you do in it, such as editing a project, completing a task, commenting, or chatting with a Digital Worker, actually happens and is recorded against you. The Preview tab’s Preview as is the safe way to look without writing anything.

Where to Start It

  • Preview tab — Pick an account and person in Preview as, then open the ⋮ menu next to it.
  • Access tab → People — Select Open as this user on a person’s row. If they’re a contact of several accounts, choose which account to open. While Customers is switched off, the row shows Sharing off instead.
  • Check an address — After an Admitted result, open the portal as that person.

Preview URL or Live Site

Every entry point asks which build to open:
  • Impersonate user in preview URL — Your latest deployed preview, on its own preview address. It isn’t customer-facing. This needs a preview that’s already built; see Previewing and Going Live.
  • Impersonate user in live site — The published portal on its customer-facing address. It’s unavailable until the portal is live.

What Happens

  1. A confirmation names the person and the build. If that person couldn’t actually sign in (no grant, a switch is off, or no contact record), the dialog says so. Impersonation skips the sign-in check, so it still opens. That way, getting in as someone never misleads you into thinking they can get in.
  2. Select Open and the portal opens in a new tab through a single-use link that expires after 60 seconds. If your browser blocks the tab, allow pop-ups for Statisfy and try again.
  3. The portal shows an amber Viewing as banner with your email while you’re impersonating, so anyone looking at the screen can tell it isn’t an ordinary session. Select Stop on the banner to end the session.
Impersonation from the Preview tab works even when both Access switches are off, so you can check a portal before you let anyone in.

Next Steps