How client access works
Your client signs in to their own account. Here is what that means, and what they can and cannot reach.
Your client gets an account on your portal, and only you can give it to them. There is no public sign-up, so the people who can get in are exactly the people you put there.
Why they set a password
Because the alternative is that a link IS the key, and links get forwarded, sit in inboxes for years and end up on shared computers. A password ties the documents to a person rather than to whoever holds a URL. It costs your client about twenty seconds, once.
What they can reach
Their own page, for the work you sent them. On it they can:
- See the documents you asked for.
- Upload their files.
- Sign what you sent to be signed.
- Message you.
- Pay their invoice.
- Download the finished work.
It does not open anyone else's documents, and it does not open your firm's side of Vylan.
A forwarded link is not a way in
Someone who is sent one of your client's links cannot use it. They are asked to sign in, and the account behind that page is not theirs. That is the whole point of the change: the documents belong to a person, not to a URL.
A client who cannot get back in uses the same forgot-password link as anywhere else. You do not have to do anything.
Your own account is different
None of this applies to you. Your firm's side is a real account with a real password, and you should turn on two-factor. See two-factor login.