Skip to content
Scattered spreadsheets, messages, email and folders converging into one orderly portal interface

Before a Client Portal, Audit the Work It Replaces

Avidni Editorial Team / Portals8 min read.

A workflow audit for teams considering a client portal, beginning with the spreadsheets, WhatsApp threads, email approvals, files and exceptions the new system must responsibly replace.

The feature list is usually the wrong place to start

'We need a dashboard' sounds decisive, but it often describes the screen rather than the work. The real problem may be that a client sends details on WhatsApp, a coordinator copies them into a spreadsheet, a manager approves by email, files live in several drives, and nobody can tell the client what changed without asking three colleagues. A portal should remove that ambiguity. If it merely adds a login above the same ambiguity, it has become another place to check.

Run a one-week workflow inventory

Choose one representative process and follow real work from request to completion. Record every handoff, tool, decision, wait, correction and exception. Do not tidy the story for the workshop. The duplicated spreadsheet and the voice note that saves the day are exactly the evidence the portal needs.

A practical workflow audit template
PromptWhat to recordWhy it matters
TriggerWho starts the work, through which channel and with what minimum informationDefines intake and validation
Authoritative recordWhere the accepted facts live after conflicts are resolvedPrevents competing sources of truth
RolesWho may view, create, edit, approve, download, assign or deleteShapes permissions and auditability
StatesThe meaningful stages from new to complete, cancelled or archivedGives clients and staff a shared language
HandoffsWhat moves between people or systems and how receipt is confirmedExposes delays and notification needs
ExceptionsMissing data, rejected work, duplicates, timeouts and disputed decisionsPrevents a happy-path-only build
EvidenceFiles, notes, approvals, timestamps and messages needed laterDefines history, retention and reporting
CompletionWho decides the work is done and what the client receivesCreates acceptance and closure

Choose one source of truth for each fact

A portal does not need to own every record, but the architecture must know which system does. Client identity might belong to a CRM. Payment status might belong to a payment provider and a finance ledger. Project tasks might belong to an operations system. The portal can present and coordinate those facts without becoming an uncontrolled duplicate database.

Permissions are business rules

Do not stop at administrator, staff and client. Ask whether one client may see several organisations, whether an organisation has billing and operational contacts, whether a staff member can reassign work, whether a reviewer can approve without editing, and whether former users retain access to exported files. Enforce those rules on the server. Hiding a button in the browser is not access control.

The OWASP Application Security Verification Standard can help procurement and technical teams turn security expectations into testable requirements. For personal data, the Office of the Data Protection Commissioner guidance is the appropriate Kenyan starting point for consent, impact assessment and sector-specific questions.

Design the exception queue before the celebration screen

Every workflow has cases that do not fit. A document is unreadable. A client submits twice. An approval expires. An external service is unavailable. A staff member leaves with assigned work. The portal needs a named state, owner, explanation and recovery action for each material exception. Otherwise the team returns to private messages, and the clean dashboard becomes a decorative summary of incomplete records.

A sensible first release

  1. One well-defined workflow with a clear owner and measurable delay or error problem.
  2. Role-aware sign-in and server-enforced access to the right records.
  3. Validated intake with draft, submission and correction states.
  4. A shared status model for clients and staff.
  5. Files with type, size, access and retention rules.
  6. Notifications that point back to the record instead of becoming the record.
  7. An activity history and an exception queue for staff.
  8. A handover and support plan for the people who will operate it.

Signs you are not ready to build

Pause if nobody can name the process owner, the team disagrees about the real stages, the data has no agreed source, the business expects the portal to fix an unresolved policy, or every exception is described as 'we will handle that manually' without saying who and how. A short audit is cheaper than encoding a disagreement into software.

A Web App or Client Portal should make the work more visible, controlled and supportable than the channels it replaces. That outcome begins with observation, not a dashboard template.

Map a Portal Workflow

Build the website or system your next stage needs.

Strategy, Delivery and Ownership in one accountable process.

Bring the brief, the challenge or simply the outcome you need. Avidni will shape it into a clear delivery plan for a business website, e-commerce store, client portal or automated workflow. You will know what is being built, who owns each decision and what happens after launch, with ongoing care available where it adds real value.

Start a Project