Skip to main content

Client Portal Report Access: Secure Link

Learn how report access in the Client Portal now requires a tokenized link for security, how clients can get one, and what's unaffected by this change.

Written by Shannon Lewis

A security update now gates report access in the Client Portal behind secure links. This ensures that only authorized recipients — buyers and agents listed on the inspection — can view reports.

What Changed

Previously, report buttons in the Client Portal worked for anyone who had the inspection's link, even if that link carried no personal access token. This meant a report could be reached by anyone who obtained or guessed a URL.

With this update, report buttons only work when the link includes a valid token tied to an authorized recipient. When someone opens the portal with a plain, non-secure link:

  • Report buttons remain visible but no longer open the report.

  • Hovering over a report button shows the message: "A secure link is required to open this. Request one to have it sent to your email."

  • Clicking a report button launches the Get Full Access experience.

  • An "Unknown user (This view is limited)" banner appears at the top of the portal with a Get Full Access button.

This applies across both the Documents list and Repair Request views, and covers all report versions: web viewer, summary PDF, full PDF, and repair-request report.


How Clients Get a Secure Link

Clients can get a valid secure link in one of two ways:

  1. Via a Spectora email — Any email Spectora has already sent (such as a confirmation or publishing email) contains a secure link baked in. Clicking that link opens the portal with full report access.

  2. Via the request-a-link flow (Get Full Access) — The client clicks "Get Full Access", enters their email address, and completes a reCAPTCHA. If that email matches a recipient on the inspection, Spectora sends them an email with a working secure link.

Important: The email the client enters must match someone the inspection company added to the inspection. If a client's email is not on the inspection, they will not receive a link. The inspector will need to add them first.

Tokens are tied to the person rather than the specific link and do not expire, so once a client has a working secure link, it continues to work.


What's Not Affected

This change only applies to report links. Agreements, invoices, and attachments are not gated and remain accessible as before.


Key Points and Limitations

  • Automations do not currently send secure links. Clients who receive portal links through automations will see limited access and will need to use the Get Full Access flow.

  • This change is enabled on a per-company basis via a feature flag, allowing gradual rollout. Companies without the flag enabled will see the portal behave exactly as it does today.

  • This is a background change — no action is required to enable it for accounts where the flag has been applied.


FAQs

  • Why can't my client open their report?

    • Report access now requires a secure link — a secure URL tied to your email address and role on the inspection.

    • If you're opening the portal from a plain link (one that wasn't sent directly to you by Spectora), the report buttons will appear but won't open the report.

    • To get access, click the Get Full Access button, enter the email address associated with the inspection, and complete the reCAPTCHA.

    • If your email matches a recipient on the inspection, you'll receive an email with a working link.

    • If you don't receive an email, contact your inspector or agent to confirm your email address is on the inspection.

  • How do I get a secure link?

    • You can get a secure link in one of two ways:

      • Check your email from Spectora — Any email Spectora has already sent you (such as your confirmation or report publishing email) contains a secure link. Simply click the link in that email to open the portal with full report access.

      • Request one through the portal — Open the Client Portal, click Get Full Access, enter your email address, and complete the reCAPTCHA. If your email is on the inspection, Spectora will send you an email with a working secure link. Tokens don't expire, so you can use the same link in the future.


If you have any questions or feedback, write into our chat bubble or email support@spectora.com!

<a href="https://spectora.slite.com/api/files/YJ1LwUWEfvlfM6/image.png" target="_blank" rel="nofollow noopener noreferrer">https://spectora.slite.com/api/files/YJ1LwUWEfvlfM6/image.png</a>
Did this answer your question?