Skip to content

Permissions

Choose the portal menu, rename features, control exports, and read the client activity log.

5 min read

Two sections of Settings → White-Label decide what a client can do: Features holds the portal menu, the client-facing feature names, and the export switch; Logs records what everyone did afterwards.

Everything in Features applies to the whole portal, not to one client. Brand access and the per-client export switch are the only settings that vary by client, and those live under Clients.

The portal menu

The Features section shows the client sidebar as a live list. Click a row to hide or show it. Four rows carry a lock and cannot be turned off, because a portal without them cannot explain its own numbers: the score, the questions behind it, the brands it is compared against, and the sources the answers cite.

FeatureIn the menuWhat the client gets
DashboardRequiredVisibility overview and trend
PromptsRequiredThe prompts you track and how each performs
ReportsOn by defaultHistorical reports for the brand
CompetitorsRequiredCompetitive comparison
CitationsRequiredWhere the brand is cited, and by which sources
PerceptionOn by defaultHow models describe the brand
PagesOff by defaultPage-level detail, read-only
ResultsOff by defaultWhat the work changed, measured before and after
DocumentsOff by defaultAgent documents you have published for this client

Two shortcuts sit in the header. Required only strips the menu back to the four locked features. Show all turns everything on, Documents included.

Documents is off by default on purpose. A document is written by your team for one client, so nobody should be able to read it before you decide it is ready.

Tip
Add Pages when a client asks which URL to fix, and Results when they are ready to read measured outcomes, including the honest Couldn't measure. Start with the views you already talk about in the service.

Renaming a feature

Client-facing names are edited in the same list. Hover an optional row and click the pencil, or double-click the name of any visible row. Type up to 30 characters, then press Enter to save or Escape to cancel. A renamed optional row is tagged custom and gains a reset icon that puts the default back, and Reset names in the header clears every custom label at once.

Renaming changes the sidebar label and nothing else. The page heading, the URL, the data, exported reports, and your own navigation all keep the standard names.

Data export

Allow data export at the bottom of Features is a single switch that covers both PDF and CSV for the whole portal. It is off unless you turn it on.

Each client also carries Can export data, set when you invite them and changed later in the client drawer. A client needs both: the portal switch and their own. Turn the portal switch off when nobody should download anything, and the client switch off when one client should stay view-only while others export.

What a client cannot do

The portal is read-only, and the limit is enforced by the API rather than by hiding buttons.

ActionClient
Read dashboards, prompts, citations, competitorsYes
Export PDF or CSV, when both switches allow itYes
Edit prompts or audiencesNo
Add or remove competitorsNo
Change brand settings or trackingNo
Start a check or a report runNo
Invite anyoneNo
See the Agent, Traffic, or your Agency workspaceNo

Every configuration control stays in your own account, so a client can explore their data without reaching anything that would change it.

Brand access

A client only ever sees brands granted by their invite: named brands, or one brand group that keeps growing with the group. To change the scope, revoke the record and invite again. Clients covers the invite form and the states in detail.

The activity log

Logs is the portal's audit trail. Only team owners and admins can open it. Clients have no route to it and cannot see their own entries, let alone anyone else's.

CategoryExamples
AuthenticationSign-in, sign-out, failed sign-in, password reset
NavigationPage views inside the portal
ExportsPDF and CSV downloads
AdminClient invites and revocations, brand access, branding and feature changes
SecurityDenied access, rate limits, suspicious activity
SystemEmail delivery, retention cleanup, client health scoring

Each entry carries a timestamp, the actor and their type, the action and category, the target, the IP address, and whether it succeeded. Settings changes also record the old and new value, which the detail view shows side by side.

Quick filters cover security, exports, admin, and failures. Advanced filters adds actor type, category, a date range, and success or failure. Export CSV takes its own date range and category filters, and lets you include or leave out the IP address, user agent, and session ID.

Retention is set below the table: 30, 60, 90, 180, 365, or 730 days, defaulting to 90. Anything older is deleted by the cleanup job.

Warning
Shortening retention deletes the excess on the next cleanup and cannot be undone. Export what you need before you save a shorter period, and treat the CSV as sensitive: it carries client emails and IP addresses.

Common questions

Can different clients see different features?

No. The menu and the names are portal-wide. If two clients genuinely need different feature sets, that needs two teams with two portals.

Do renamed features change reports?

No. Custom names appear in the portal sidebar only. Exports and report content keep the standard names.

How quickly do menu changes reach a client?

The setting saves immediately, but the sidebar reads it at page load. A client already signed in sees the change after a refresh.

Why can a client not see a feature I enabled?

Check in this order: the feature is on under Features, the client has brand access, and their status is Active rather than Revoked. Then have them reload.

Press ? for keyboard shortcuts