Give contacts a sign-in page where they can view and reply to their support tickets
A private ticket view for your customers, fed by the same Inbox your agents work.
The customer portal is a signed-in page where a contact sees their own support tickets: status, priority, your public replies, and attachments. They can reply from the portal, and replying to a resolved ticket reopens it automatically, so a customer is never stuck emailing a closed thread. Internal notes never appear in the portal, only the replies your team sends publicly.
Send a portal link from the contact's record.
Go to People, open the contact, and switch to the Related tab. The Customer portalcard sits with the contact’s tickets. You need the ticket edit permission to see it, and the contact needs an email address on file.
Click Invite to portaland confirm. The contact receives an email with a personal sign-in link that stays valid for 30 days. The link is theirs alone: it is never shown in the app, so it cannot leak from an agent’s screen.
Resend linkissues a fresh link and quietly retires the previous one, so there is only ever one live link per contact. Resends are briefly throttled to protect the customer’s mailbox from accidental double-sends.
Customers can also sign themselves in, no invite required.
A contact who already exists in your CRM can reach the portal without waiting for an invite. On the portal sign-in page they enter their email address and receive a 6-digit code that is valid for 5 minutes. Entering the code starts a normal 30-day portal session. The code is single-use and locks after a few wrong guesses, and the sign-in page answers the same way whether or not an address is recognized, so it cannot be used to probe which of your contacts exist.
Choose how much of their company's ticket history a contact can see.
By default a contact sees only their own tickets. For a champion or account admin at a customer company, you can widen that from the same Customer portal card once an invite exists, using the What they can see selector:
The scope belongs to the contact, not to a particular link: it survives resends and fresh code sign-ins until your team changes it. Company visibility follows the company on the contact’s CRM record, so keeping that association current is what keeps the portal view correct.
Cut off a contact's portal access immediately.
Revoke accesson the Customer portal card deletes the contact’s portal credential and invalidates any sign-in codes they requested but have not used. Every portal link they received stops working immediately. Revoking is the right move when a contact leaves the customer company or an inbox may be compromised. It is not a permanent ban: the contact can sign in again later with an email code, which starts them back at the default own-tickets scope.
Tickets filed by an unverified address are held until the sender confirms.
When someone files a request through your public Help Center form, they may type any email address. Until that address is confirmed, the ticket is created in a pending verification state: the sender gets a confirmation email with a link that is valid for 7 days, and clicking it marks the request as genuine.