Glossary

Cbusiness

Client portal

A signed-in site where a named client uploads and downloads files across many jobs, instead of receiving a new link each time.

The credential is the account. The files sit in folders or tickets scoped to that account. NIST SP 800-53 AC-3 is the control: the server allows the approved identity and denies everyone else. A portal that works logged out is a public link with a logo.

The difference from an expiring link is lifetime and identity. A link dies on a clock and can be forwarded. A portal account survives until someone disables it, and a forward of the URL hits a login. The difference from managed file transfer is who acts. A portal waits for a person. An MFT job runs on a schedule with no one at the keyboard. Teams use both: the portal for the messy human exchanges, the job for the nightly file that must exist by 02:00.

Worked example

An agency gives Northwind an account. In March the client uploads a 6 GB brief through a file request inside the portal. In April they download three cuts, each logged against the user, not against a one-time URL. When the contract ends, disabling the account stops the next login. It does not delete cuts already saved on the client's laptops. A vendor who instead emailed twelve separate links has no single switch, and the access log is a pile of anonymous URL hits. The portal costs a password reset flow and a session timeout. The links cost a trail of who-has-this guesses.

A portal is not a protocol. Under the session you still have HTTPS, object storage, and a size cap. The useful test is whether you can name the human, revoke them, and list their transfers without hoping they still have the email.

Related

Sources

  1. NIST SP 800-53 Rev. 5, AC-3 Access Enforcement

    Standing access is a rule on an identity, not a URL secret

  2. RFC 9110, HTTP Semantics

    The browser session that carries portal uploads and downloads