Skip to content
Knowledge ERP Docs

API Reference ↗
Sales

Customer Portal

A branded, passwordless self-service portal where customers view quotes, invoices, orders, rentals, loans, and appointments — and accept quotes, request returns, reschedule appointments, request due-date extensions, and keep their own details up to date.

The customer portal is a public, self-service area where your customers can see and act on everything you've shared with them — without an account password and without staff involvement. It pulls together records from across the app (Sales, Appointments, Rentals, and Inventory loans) into one branded view, scoped to the signed-in customer.

Signing in #

The portal is passwordless. A customer enters their email on the sign-in page and receives a one-time magic link that signs them in for the session. Links are single-use and expire after 24 hours.

  • If the email matches an existing customer, they're signed straight in.
  • If it doesn't, the email is still sent — and the customer record is only created after they click through, so a stray address never creates a contact.

Reminder emails (below) embed a magic link, so a customer can jump from an email straight into the relevant record.

Requests are rate-limited. A given address can be sent three sign-in links in a fifteen-minute window, and there is a wider ceiling per origin address. Ask for a fourth and the page says so — that a link has already gone out, to check the spam folder, and roughly how long until another can be requested. The wording is the same whether or not the address belongs to one of your customers, so the form can't be used to find out who your customers are.

Branding #

The portal and its emails are branded to the account, not to Knowledge ERP:

  • The account name and uploaded logo appear on the sign-in page, the dashboard header, and outgoing portal emails. Both live under Account Settings → Branding; the logo is stored once and resized automatically for each surface, and also appears on document PDFs.
  • You can rename your business at any time, under that same Branding section. The new name is used everywhere the moment you save it — portal, booking pages, PDFs, and the sender name and subject line of new emails. Renaming does not change the web address you sign in at, so nothing your customers have bookmarked breaks; ask support if you need the subdomain changed as well. Emails already sent keep the name they were sent under, which is what your customers will see if they go looking in their inbox.
  • The settings your customers see are administrators-only — the business name, the logo, the timezone your booking page publishes, and the support email in the footer. Anyone with the manage settings permission can still open the page and edit the welcome message; see Who can change what.
  • The subject line and the sender name are yours. A customer sees "Invoice INV-0020 from Tallgrass Outfitters" from Tallgrass Outfitters, not from us — which is what decides whether they open it at all. The same applies to quotes, purchase orders, statements, appointment and booking emails, survey invitations and automation emails. Replies go to your portal support address when you've set one.
  • The underlying sending address stays ours (no-reply@ on our domain). Sending from your own domain would mean verifying it with our mail provider and would tie your deliverability to every other account's, so we send under our verified, monitored domain with your name on it. Some mail clients show this as "Tallgrass Outfitters via …" the first time; nothing else changes.
  • A per-location support phone and an account welcome message / support email tell customers how to reach you.
  • Every page carries your contact details. The account's portal support email and the location's support phone and address appear in the footer of every portal page, every survey page and the public booking pages — so a customer with a question about an order always has somewhere to put it. Fill these in under Account Settings → Customer Portal and Location → Appointments; the block is hidden entirely when none of them are set.
  • No route to the staff sign-in. Nothing a customer can reach links to the Knowledge ERP login. If a customer hits an error — a magic link already used, a survey already answered, a form left open too long — the page is branded as your business and points back at your portal, not at our sign-up.

In production each account's portal lives on its own subdomain.

The dashboard #

After signing in, the customer lands on a tabbed dashboard. A tab shows only when your subscription includes the related module — Sales for quotes, invoices and orders, Appointments for appointments and pre-visit forms, Rentals for rentals, and Inventory for loans. A customer's records in a module you do not subscribe to are not listed, including records imported from another system. Clicking a tab updates the URL (?tab=…) without a reload, so links and the back button behave naturally.

A customer only ever sees their own records; the session is scoped to the linked customer.

Drafts are never shown. A Draft quote, invoice, or sales order has not been sent yet, so it is not visible in the portal — and for quotes and invoices the PDF is refused even over a direct link, so the list and the document itself always agree. A quote that has been Converted to a sales order is likewise hidden, since the order supersedes it. Terminal-but-already-sent records stay visible: a Declined or Expired quote, a Voided invoice, and a Cancelled order are all more useful to a customer shown than silently withdrawn.

Quotes #

Customers see their quotes with line items, total, and expiry. Each quote can be viewed as a PDF in the browser or downloaded, and a Sent quote can be accepted or declined in one click. The Quotes tab badges quotes awaiting a response.

Invoices #

Invoices list with invoice date, due date, invoice total, and balance due, each with view/download PDF. The tab opens with the customer's total balance due, and flags how much of it is overdue — so they do not have to add their own invoices up.

Each row's status is written for the customer rather than for you: Unpaid, Partly paid, Overdue, Paid, or Cancelled. It is worked out from the balance and the due date at the moment the page loads, so an invoice becomes Overdue on the day it passes its due date whatever the internal status says.

When an online payment gateway is connected, a customer can pay an open invoice from the portal. When one is not, the balance panel tells them to contact you instead of leaving them with a figure and no next step. The Invoices tab badges any Sent or Partially Paid invoices.

Orders #

Sales orders show both their status and their delivery status. Once any of an order has gone out — Partially Shipped, Shipped or Delivered — the customer can request a return — choosing items and quantities (capped at what shipped), a reason, and a note. That opens a Submitted return for your staff to process; see Customer Returns.

Rentals & Loans #

Rental agreements and loan agreements are clickable to a detail page showing the return/due date and the items in the agreement (rentals also show the rate breakdown, total, and a link to the invoice PDF). From there a customer can request a due-date extension (see below). A row is flagged Extension requested while one is pending.

Appointments #

Each appointment opens to a detail page with the location's address and support phone, the requested equipment, and status-aware actions:

  • Pending appointments can be cancelled, have their details edited (contact info, notes, and — when the type allows equipment selection — the requested equipment, re-held against on-hand stock), and be rescheduled directly to any open slot (validated against the same availability rules as the public booking flow).
  • Confirmed appointments can be cancelled, and a reschedule becomes a request for staff to approve — or applies immediately when the location opts into auto-approval. Cancelling can notify the location's cancellation-notice email, and so does a move that goes through: a customer moving their own appointment used to change your diary with nothing to tell you. The customer gets a fresh confirmation with a calendar entry that replaces the old one.
  • Every time on the page names the clock it is on — the appointment itself, the slots offered when rescheduling, and a request waiting on you.
  • Completed appointments show the records they produced — the related sales order, rental, loan, or return.

Pre-visit forms #

Outstanding pre-visit forms tied to the customer's appointments are listed for completion.

Your details #

When you let customers see any of their details, the dashboard header has a Your details link. It opens a page showing the customer's own record, as far as your settings allow:

  • Built-in details — name, company, email, phone, website and the two addresses — follow the Customer details settings. A detail the customer can see but not edit is shown as text; one they can edit is a box they can type in; one that is off is not on the page.
  • Custom fields on customers follow each field's Customer can see, Customer can edit and Required from the customer settings (see Custom Fields). User fields are never shown.

The link and the page are not there when nothing is turned on.

Saving applies straight away. There is no approval step. A detail that is Required from the customer can't be saved blank — for Name that means the first and last name, and for an address its first line and city. A customer can't leave their record with neither a first name nor a company name.

Every change is in the record's change history, with the customer as the person who made it.

Changing an email address #

Customers sign in to the portal with their email address, so a new one has to be confirmed before it is used. When Customer can edit is on for Email:

  1. The customer enters the new address and asks for a confirmation link.
  2. The link is sent to the new address. Their current address is told that a change was asked for.
  3. Nothing changes until the link is opened and Confirm email address is pressed. Until then the customer keeps signing in with their current address.

The link works once and expires after 24 hours. Asking again replaces the previous request, and the customer can cancel a request from the page. Sign-in links already sent to the customer stop working once the change is confirmed.

The portal checks that none of your other customers has the address, including deleted ones, when the change is asked for and again when it is confirmed — the portal could not tell two customers with one address apart at sign-in. If one does when the change is asked for, the page looks the same to the customer and the new address is sent a note that it is already on another record, with no link. If one does by the time the link is used, the link is refused.

A link is also refused if the customer's email was changed after they asked — for example, by your staff — or if you have since turned off Customer can edit for Email.

How many can be asked for. Each customer can ask for three changes in a quarter of an hour, and your customers together for 50 in an hour, counted from the first one they ask for. The hour then starts again at the next request, so around the turn of one you may see more than 50 close together. A customer refused by the second limit is told that your business cannot send any more confirmation links just now, and when to try again — it does not use up any of their own three, and it says nothing about your other customers.

Due-date reminders & extensions #

Both rentals and loans support automatic due-date reminder emails and customer-requested extensions:

  • Reminders. When a rental or loan is within its location's reminder window, the borrower is emailed once — with the equipment list and a magic-link button into the portal. Each agreement is reminded only once per due date (the marker resets if the due date is extended).
  • Extensions. From the agreement's detail page the customer picks a length:
    • Loans: 1, 2, 4, 8, or 16 weeks.
    • Rentals: 1 or 2 weeks, or 1 month — with a live estimated additional cost for the chosen length. Extending a rental only moves the return date; the extra rental is billed through the normal cycle/return billing, so no separate invoice is created at extension time.
  • Approval. By default an extension waits for staff approval (each module has an Extension Requests queue with a pending-count badge). With the location's auto-approve toggle on, it's applied immediately. A customer can withdraw a pending request, and approving/declining emails them the outcome.

Configuration #

Portal behavior is configured per account and per location:

Setting Where Effect
Business name, logo Account Settings → Branding (administrators only) Portal + booking pages + email sender and subject + PDFs
Welcome message Account Settings → Customer Portal Sign-in page
Support email Account Settings → Customer Portal (administrators only) Sign-in page + footer of every public page
Customer details Account Settings → Customer Portal (administrators only) What the customer sees and can change on Your details
Support phone Location → Appointments Appointment details
Cancellation-notice email Location → Appointments Notified on portal cancellations
Auto-approve confirmed reschedules Location → Appointments Apply reschedules immediately
Default quote validity (days) Location → Sales Pre-fills a new quote's "Valid Until"
Loan reminder days / auto-approve extensions Location → Loans & Checkouts Reminder lead time + extension approval
Rental reminder days / auto-approve extensions Location → Rentals Reminder lead time + extension approval

The Sales and Rentals cards appear on the location form only for plans that include those modules; Appointments and Loans are always there.

Customer details #

Under Account Settings → Customer Portal → Customer details, each of a customer's own details has three switches:

  • Customer can see
  • Customer can edit — needs Customer can see
  • Required from the customer — needs Customer can edit

The details are Name (first, middle and last together), Company, Email, Phone, Website, Billing address and Shipping address. Notes, payment terms, price list and the customer number are not offered.

Every switch starts off. Turning a switch off also turns off the ones that need it. Only administrators can change these.

The portal's Your details page follows these settings. The pre-visit form does not use them yet.

Security & audit #

Magic-link tokens are validated and consumed on use, and the session is limited to the linked customer's data. Every portal change — cancel, reschedule, edit, return request, extension request, quote decision, a change to the customer's own details — is recorded in the change history attributed to the customer who made it. Reminder emails are sent by the scheduled loans:send-due-reminders and rentals:send-due-reminders commands.