The producer portal =================== The **producer portal** is a separate, self-service area of the platform where a producer can see their own standing — credentials, compliance issues, finalized commission statements, contracts and book of business — without a staff account. It lives at ``/portal``, is strictly read-mostly, and is completely walled off from the staff application: a portal account can never reach staff screens, and staff accounts can never enter the portal. This chapter covers both sides: how your staff grant and manage portal access, and what the producer sees. Granting portal access (staff) ------------------------------ Portal access is granted per producer from the **Portal access** card on the producer's detail page (:doc:`producers`): #. Click **Grant access…**. The dialog asks for the **Sign-in email** (pre-filled from the producer record — change it if the producer signs in with a different address). #. Confirm with **Grant access**. The producer immediately receives a one-time sign-in link by email — *"the portal has no passwords"*. The card then shows **Signs in as** (the email) and **Last sign-in**. Two more actions are available: * **Send sign-in link** — email a fresh link at any time (granting again later just sends a fresh link; it never duplicates the account). * **Revoke…** — deactivates the portal account **and ends any live session immediately**. The card shows a *revoked* pill; access can be restored later with **Re-grant access…**. Granting and revoking are **manager-only** operations. Two guards protect the identity mapping: the sign-in email may not belong to a staff member of your tenant, and not to another producer — one portal account maps to exactly one producer. .. tip:: Portal access can also be provisioned in the same step as approving an onboarding application (an option on the approval API), so a newly approved producer starts with their portal ready. Signing in — magic links, no passwords -------------------------------------- The portal has **no passwords**. The producer: #. Opens ``/portal/login`` (*"Producer portal — we email you a sign-in link, no password needed."*), enters their **Email** and clicks **Email me a sign-in link**. The page always answers *"If that address has portal access, a sign-in link is on its way"* — it never reveals whether an address is known. #. Clicks the link in the email (*"Your producer portal sign-in link"*). The link **expires after 30 minutes and works once**; signing in invalidates any other outstanding links. #. Lands on the portal overview. An expired or reused link shows *"This sign-in link is invalid or has expired."* with a **Request a fresh link** shortcut. A producer who works with several carriers on the platform gets a **Carrier** switcher in the portal's top bar; everything shown applies to the selected carrier only. What the producer sees ---------------------- The portal has six surfaces — **Overview**, **Compliance**, **Commissions**, **What-if**, **Contracts**, **Book**: Overview *"Your standing, credentials and paperwork at a glance."* A standing banner — green *"You're in good standing — licensed, E&O current, and clear for commission payouts."* or red *"Commission payments are on hold."* with the exact reasons and the note that payouts resume automatically once resolved (see :ref:`payability `). Four KPI tiles: **Open alerts**, **Expiring in 30 days**, **Already lapsed**, **Awaiting your signature**. The profile card is read-only — *"profile changes go through your carrier"*. Compliance Read-only tabs for **Licenses**, **E&O**, **Appointments** and **Alerts**, each row with a health pill (*current* / *expiring soon* / *expired*). Producers see their issues; triage remains a staff activity (:doc:`compliance`). If producer notifications are enabled (:doc:`tenant-administration`), the producer is also emailed a daily *"Action needed"* digest of the compliance items they can act on themselves. Commissions *"Your finalized statements — open one to drill into lines or raise a question."* Only **finalized** statements appear — drafts are staff work-in-progress. Opening one shows the total and every line. The producer can click **Question** on a line, or **Question this statement**, describe the problem, and **Send** — this raises a statement **dispute** that your managers are notified about and work from the statement drawer (:doc:`commissions`). The portal's *Your questions* card tracks each dispute's status and shows the carrier's written resolution. When the producer has incentive awards (:doc:`performance`), this screen also shows an **Incentive awards** card: their year-to-date awards summarised by program, with a base-currency total. What-if *"See what your commission would look like at a different blended rate."* The producer enters a **proposed rate** and the portal projects it **over their own book only**: the commission actually paid to date (**baseline**) versus their written premium at the proposed rate (**projected**), and the **difference**. It is an estimate — nothing is saved, and nothing is shared with the carrier. This is the producer-scoped counterpart to the staff *what-if scenarios* (:doc:`commissions`), which model rate changes tenant-wide. Contracts The producer's agreements, with a banner when any are *"waiting for your signature"*. A **Review & sign** button opens the public signing page for contracts that have been sent (:doc:`contracts`). Drafts and voided contracts are never shown. Book *"Policies attributed to you, and the producers in your downline"* — the producer's ingested policies (paged) and their downline tree. For an upline, this screen also shows an **override earned (year to date)** summary: the override commission they earned across their downline for the year so far, per currency — the producer's own view of the staff **Roll-up** (:doc:`commissions`). How access is enforced ---------------------- A portal account is a normal platform user whose membership in your tenant carries the **producer** role, pinned to exactly one producer record. Everything the portal serves is filtered to that producer on the server — the mapping is never taken from the browser — on top of the tenant-level row isolation (:doc:`tenant-administration`). Portal users are excluded from every staff API and screen, and there is no administrator bypass into the portal.