What partners can see — and what they never can
Show this article to a client who asks what the portal exposes — it is the whole contract, and none of it depends on a hidden button. A partner's session is scoped in the database: fields they must not see are not merely hidden from the screen, they are not in the data the portal is allowed to read.
| Partners see | Partners never see |
|---|---|
| Project status, timeline & progress | Rates, costs, margins, budgets |
| Phases, tasks & milestones | Time entries — not even totals |
| Documents you explicitly share | Internal notes & unshared documents |
| The co-managed comment thread | Internal comments |
| People on their shared projects | Your staff roster |
| Their own shared projects | Any other client's data |
The screens a partner actually gets
The portal is two screens. There is no navigation to anything else — no CRM, no reports, no settings, no search across your workspace.
- +Your projects — a card per shared project with a progress ring, the status, and the due date. If nothing has been shared yet, they see an empty state ("No projects shared yet"), not an error.
- +The project — overall progress, a task breakdown (done / in progress / upcoming), a milestone timeline, the work plan grouped by phase, any shared documents, and the conversation. The project header carries a Read-only marker, and the portal is read-only throughout: the one thing a partner can write is a comment.
Open a project they are not a member of — an old link, a forwarded URL — and they get "This project isn't available". There is no all-projects view for a partner: no membership, no project.
Field by field, what reaches the portal
| Record | What a partner gets | What is stripped |
|---|---|---|
| Project | Name, status, progress, due date | Budget, billable rate, contract, health score, PSA identifiers, project mode |
| Phase | Name and order | Everything else |
| Task | Name, state, progress, start/end dates, milestone flag — and a partner-facing task's description is included in the partner-safe data (it is blanked out on every other task), though today's portal screens show only task names and status | Assignee, estimated and logged hours, billable flag, contract, priority, internal notes — and the description on every task not flagged partner-facing |
| Document | Only documents explicitly marked shared with partners | Everything else — documents are not shared by default |
| Comment | Only comments marked visible to co-managing users, with the author's name | Internal comments, mentions, and message identifiers |
| Time entry | Nothing at all | The whole record — hours, rate, billing code, notes, and totals |
What you control, per item
Three things are opt-in, and all three default to closed:
- +Documents. A document reaches the portal only when it has been explicitly marked shared with partners. New documents are private to your team until someone makes that call. See "How SharePoint folders and documents work in projects".
- +Comments. When your team posts on a project, the composer carries a "Visible to co-managing users" checkbox. Off (the default) means internal only — the partner never sees it, and it posts private in your PSA. On means it appears in the portal thread and publishes co-managed. Every comment is tagged in the staff view (Partner-visible or Internal) so you always know who can read it.
- +Task descriptions. A task's description only reaches the partner-safe data when that task is flagged partner-facing; on every other task the description is blanked out before it ever leaves the database. The flag is an Autotask-owned field — Current shows it read-only in the task drawer, under Classification, as "Partner facing?". ConnectWise-synced projects have no equivalent field yet, so descriptions there stay internal.
Partners can only ever post co-managed. Their reply is forced partner-visible, so a client can never accidentally write something into your internal thread — and your team sees it in the project conversation, and in the mapped Teams channel if you use one.
The things people assume are visible, and aren't
- +Your full staff roster. A partner can't browse your people — they only ever reach the people who are members of a project shared with them, and in the portal they see just the names on conversation posts.
- +Other partners. A partner can't browse a directory of portal users. They can only ever reach people who share a project with them — never anyone at another client, and never your wider user list.
- +Other clients. Cross-client visibility is impossible: workspace and project scoping are both enforced in the database.
- +Anything in the CRM. Companies, deals, pipeline, campaigns, sequences, business reviews — a partner role is blocked outright.
- +Task detail. Assignees, hours, priorities, and internal notes never leave your side, even on a project they can see.
The right-hand column of that first table isn't a preference — it's enforced three times over, at the data layer, and verified with real partner sessions rather than by clicking around the app. "The partner financial firewall" explains how, and "Roles & permissions: who sees what" puts the partner role next to every other role in one table.
