How to use it: mark each requirement Must, Should, Could, or Not needed. Assign an owner, ask vendors to demonstrate the requirement with your scenario, and record the evidence. A “yes” in a sales sheet is not the same as a tested workflow.
Users and access
- Define every external user type and the organization or account each belongs to.
- Define roles for account owners, billing admins, contributors, viewers, and auditors.
- Require tenant isolation so one customer can never access another customer’s data.
- Decide whether customers need SSO, MFA, passkeys, or passwordless login.
- Document invitation, offboarding, account recovery, and delegated administration flows.
Customer workflows
- Choose the first three customer tasks the portal must complete end to end.
- Define status labels and the source system that owns each status.
- Include exception, cancellation, correction, and escalation paths.
- Specify notifications, recipients, channels, and retry behavior.
- Define the mobile and accessibility requirements for each critical task.
Data and integrations
- Name the system of record for contacts, orders, invoices, files, tickets, and identity.
- Verify read and write API coverage for every required field and action.
- Document synchronization frequency, conflict handling, and failure recovery.
- Verify API authentication, tenant scoping, pagination, rate limits, and versioning.
- Require webhook signatures, retries, idempotency, and delivery logs.
Security and compliance
- Classify the data shown, uploaded, exported, and stored in the portal.
- Require encryption in transit and at rest with documented key management.
- Log authentication, exports, sensitive access, permission changes, and admin actions.
- Define retention, deletion, backup restoration, and incident-response requirements.
- Verify required contracts and evidence such as a DPA, BAA, SOC 2 report, or penetration test.
Experience and operations
- Test search, empty states, errors, loading states, and support escalation.
- Define branding scope across domain, email, login, files, notifications, and mobile.
- Assign owners for content, permissions, integrations, support, and release approval.
- Set service-level objectives for availability, support response, and data freshness.
- Plan a pilot, migration, customer communication, training, and rollback path.
Commercial evaluation
- Record whether pricing is per internal user, customer, active user, usage, tier, or quote.
- Model growth in users, storage, transactions, integrations, support, and environments.
- Include implementation, migration, training, security review, and ongoing administration.
- Verify export formats, API access, termination support, and data deletion after exit.
- Compare a three-year total-cost model using the same assumptions for every option.
Turn requirements into a decision
- Reject any option that fails a Must requirement.
- Score only requirements that distinguish the remaining options.
- Run the same end-to-end scenario in every demo.
- Verify security, API, and exit claims with written evidence.
- Choose a pilot with measurable completion, adoption, support, and data-quality targets.
Continue with the build-versus-buy guide, the portal pricing model, and the secure portal checklist.