Customer Portal Requirements Checklist

Use this checklist before vendor demos or development estimates. It is designed to expose missing workflow, ownership, security, and exit requirements—not just collect features.

Download the CSV checklist

How to use it: mark each requirement Must, Should, Could, or Not needed. Assign an owner, ask vendors to demonstrate the requirement with your scenario, and record the evidence. A “yes” in a sales sheet is not the same as a tested workflow.

Users and access

  • Define every external user type and the organization or account each belongs to.
  • Define roles for account owners, billing admins, contributors, viewers, and auditors.
  • Require tenant isolation so one customer can never access another customer’s data.
  • Decide whether customers need SSO, MFA, passkeys, or passwordless login.
  • Document invitation, offboarding, account recovery, and delegated administration flows.

Customer workflows

  • Choose the first three customer tasks the portal must complete end to end.
  • Define status labels and the source system that owns each status.
  • Include exception, cancellation, correction, and escalation paths.
  • Specify notifications, recipients, channels, and retry behavior.
  • Define the mobile and accessibility requirements for each critical task.

Data and integrations

  • Name the system of record for contacts, orders, invoices, files, tickets, and identity.
  • Verify read and write API coverage for every required field and action.
  • Document synchronization frequency, conflict handling, and failure recovery.
  • Verify API authentication, tenant scoping, pagination, rate limits, and versioning.
  • Require webhook signatures, retries, idempotency, and delivery logs.

Security and compliance

  • Classify the data shown, uploaded, exported, and stored in the portal.
  • Require encryption in transit and at rest with documented key management.
  • Log authentication, exports, sensitive access, permission changes, and admin actions.
  • Define retention, deletion, backup restoration, and incident-response requirements.
  • Verify required contracts and evidence such as a DPA, BAA, SOC 2 report, or penetration test.

Experience and operations

  • Test search, empty states, errors, loading states, and support escalation.
  • Define branding scope across domain, email, login, files, notifications, and mobile.
  • Assign owners for content, permissions, integrations, support, and release approval.
  • Set service-level objectives for availability, support response, and data freshness.
  • Plan a pilot, migration, customer communication, training, and rollback path.

Commercial evaluation

  • Record whether pricing is per internal user, customer, active user, usage, tier, or quote.
  • Model growth in users, storage, transactions, integrations, support, and environments.
  • Include implementation, migration, training, security review, and ongoing administration.
  • Verify export formats, API access, termination support, and data deletion after exit.
  • Compare a three-year total-cost model using the same assumptions for every option.

Turn requirements into a decision

  1. Reject any option that fails a Must requirement.
  2. Score only requirements that distinguish the remaining options.
  3. Run the same end-to-end scenario in every demo.
  4. Verify security, API, and exit claims with written evidence.
  5. Choose a pilot with measurable completion, adoption, support, and data-quality targets.

Continue with the build-versus-buy guide, the portal pricing model, and the secure portal checklist.