Skip to content
Solutions / GA Applications

Solution / Controlled access

Give each person a focused window into the work they are allowed to see and do.

A portal provides a secure, role-specific place for customers, staff or partners to exchange information, complete actions and review approved status. GA Applications defines the identity, permissions, records and support model first, then designs a clear responsive experience connected to the appropriate operating systems.

Problemone recurring constraint
Flowpeople, records and hand-offs
Outcomeobservable working change
Why it matters

Customer workspace

Show approved requests, milestones, documents and actions relevant to that relationship.

CHAPTER 01

Design separate journeys around real responsibilities.

Customers, field staff, coordinators and partners should not receive the same navigation or information by default.

01.1

Customer workspace

Show approved requests, milestones, documents and actions relevant to that relationship.

01.2

Staff workspace

Prioritise assigned work, required evidence and exceptions for the role.

01.3

Partner access

Limit shared records by organisation, project, time and purpose.

CHAPTER 02

Make identity, permissions and sensitive actions explicit.

Authentication is only one part of portal security; record-level access, session behaviour and recovery paths also require design.

02.1

Access model

Map roles to allowed records and actions, including temporary and delegated access.

02.2

High-risk actions

Require suitable re-authentication or approval for consequential changes.

02.3

Audit trail

Record important views, submissions and permission changes in proportion to risk.

CHAPTER 03

Support people when self-service is not enough.

The portal must explain status, validation and recovery clearly and provide a visible human support route.

03.1

Plain status

Use language that explains what happened, what is waiting and who acts next.

03.2

Safe upload

Set file rules, scanning, retention and visibility before requesting documents.

03.3

Assisted path

Let a user contact the team with the relevant record context when blocked.

Questions worth resolving

What to clarify before committing.

Can a portal connect to our current CRM or job system?
Yes when the source system provides suitable access. The portal should expose only approved data and actions through a documented integration boundary.
Do customers need a password?
The identity method depends on risk and frequency. Options can include managed accounts, federated sign-in or time-limited links for narrowly scoped low-risk actions.
Can the portal work on mobile?
Yes. Responsive design, touch targets, readable forms and recovery from interrupted connections should be part of the acceptance criteria.

Bring the real problem

Define one audience and one complete portal task.

Show us who needs access, what they must complete and which system owns the result. We can shape a secure first release.