Browse help topics

What your client sees when they authorize you

In this article: The consent page, what it commits them to, and the record it leaves behind.

You'll be asked what the email is and what they're agreeing to. Here's the honest answer, which is worth being able to give quickly.

The email

Says your agency has asked to manage compliance for their company, and carries one link. No account needed to open it.

The page

Names your agency, sets out what authorizing allows, and has a box to tick and a button to grant. They can also decline.

What they're agreeing to

That your agency may work inside their organization — see their contractors, their certificates and licences, request documents on their behalf, and run reports.

It is not a transfer of ownership. It's their data, in their organization; you're granted access to it.

What gets recorded

Consent is an audit record, not a checkbox: the email address that granted it, the IP address it came from, the version of the agreement they saw, and the timestamp. It's in the activity log afterwards, on both sides.

That record is what makes the arrangement defensible later — which matters most in exactly the situation where nobody wants to be reconstructing who agreed to what.

Withdrawing

A client can withdraw at any time. Your access stops immediately: the organization stays in your portfolio, listed, with nothing readable in it.

The original consent record is never reopened or edited. If they want to re-authorize, that creates a new record — so the history of who agreed to which version, and when, stays intact.

Note

If a client moves to a different agency, their consent to you is closed out and they start the handshake again with the new one. Consent never survives a change of agency.

Related articles

Didn't find what you were looking for?

Send us the question — a person answers, usually the same working day.

Contact support