You'll be asked what the email is and what they're agreeing to. Here's the honest answer, which is worth being able to give quickly.
The email
Says your agency has asked to manage compliance for their company, and carries one link. No account needed to open it.
The page
Names your agency, sets out what authorizing allows, and has a box to tick and a button to grant. They can also decline.
What they're agreeing to
That your agency may work inside their organization — see their contractors, their certificates and licences, request documents on their behalf, and run reports.
It is not a transfer of ownership. It's their data, in their organization; you're granted access to it.
What gets recorded
Consent is an audit record, not a checkbox: the email address that granted it, the IP address it came from, the version of the agreement they saw, and the timestamp. It's in the activity log afterwards, on both sides.
That record is what makes the arrangement defensible later — which matters most in exactly the situation where nobody wants to be reconstructing who agreed to what.
Withdrawing
A client can withdraw at any time. Your access stops immediately: the organization stays in your portfolio, listed, with nothing readable in it.
The original consent record is never reopened or edited. If they want to re-authorize, that creates a new record — so the history of who agreed to which version, and when, stays intact.
Note