
Index
Inviting an external person should not grant permanent access by accident. A portal needs to list invitation, purpose, scope and expiration, with revocation available to the authorized person.
How to evaluate this decision
Define which tasks the guest can perform and for how long. Differentiate between the validity of the invitation and the duration of access after acceptance. Authorization must be checked on the server for each relevant operation, not just upon sign-in. Changes to the link or organization need to update access and prevent undue continuity.
Criteria for comparing proposals
- Scope: limit projects, documents or actions available to the guest.
- Deadline: explain the beginning, end and who can renew access.
- Audit: record granting, relevant use and revocation according to the defined policy.
A scenario to discuss with the supplier
Hypothetical example: A consultant accesses documents during a design review. Closing the invitation link after acceptance does not end your session; the authorization rule must also recognize the end of the contracted period.
What to validate upon delivery
Test expired invite, revoked access, and attempt to open a saved URL. Check that the restriction works on APIs and files, in addition to hiding interface options.
Prepare the conversation about the project
Bring Quantum9 external roles, resources and duration policy. Development must connect the invitation experience to effective access control, with clear recovery and renewal.
Development of portals · Map the company's priority