Customer portal
The portal is where your customers sign in to see their own documents, tickets and orders.
Portal access is its own kind of identity
A contact is granted portal access. They do not become a member of your organization, they do not get a role, and they cannot be given one by mistake.
This separation is structural, not a setting
If a customer were a user with a narrow role, they would be one misconfiguration away from your data. As a different kind of identity, the misconfiguration is not available to make.
What a customer sees
Their own documents, their own tickets, their own orders. Not another customer's, not your internal notes, not your costs.
Registration
How somebody gets access is configurable per organization: by invitation only, on request with approval, or open registration. Invitation-only is the right default for most businesses.
Enquiries
A portal enquiry can become a lead or a ticket, so a customer's question arrives where it will be worked rather than in an inbox.
The account page
Customers manage their own details and their contact preferences. Consent withdrawn there is consent withdrawn everywhere, immediately.