v2.47 includes our new client portal overhaul. This marks a significant change and greatly increases the abilities of the portal user role.
Client portals will be replaced with a free portal user role in the main Hudu app. Existing portal members will be converted automatically. After the change, /portal/... URLs bounce into the main app (that company's page after sign-in), and the curated “In Portal” experience goes away. Portal users sign in to Hudu like everyone else, with a read-only role that is similar to Spectator, but slightly more limited.
There are a number of things you can do ahead of this transition to prepare, outlined below.
What portal users will be able to do
- Access an unlimited number of companies, but only the companies their groups allow.
- Read company records their groups allow (assets, passwords, KB, and other tools you enable on those groups).
- Use Central KB if you allow it on their groups (and Central KB is on for the instance).
- Use My Vault if you allow it on their groups (and My Vault is on for the instance).
- Create client request links if you allow Request on their groups.
- Switch between companies they can access using the company switcher.
- Use the Hudu Assist and Hudu Password Manager browser extensions and the mobile app, if you enable those apps and their groups allow the related records.
- Use Hudini if AI is enabled on your instance and you allow Hudini on their groups.
- Send secure notes if sharing is on for the instance and you allow Share on their groups.
What portal users will not have
These limits are part of the portal user role. Putting them in a more open group does not turn them on.
- Create, edit, archive, or delete records
- Flag records
- Global tab
- Hudu Radar
-
The companies directory (
/c), Companies in the top nav, or a Companies breadcrumb back to that list - Archived companies
- Internal company quick notes, Magic Dash, agreements tile, and activity feed on company home page
- Hudu dashboard (including Home on mobile)
- Integrations sync in the top nav bar
- MCP
Spectator remains a licensed internal role with a broader read-only experience (directory, dashboard, Radar, flagging, and so on). Use portal user for clients who should stay free and more restricted.
What will happen on update to v2.47
- Every portal member will become a portal user, including archived portal members. Archived users will stay archived — they will not be deleted.
- Each active portal member will be added to a group named Previously ungrouped portal users. This will happen once, during the v2.47 migration — not when you invite people later. If you have no portal members, that group is not created. Archived portal members will be converted but will stay archived and will not be in any group.
- That group will start with access to no companies, no asset layouts, and all group Core features off. Until you move them into real groups, those users will sign in and see an empty state — not the old portal pages. After everyone is moved out, you will delete the group; Hudu will not keep using it for new invites.
- Company access will be controlled by groups, not by a single assigned company field.
-
Client portal settings and “add to portal” toggles will be deprecated immediately. Bookmarks to
/portal/...will no longer open the old portal pages — they will send people to that company's page in the main app after they sign in. Until you assign groups, they may still see an empty state. - The Portal Member Export (Admin → Export Data) is removed. Download it in v2.46 if you still need a people inventory.
What you should do now
1. Inventory your current portal members (v2.46 export)
v2.46 includes the ability for Super Admins to download a Portal Member Export from Admin → Export Data. This is a temporary tool to help with portal migration prep. Download it in v2.46 as it will not be supported come v2.47.
How to use it
-
Filter or pivot by
company_name/company_id. That is the company each person can access today, and the starting point for which company their group should allow after v2.47. They will not get that company automatically — you will manage company access via groups. -
Confirm that each portal member in the export should still have access. Filter
archived=truefor people who will stay archived after v2.47. Iflast_loginis Never, decide whether to keep them, reach out, or archive them. Archiving does not skip the v2.47 conversion — they become archived portal users.
2. Inventory what is in portals today (v2.46 export)
v2.46 also includes the ability for Super Admins to download a Portal Record Export from Admin → Export Data. This is a temporary tool for portal migration prep.
The file lists every record currently shared in portals, across the instance — one row per asset, website, password, or article. Folders are not listed; articles inside shared folders (including nested folders) are.
Columns include company name and ID, record type and name, asset layout (assets), folder name (articles), whether the item is pinned, and whether that company’s portal is active.
How to use it
-
Filter or pivot by
company_nameso you can see what each client currently has in their portal. -
Use
record_typeto see what is shared. Useasset_layoutfor assets andfolder_namefor articles (KB folders). Password rows are individual passwords — the export does not include password folder names. Use that inventory to decide which companies, asset layouts, and KB folders a group should allow after v2.47.
3. Prep groups and permissions
Portal users can belong to groups, including your default group, the same way as other roles. They can share groups with technicians or sit in their own groups — use whatever is easiest to maintain.
They are read-only, but they still inherit everything their groups can see. The old portal only showed records you marked “in portal.” The main app does not work that way.
Before v2.47
-
Decide which group(s) each current portal member should join after upgrade. Use the Portal Member Export so each person’s group allows at least the company in
company_name. You will assign those groups after the v2.47 update — not yet. - Review what those groups already allow (companies, asset layouts, password folders, KB folders, Core features). That is what those portal users will be able to read.
- Create new groups for your soon-to-be-migrated portal users as needed.
- Remember: new portal users you invite after v2.47 are not added to a special group. You choose their groups at invite time, just like Spectator or Editor.
v2.46 includes new permissions features you'll want to review and make use of:
- Core feature on/off — Turn tools off for the whole instance (Admin → General) and/or per group (Admin → Groups → Access). Use this if a group that will include portal users should not see passwords, company KB, photos, IPAM, racks, websites, expirations, assets, Central KB, or other Core features. (The portal user role still blocks Global even if they belong to a group with Global turned on.)
- KB folder permissions — Restrict knowledge base folders in both companies and Central KB to specific groups.
4. Give your clients notice on what to expect
Have them update bookmarks and password managers to your normal Hudu login URL. Old /portal/... links will still bounce them there (then to that company's page) after they sign in, but a saved main-app URL is clearer. Tell them to use username and password, not your team’s SSO button.
Portal users are exempt from enforced SSO and Duo; they do not need a separate SSO-exempt group. If you enforce app-based two-factor authentication (TOTP), portal users may still be asked to set that up.
Portal users can also use Hudu’s two browser extensions (Hudu Assist and Hudu Password Manager) and the mobile app, depending on what you enable (Admin → External Apps) and what their groups can see. If you plan to give clients access to any of these, let them know how to access these tools.
Treat them as new Hudu users. They may need assistance learning how to navigate the new platform.
What you should do immediately following the update
The Previously ungrouped portal users group is created only by the v2.47 migration, and only if you had portal members to convert. Only former portal members are placed in it. Hudu will not move people out of it for you. It will also not add new invites to that group.
- Add each migrated portal user to the group(s) you decided on in step 3 of the "What you should do now" section above.
- Remove them from Previously ungrouped portal users. Staying in that group continues to block access — even if they are also in a real group, layouts and Core features stay denied.
- When the group has no members left, delete it. Archived former portal members are not in this group (archived users cannot be in groups). If you unarchive one later, they join the default group, the same way other roles do — then assign the groups you actually want.
- Hint: You can impersonate users to experience Hudu as they would. Select the user in Admin/Users and click the "Impersonate" button in the top right corner. Use this to double check a user's permissions and experience.
Sample client template
Subject: A new link for your documentation
Hi [name],
We are moving the site where you view your documentation. Starting [date], please use this link instead:
[your Hudu URL]
Signing in
- Your email address and password stay the same. There is nothing new to set up.
- Please update your bookmark, and any saved password in your browser or password manager, to the new link.
What is different
- The page will look different, but your documentation is the same.
- Use the search bar at the top to find what you need.
- [If we document more than one company or location for you, you can switch between them by clicking the company name at the top of the left-hand navigation panel.]
- You can read and search everything we share with you. As before, you will not be able to edit or delete anything.
The first time you sign in
- Click your profile picture in the top right, then Edit profile, and check your name, time zone, and photo. You can also switch between a light and dark theme.
- If you sign in and do not see anything yet, that is expected while we finish setting up your access. Let us know if it is still empty after [date].
(Optional — include only if you are giving clients the browser extensions or mobile app)
You can also reach your documentation from your browser or your phone. Let us know if you would like these set up, and we will send instructions:
Please reach out with any questions or if you need assistance.
FAQ
When will this change happen?
Portal users will replace client portals in v2.47. Use v2.46 to download the Portal Member Export (it is removed in v2.47) and the Portal Record Export, set Core feature on/off (instance and per group), set KB folder permissions and prep your groups ahead of time.
Will this use extra licenses?
No. Portal users are free, like today’s portal members.
Can one portal user see more than one company?
Yes, if you put them in groups that allow more than one company. They switch companies with the company switcher, not a full companies list.
Do we have to recreate users?
No. Existing portal members are automatically migrated, including archived ones (they stay archived as portal users, with no group). If you unarchive them later, they are added to the default group like any other role.
Will clients use our SSO?
Usually no. Hudu allows one SSO provider, which is typically for your staff. Portal users are exempt from enforced SSO and Duo. They should sign in with username and password. If you enforce app-based two-factor authentication (TOTP), they may still need to set that up. You cannot configure a separate IdP per client.
Does IP access control apply to portal users?
Admins can currently disable IP access control for portal members in Admin/Security/IP Access Control. This will continue to be true post overhaul. If you already have it disabled for portal members, it will still be disabled for them in v2.47.
Can we keep the old portal?
No. After this release, new portal use is turned off. The old portal UI is gone. Existing /portal/... bookmarks bounce to that company's page in the main app after sign-in.