Documentation

Client Portal

The client portal puts a client's Brand Dashboard on a subdomain you control, with your name and logo on it instead of ours. Your client opens a link, types one password, and sees their AI visibility numbers live. There is no account to create, nothing to install, and nothing they can change.

It is the same dashboard you use, with every button that would edit something taken out.

What You'll Learn

  • How to point a subdomain of your own at Spyglasses
  • How to publish a portal for one client and set its password
  • What to hand the client, and what they see when they open it
  • What is deliberately hidden from the portal

What the Client Portal Is

Three things, together:

  • White-label. The portal lives at https://ai-visibility.youragency.com/acme.com. Your logo sits in the banner, your name is in the browser tab and the footer, and there is no Spyglasses branding anywhere on the page.
  • Read-only. Clients can read every number, open every drill-down, change the date window, filter, and export. They cannot ignore a publisher, claim a consultation, start an audit, or touch your setup in any way.
  • Password-protected. One password per client, which you generate, reveal, or set yourself. Clients never get a Spyglasses account, so there is no seat to pay for and no user to offboard later.

Because it is the live dashboard and not a snapshot, the numbers move as your Daily Prompt Tracking runs. You do not regenerate anything.

Requirements

  • An Agency or Enterprise plan. Client portals are part of the same white-label feature set as branded exports.
  • A subdomain you control. Something like ai-visibility.youragency.com or reports.youragency.com. Use a subdomain, not your root domain, which almost certainly already points at your website.
  • Organization owner or admin. Both the domain setup and each client's portal are admin-level settings.

You get one portal domain per organization. Every client lives as a path underneath it, so you only do the DNS work once.

Step 1: Add Your Portal Domain

  1. Open Organization settings → Client portal.
  2. Type the hostname your clients will visit, for example ai-visibility.youragency.com.
  3. Click Add domain.

We then show you the DNS records to create at your registrar:

  • A CNAME record pointing your subdomain at cname.vercel-dns.com. This is the record that actually routes traffic.
  • Sometimes a TXT record as well. It only appears when the hostname needs an extra ownership check, so create it if you see it and ignore it if you do not.

Every value has a copy button next to it. Once the records are in, click Re-check. We also re-check pending domains automatically every hour, so a domain that verifies overnight will be Active in the morning without you doing anything.

The status badge tells you where you are:

StatusWhat it means
PendingWaiting on DNS. Set up client portals now; they go live the moment this turns Active.
ActiveLive. Portals under this domain are reachable.
ErrorWe cannot verify the hostname, so portals on it are offline. Check the records, then re-check.

The HTTPS certificate is issued automatically once the record resolves. There is nothing to buy, upload, or renew.

Removing a portal domain stops every client portal underneath it immediately and releases the hostname. Clients who open their link will see a message asking them to contact you. Only remove a domain when you mean to shut the whole thing down.

Step 2: Publish a Client's Portal

Each client is published from their own property.

  1. Open Settings → Client portal for that property.
  2. Check the Portal address. It defaults to the client's own domain, so acme.com gives you https://ai-visibility.youragency.com/acme.com, which is the version clients recognize. You can change it to anything using lowercase letters, numbers, dots, and hyphens. A few addresses are reserved; if you pick one, we say so and you pick another.
  3. Turn on Publish this portal. The switch stays disabled until your portal domain is Active, with a link straight to the domain settings if it is not.
  4. Set the password. A strong one is generated for you, using an alphabet with no lookalike characters, so it survives being read out over the phone. Click Reveal to see it, the copy button to grab it, Regenerate for a new one, or Set a custom password if your client would rather pick their own (10 to 128 characters).

The tab also shows whether the portal is Live and when it was last opened, which is a quick way to see whether a client is actually using it before your next check-in.

Regenerating a password signs out everyone using the old one straight away, including a client who is reading the portal at that moment. Changing the portal address does the same to the old URL. Both are useful when a client changes agencies or someone leaves their team; just remember to send the new details afterwards.

Step 3: Hand It to the Client

Click Download credentials PDF. You get a one-page sheet carrying your logo and name, the client's name, the portal address, the password, and a QR code of the link. It is generated the moment you ask for it and never stored anywhere, because it contains a live password. Email it, print it, or drop it into a kickoff deck.

What the client experiences:

  1. They open the link and see a password screen with your branding and their brand name on it.
  2. They type the password and land on the dashboard. That is the entire sign-in flow.
  3. They stay signed in on that browser for 30 days, so day-to-day checking costs them nothing.

If someone gets the password wrong ten times in a row, that portal locks for 15 minutes. The lock clears by itself; regenerating the password clears it immediately and gives you fresh credentials to send.

Deep links work too. If you send a client straight to a drill-down page, they unlock once and land on that page rather than being dropped at the top and left to find their way back.

What Clients See

Everything on the Brand Dashboard, one card per metric, and every drill-down behind those cards:

  • Share of Voice and visibility trends
  • Competitor comparisons
  • Brand consistency checks and individual check records
  • Site consultations
  • Earned media and publisher value
  • Project goal impact
  • Locations
  • Key message pull-through
  • SEO opportunities and grounding search rankings
  • Site readiness
  • Citation Intelligence, and the raw AI answer behind any citation

Filters, tab switching, and the date-window selector all work normally, and the export button is still there, so a client can pull a CSV for their own reporting without asking you for it.

What Is Deliberately Hidden

  • Anything that changes data. Ignoring a publisher, adding a placement to a project, claiming or dismissing a consultation, starting a re-audit, editing anything.
  • Links to pages that are not in the portal. Projects, key messages, competitors, site audits, and the Citation Optimizer are yours, not theirs. Those labels render as plain text instead of links, so there are no dead ends.
  • Annotations. Your notes on the charts stay internal. Project names are shown, so a client can see which work a goal belongs to.
  • AI Traffic Analytics. That module needs the tracking plugin and lives outside the dashboard, so it is left out of the portal entirely.
  • Report recipient email addresses, which never leave your side of the product.

Portals are also kept out of search results: we send a noindex header on every portal page and disallow crawling for the whole hostname.

FAQ

Can I change a portal's address after I have sent it out? Yes. Edit the address and save. The old URL stops working right away, so send the new link before you change it, or straight afterwards.

What happens if my plan lapses? Portals stop serving and clients see a short message asking them to get in touch with you. Nothing is deleted. Your settings stay editable, you just cannot publish a portal again until the plan is active. Renewing brings every portal back as it was.

Can I remove a single client's portal? Yes. Remove portal on that property's Client portal tab. The address stops working and the password is discarded. You can publish a new portal for the same property later; it gets a new password.

Will a portal show up in Google? No. Every portal page carries a noindex, nofollow header and the whole hostname is disallowed in robots.txt. Anyone without the link and the password sees a password screen.

Can I use more than one domain? One portal domain per organization. Every client sits at their own path under it, which is also what keeps the DNS setup to a single record.

Which properties can have a portal? Brand, product, and person properties. Location and category properties are shown inside their parent's dashboard, so a portal pointed at one would come up empty.

Do clients need a Spyglasses account? No. The password is the only credential, and it is shared by the client's whole team.

On this page

How-to guides for setting up Spyglasses to track your AI traffic