How to Build a Secure Notion Client Portal with Page-Level Permissions

Keeping your client portal in Notion gives you one organized place to exchange information, share updates, manage tasks, and document important notes. The challenge is making the experience convenient for clients without exposing the master databases you use to manage the rest of your work.

Notion’s page-level permissions offer a practical solution. With the right structure, each client can see only the task, note, or database pages assigned or shared with them. You still maintain centralized task and notes databases across all clients, while every client receives a focused portal experience.

This setup requires a Notion Business or Enterprise plan. If you do not use one of those plans, you can still create a useful client portal, but you will need a simpler structure that does not depend on advanced permission rules.

Check this template for a simple pre-built solution without these page-level permissions!

What You Will Build

The system begins with a private Client Manager page. Inside it, you will create three databases: Client Portals, Tasks, and Notes. The Client Portals database gives every client a dedicated home. The other two databases act as private master lists that let you manage work across all clients.

Each client portal page contains linked views of the Tasks and Notes databases. Page-level permissions then determine which individual records a client can see. This means your internal database stays centralized, but each client receives a filtered and permission-controlled experience.

Step 1: Create the Three Core Databases

Start by adding a new page to your Notion workspace and naming it Client Manager. If you work alone, you can keep it in your Private section. If you have a team, place it in the appropriate teamspace and confirm that only the right internal team members have access.

Inside the Client Manager, create three full-page databases:

  • Client Portals: One page for every client portal
  • Tasks: A master task list across all clients
  • Notes: A master notes database across all clients

Keep the structure simple at first. You can add projects, invoices, files, meeting notes, or other databases later when the foundation is working correctly.

Recommended properties include:

  • Tasks: Task name, Status, Due Date, and Assignee
  • Notes: Note name, Shared With, Created Time, and optional Files
  • Client Portals: Client name and any internal tracking fields you need

The Person properties are essential. They connect an individual task or note to the client who should be allowed to access it.

Step 2: Build a Reusable Client Portal Template

Open the Client Portals database and create a new database template. Give it a clear name such as New Client Portal.

Inside the template, add a welcome callout and write a short message that explains how the client should use the space. Under the welcome area, add linked views of your Tasks and Notes databases. Rename the views so clients immediately understand what they contain.

For the Tasks view, group items by Status to make progress easy to scan. For the Notes view, sort by Created Time with the newest notes at the top. You can also hide database titles and unnecessary properties to create a cleaner presentation.

Set this template as the default for the Client Portals database if you want every new client page to start with the same structure.

Step 3: Configure Page-Level Permissions

Open the Tasks database, select Share, and go to the advanced permissions area. Create a new rule based on the Assignee property. This tells Notion that the person assigned to a task can access that task page.

Choose the access level that supports your workflow:

  • Can view: Clients can follow progress without changing anything.
  • Can comment: Clients can leave updates or questions as comments while you maintain control of the database pages.
  • Can edit: Clients can update the page content and properties directly.

Repeat the process in the Notes database using the “Shared With” property. You might allow editing if you want clients to add their own notes, or use comment access when you prefer to control the content.

The safest choice depends on how much participation you want from the client. Start with the least access needed and expand it only when there is a clear reason.

Step 4: Create and Share Each Client Portal

Create a new page in the Client Portals database and apply your template. Name it for the client, review the welcome message, and confirm that the linked views are present.

Suggested portal components include:

  • A welcome message and short instructions
  • A task view grouped by status
  • A notes view sorted by newest first
  • Project updates or milestones
  • Meeting notes and shared files
  • Invoices or payment information when appropriate

Share the portal page directly with the client’s email address. Choose the page-level access carefully. Can view or Can comment is often enough when you do not want the client to change the portal layout. Use Can edit only when the client needs to add content directly. Avoid Full Access unless the client truly needs permission to share and manage access to the page.

When Notion asks whether you want to upgrade a client from guest to member, choose the option that fits their role. A guest is usually appropriate when the person only needs access to their own portal.

Step 5: Assign Tasks and Share Notes

Return to your private Tasks database and create a task for the client. Add a status and due date, then select the client in the Assignee property. Once the permission rule is active, that task becomes available to the assigned person.

Follow the same process in Notes. Create the note, add the client to Shared With, and enter the content you want to share. If the client has edit access, they can contribute directly to the page. You will see those changes in your master Notes database.

This structure lets you manage every client from one place. Your client sees only the relevant records, while you can review all tasks and notes across your business.

Step 6: Test the Client Experience

Always test the portal before using it for active work. Open the portal from the invited client’s account or ask a trusted test user to confirm what is visible.

Verify that:

  • The client can open the main portal page.
  • Only tasks assigned to that client appear.
  • Only notes shared with that client appear.
  • The selected view, comment, or edit permissions behave as expected.
  • The client cannot open your master Tasks or Notes databases.
  • No content belonging to another client is visible.

Testing is especially important when you duplicate templates or adjust sharing rules. A short access review can prevent accidental oversharing.

Protect the Master Databases

The master Tasks and Notes databases should remain private to your internal team. Do not share those database pages directly with clients. Access should come only from the page-level rule connected to the relevant Person property.

Remember that you may still see every task and note when viewing a client portal yourself because your internal account already has broader access. The client’s view is different. That is why testing through a separate invited account is an essential part of the setup.

Expand the System When You Are Ready

Once the basic portal works, you can add databases for projects, invoices, meeting notes, deliverables, or files. Use the same principle: keep the master source private, add the right Person property, configure page-level access, and display the relevant information through linked views inside the client portal.

You can also improve your Client Manager dashboard with linked views of Client Portals, Tasks, and Notes. A gallery can make client portals easy to open, while grouped task views and sorted note views help you manage daily work efficiently.

Check the Video Guide

Since this tutorial involves many steps, I highly recommend my video guide so you can follow along! Be sure to check it out below:

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.