Skip to main content

Overview

The Estate Manager Portal uses a granular permission system to control what firms can do with client data. Permissions are set at the firm-client relationship level, meaning they apply to all users within a firm who have access to a particular client.

Permission Model

Permissions are granted at the firm-client relationship level. When a client grants access to a firm, they choose which permissions to enable:

How Permissions Apply to Users

Firm users inherit relationship permissions based on their role:
Permissions define what actions are allowed. Roles define who can perform those actions. Both must align—a Viewer cannot edit even if the relationship allows editing.

Individual Permissions

View Items

boolean
Allows viewing items in the client’s portfolio.
What it enables:
  • See item list and search/filter items
  • View item detail pages
  • See item images and attachments
  • Read item descriptions and notes (not firm notes)
  • View item history
What it does NOT enable:
  • Seeing values or prices (requires view_valuations)
  • Making any modifications
  • Exporting data
Typical use cases:
  • Initial relationship setup
  • Review-only scenarios
  • When combined with other permissions

Edit Items

boolean
Allows creating, updating, and deleting items in the client’s portfolio.
What it enables:
  • Create new items
  • Edit existing item details
  • Delete items
  • Upload and manage item images
  • Update item notes
What it does NOT enable:
  • Seeing valuations (requires view_valuations)
  • Managing collections or locations (separate permissions)
  • Exporting data
Typical use cases:
  • Active portfolio management
  • Inventory documentation
  • Ongoing advisory relationships
This permission allows permanent data modification. Grant only to trusted firms that need to actively manage items.

View Valuations

boolean
Allows viewing prices, market values, and portfolio totals.
What it enables:
  • See item purchase prices
  • See current valuations
  • View spot prices for precious metals
  • See portfolio total value
  • View allocation breakdowns by value
  • See value charts and trends
What it does NOT enable:
  • Modifying valuations (requires edit_items)
  • Exporting value data (requires export_data)
Typical use cases:
  • Financial planning
  • Insurance documentation
  • Estate valuation
  • Wealth management

Export Data

boolean
Allows exporting client data to PDF or CSV formats.
What it enables:
  • Generate PDF portfolio reports
  • Export item data to CSV
  • Create print-friendly views
  • Download images and documents
Audit note: All exports are logged with:
  • User who exported
  • Timestamp
  • Export format
  • What data was included
Typical use cases:
  • Insurance documentation
  • Tax reporting
  • Legal proceedings
  • Compliance reporting
Clients receive notifications when their data is exported. The audit log shows all export activity.

Manage Collections

boolean
Allows creating, editing, and deleting collections.
What it enables:
  • Create new collections
  • Rename collections
  • Delete collections
  • Add items to collections
  • Remove items from collections
  • Reorder collections
What it does NOT enable:
  • Creating or editing items (requires edit_items)
Typical use cases:
  • Portfolio organization
  • Insurance grouping
  • Category-based management

Manage Locations

boolean
Allows creating, editing, and deleting storage locations.
What it enables:
  • Create new locations
  • Edit location details
  • Delete locations
  • Assign items to locations
  • Change item locations
Typical use cases:
  • Storage documentation
  • Security planning
  • Insurance requirements
  • Inventory auditing

Manage Alerts

boolean
Allows creating and managing price alerts on the client’s behalf.
What it enables:
  • Create price alerts for precious metals
  • Edit alert thresholds
  • Delete alerts
  • Configure alert notifications
Typical use cases:
  • Active portfolio monitoring
  • Investment advisory services
  • Market-aware management

Manage Shares

boolean
Allows creating and managing share links on the client’s behalf.
What it enables:
  • Create share links
  • Configure share link settings
  • Revoke share links
  • View existing share links
Typical use cases:
  • Coordinating with third parties (appraisers, etc.)
  • Insurance agent access
  • Multi-party estate planning
This permission allows the firm to create share links that grant access to others. Grant only when the firm needs to coordinate with third parties.

View Heirs

boolean
Allows viewing the client’s heir access designations.
What it enables:
  • See designated heirs
  • View heir access settings
  • See waiting period configurations
What it does NOT enable:
  • Modifying heir designations (requires manage_heirs)
Typical use cases:
  • Estate planning review
  • Succession planning
  • Legal document preparation

Manage Heirs

boolean
Allows modifying heir designations on the client’s behalf.
What it enables:
  • Add new heir designations
  • Remove heir designations
  • Modify heir access settings
  • Change waiting periods
Requirements:
  • Requires legal verification before this permission can be granted
  • Additional confirmation steps for changes
  • Enhanced audit logging
Typical use cases:
  • Estate attorneys acting as legal representatives
  • Court-appointed executors
  • Power of attorney situations
This is the most sensitive permission. It should only be granted to verified legal representatives. Granting this permission requires additional legal verification through Storehouses.

Permission Presets

Presets are predefined permission combinations for common use cases.

View Only

Best for: Initial reviews, read-only access, preliminary consultations

Reporting Only

Best for: Insurance documentation, tax reporting, compliance needs

Standard Management

Best for: Most advisory relationships, ongoing portfolio management
This is the default preset for new firm relationships.

Full Management

Best for: Comprehensive portfolio management, family offices
Best for: Estate attorneys, executors, legal guardians
This preset requires legal verification. You will be asked to provide documentation confirming the firm’s legal authority before this preset can be applied.

Custom

Best for: Unique situations requiring specific permission combinations When none of the presets fit your needs, you can toggle individual permissions to create a custom configuration.

Role-Based Access Control

While permissions define what actions are allowed, roles determine who can access which clients within a firm.

Firm Roles

Permission + Role Matrix

A firm user can only perform an action if:
  1. The firm-client relationship has the required permission
  2. The user has access to that client (based on role or assignment)
  3. The user’s role allows the action type
Access: All clients automaticallyCan perform:
  • All actions permitted by relationship permissions
  • Team management
  • Client assignments (Admin only)
  • Billing and settings (Owner only)

Permission Inheritance

Example scenario: A firm-client relationship has these permissions:
  • View Items: Granted
  • Edit Items: Granted
  • Export Data: Not granted
Here’s what each role can actually do:
The relationship permissions set the maximum allowed actions. A user’s role may further restrict what they can do (e.g., Viewers cannot edit even if the relationship allows editing).

Changing Permissions

Client-Initiated Changes

Clients can modify permissions at any time:
  1. Go to Account Settings → Estate Managers
  2. Find the firm and click Edit Permissions
  3. Select a new preset or toggle individual permissions
  4. Save changes
Changes take effect immediately. The firm is notified of permission changes.

Requesting Additional Permissions

If a firm needs more permissions:
  1. Firm contacts client directly
  2. Client modifies permissions through their settings
  3. New permissions become active immediately
Firms cannot request permission changes through the portal. All permission changes must be initiated by the client.

Audit Logging

Every action is logged with:
Audit logs are tamper-resistant and hash-chained. This means each entry contains a hash of the previous entry, making it impossible to modify or delete entries without detection.

Best Practices

  • Start restrictive: Begin with View Only or Reporting Only, expand as needed
  • Review regularly: Check audit logs and adjust permissions if activity doesn’t match expectations
  • Use presets: Presets are designed for common scenarios and tested for appropriate access
  • Be cautious with manage_heirs: Only grant to verified legal representatives
  • Request minimum necessary: Only ask for permissions you actually need
  • Explain your needs: Help clients understand why you need specific permissions
  • Respect boundaries: Don’t attempt actions outside your permitted scope
  • Document access: Use firm notes to record why you accessed or modified data

Next Steps

For Firms

Guide for using the portal

For Clients

Guide for granting access

Security

Security and compliance features

Portal Overview

Estate Manager Portal overview