← Back to blog

June 9, 2026

Why Your Clients Shouldn't Need Another Password

SecurityClient Experience

Every client portal eventually asks the same design question: should clients have passwords? For most firms, the honest answer is no — and it's worth being deliberate about why.

The asymmetry that matters

Your staff sign in every single morning. A password is a minor, forgettable step in a daily routine — and if they forget it, IT support (or a reset email) is one click away.

Your clients might log in once a quarter, or once a year, for a single engagement. By the time they need to come back, they've forgotten which email they used, let alone the password. Every "forgot password" flow you add is friction squarely aimed at the person you most need to not bounce off your process.

What a magic link actually buys you

A client clicks a link in an email they already opened, lands on a page that clearly says whose portal this is, and taps one button to continue. No password to invent, remember, or reset. No account to "forget you have." The security properties are actually stronger for this use case, not weaker — the link is single-use, time-limited, and tied to the email address you already verified when you invited them.

The one thing this doesn't solve

Magic links aren't a replacement for real authentication everywhere. Your own staff still need passwords — you're logging in constantly, across devices, sometimes without access to the email tied to the account at that exact moment. The right answer isn't "no passwords anywhere," it's matching the authentication method to how often the person actually needs to sign in.

That split — passwords for the people who log in daily, magic links for the people who log in rarely — is exactly how useHandoff separates staff accounts from client access.