Real-World Example
ABC Collections hires Sarah to manage consumer accounts. A parent creditor admin creates Sarah as a user and gives her the correct access. Sarah should be able to log in and manage only the records allowed by her role and account scope. If Sarah leaves the company, her access should be removed so she can no longer use the portal.Visual Flow
How It Should Work
- It should appear only for parent creditor accounts.
- It should allow authorized users to manage creditor portal users.
- User access should match the person’s role and account scope.
- A new user should receive a secure, user-specific, time-limited invitation.
- Removing or disabling a user should revoke their portal access.
User Access Lifecycle
An administrator creates the user with their name, email address, role, and permissions. The user remains pending until they complete the invited user password setup, which verifies their email and activates their assigned access.
Permissions can control access to accounts, negotiations, communications, dashboards, reports, user management, and other administrative functions. Every permission remains limited to the creditor organization that invited the user.
How It Should Not Work
- It should not appear for users who are not allowed to manage users.
- It should not let a user grant access outside their own creditor account.
- It should not accept an expired, reused, or different user’s invitation.
- It should not grant permissions that an administrator did not assign.
- It should not leave removed users with active portal access.

