Skip to main content

Employee Portal

The Employee Portal is a separate, employee-facing application where your team members can browse approved vendors, complete training assignments, acknowledge policies, and report security incidents. It uses email-based OTP authentication — no separate password or Cognito account needed.

Administration

Configure the Employee Portal from Administration → Employee Portal in the main platform. The admin page has three tabs: General, Modules, and Access Log.

Employee Portal admin page showing General tab with Enable Employee Portal toggle (off), Portal URL (not assigned), Welcome Message text field, Allowed Email Domains input with Add button, and Pending Vendor Requests section

General Settings

SettingDescription
Enable Employee PortalMaster on/off toggle for the portal
Portal URLUnique URL path for your organization (assigned by operator)
Welcome MessageCustom text shown on the portal login page (autosaves on blur)
Allowed Email DomainsWhich email domains can authenticate — add at least one
Pending Vendor RequestsQuick view of employee vendor requests awaiting review

Module Toggles

The Modules tab controls which sections employees see in the portal:

ModuleDescription
VendorsBrowse approved vendor directory, view vendor details, submit new vendor requests
TrainingView assigned training modules and completion status
PoliciesRead and acknowledge organizational policies
IncidentsReport suspected security incidents through a guided wizard
ContactSend messages to the compliance team

Each module can be independently enabled or disabled.

Access Log

The Access Log tab shows portal activity:

  • Who authenticated and when
  • Which modules they accessed
  • Session duration

Employee Experience

Authentication

The portal lives at a unique URL for your organization. Employees:

  1. Enter their work email address
  2. Receive a 6-digit OTP code via email
  3. Enter the code to start a 24-hour session

No password is needed — authentication is email-based. Only email addresses matching your configured allowed domains can authenticate.

Recognized vs. Unrecognized Users

User TypeDescriptionAccess
RecognizedEmail matches an AccessPersonnel recordFull portal access (all enabled modules)
UnrecognizedValid domain but no personnel recordCan only browse the vendor directory

Vendor Directory

Employees can:

  • Search and filter approved vendors
  • View vendor details (purpose, data types handled, security attestations)
  • Submit requests for new vendor evaluations (routed to vendor management for review)

Training

View and complete security awareness training assignments:

  • See assigned training modules and their status
  • Launch training content directly from the portal
  • Track completion progress

Policies

Review and acknowledge organizational policies:

  • See published policies requiring acknowledgment
  • Read policy content
  • Sign/acknowledge each policy
  • View acknowledgment history

Incidents

Report security incidents through a guided 5-step wizard:

  1. What type of incident?
  2. When did it happen?
  3. What happened (description)?
  4. What is the impact?
  5. Review and submit

Submitted incidents create records in the main Incident Response module for triage by your security team.

Contact

Submit questions or messages directly to the compliance team through a simple contact form.