1. Purpose and audience
- Which problem does the portal remove?
- Who are the users: clients, partners, suppliers or employees?
- Which complete workflow must each role finish?
- What remains on the public website and what requires authentication?
- What measurable outcome is expected in the first months?
- Do organizations have several users and their own administrators?
- Which languages, countries and time zones are required?
2. Identity, roles and access
- Who creates and approves accounts?
- Is SSO or an existing identity provider required?
- How is access recovered and a user disabled?
- Which roles exist within one organization?
- Can a user delegate or invite other people?
- How is data isolated between organizations?
- Which operations require additional authentication or approval?
3. Data and integrations
- What is the source of truth for each data type?
- Is data read in real time or synchronized?
- What happens when a source system is unavailable?
- Are documented APIs and test environments available?
- How is the same organization identified across systems?
- Which documents are uploaded, generated and retained?
- Which events go to CRM, ERP, SAP or email?
- How is inconsistent data corrected and reconciled?
4. Workflows and experience
- What are the three most frequent actions?
- What information is required before a decision?
- Which states, validations and exceptions exist for each request?
- Are draft, approval, cancellation and history required?
- Which notifications are useful and through which channel?
- Must the portal work on mobile?
- Which accessibility requirements apply?
- How does a user get help without abandoning the workflow?
5. Security and compliance
- Which personal or confidential data is exposed?
- Which retention and deletion rules apply?
- Which actions belong in the audit log?
- How are secrets and administrative permissions managed?
- Which limits and protections apply to uploads and APIs?
- How are security updates and remediation applied?
- What is the incident procedure and who must be notified?
For verifiable technical criteria, use primary sources such as the OWASP Application Security Verification Standard and OWASP Authorization Cheat Sheet.
6. Launch and operations
- Who administers users and content?
- How are initial accounts and data migrated?
- Which monitoring, alerts, backups and restore procedures exist?
- What are support hours and severity levels?
- How is the portal released gradually to a pilot group?
- Which events and conversions are measured?
- Who owns the repository, environments and documentation?
- How is the post-launch backlog prioritized?
Answers do not need to be perfect before discovery. They need to show what is decided, what is an assumption and which risk should be validated in the first stage.
Do you have a portal planned and need to turn the checklist into scope?
We can facilitate discovery, separate the MVP from extensions and define architecture, integration and operations before implementation estimation.
Discuss your project