AWRA OpsHub Search
Sales · Customer portal

Your customers check, answer and pay — without calling accounts.

Every customer gets their own portal with your logo on it: what they owe and what is overdue, a running statement, quotes to accept or decline, credit notes, invoice and quote PDFs, and a Pay button that sends an M-Pesa prompt to their phone. The money lands in your own till or card account and posts against the invoice by itself.

Emailed single-use link · No passwords · M-Pesa and card to your own accounts · Invoices, statement, quotes, credit notes

0 passwordscustomers sign in with an emailed link that works once
30 minthe life of a sign-in link, after which it is dead
2 gatewaysM-Pesa on the phone and card through Paystack, into your own accounts
5 sectionsoverview, invoices, statement, quotes and credit notes
What a customer sees

The questions your accounts desk answers all day, answered by the page.

“Can you resend that invoice?” “What is our balance?” “Did our payment land?” “Is the quote still valid?” Each of those is a phone call or an email thread, and each one is answered from records you already keep. The portal shows the customer those same records, live, and only theirs.

It reads the invoices, payments, quotes and credit notes your team already raises in Sales. There is nothing to publish and nothing to keep in step: an invoice appears the moment it is issued, a payment the moment it is confirmed, and a draft never appears at all.

Overview

What they owe across every open invoice, how much of it is past due, and any quote waiting for their answer.

Invoices

Every issued invoice with its lines, tax, what has been paid and the balance, a PDF to download and a Pay button.

Statement

Invoices, payments and credit notes in date order with an opening balance and a running balance, for any range they pick.

Quotes

Every quote you have sent, with its lines and validity date, a PDF, and Accept or Decline while it is still open.

Credit notes

Each credit you have issued or applied to their account, so the lower balance comes with its reason.

Access, from invitation to sign-out

A link instead of a password, and every step built for the inbox it lands in.

Customers forget passwords, share them, and reuse them on other sites. So the portal has none. You invite a contact, they get an email, and the email is the key.

You invite a contact

Pick the customer, enter the contact’s name and email, and send. Do it from the Sales screen on the web or from the mobile app. A customer can have several contacts, each with their own sign-in.

They get a link

The invitation names your business and carries a sign-in link. It works once and expires after 30 minutes. Next time, they type their email on the sign-in page and a fresh link is sent.

Opening it asks for a click

The link opens a page with a Continue button rather than signing in straight away. Mail security scanners open every link in a message, and a link that signed in on open would be used up before your customer ever saw it.

You can revoke at any time

Revoke a contact and every link already sent stops working. Access is re-checked on every page, so someone signed in at that moment is out on their next click, not when the session happens to expire.

The sign-in page gives the same answer to every address, whether it has access or not, so it cannot be used to find out who your customers are.
At most three links per address every fifteen minutes, on top of a per-connection limit, so the form cannot be used to flood a stranger’s inbox.
Only a fingerprint of each link is stored. Someone reading the database cannot rebuild a working link from it.
From Pay button to cleared balance

The gateway confirms the payment. The browser never does.

A customer can pay all of an invoice or part of it, by M-Pesa or by card, to the till and card account your business has connected. The invoice moves only when the payment provider says the money arrived.

M-Pesa
01 · CustomerEnters phone and amountPrefilled with the balance, which they can lower to pay in part. It cannot be more than the balance.
02 · PendingPIN prompt on their phoneAn attempt is recorded as pending before anything else happens.
03 · M-PesaConfirms or declinesThe confirmation comes from M-Pesa itself, not from the page.
04 · PostedPayment on the invoiceAmount paid rises, balance falls, status moves to partly paid or paid.
05 · Closed loopBooks and receiptThe collection is posted to your ledger and an emailed receipt goes to the customer.
Card, through Paystack
01 · CustomerChooses an amountAny amount up to the balance.
02 · PendingSent to Paystack checkoutThe attempt is recorded first, then the browser goes to Paystack.
03 · Back againReturns to the invoiceComing back records nothing. The page says the payment will show once confirmed.
04 · PaystackConfirms in the backgroundThe signed confirmation from Paystack is what posts the payment.
05 · Closed loopBooks and receiptSame posting, same ledger entry, same receipt as M-Pesa.

Why the Pay button sometimes does not appear. It shows only when the invoice is in Kenya shillings, has at least one shilling left to pay, and your business has an active, fully set-up M-Pesa or Paystack connection. Both gateways are connected in shillings, so an invoice in another currency is not offered a payment the gateway would price wrongly. Payment attempts are also rate-limited per customer.

Worked example

Lakeside Agrovet asks for a statement. Nobody has to send one.

Nyanza Feeds Ltd supplies Lakeside Agrovet in Kisumu on 30-day terms. In September, Lakeside’s bookkeeper wants to know why the balance is not what she expected before she releases the next payment.

She opens the portal, picks 1 August to 30 September, and sees the same figures Nyanza’s own team would read off the customer’s account: invoices as charges, payments and credit notes as credits, and a balance after every line.

The opening balance is real. Everything dated before the range is added up into one opening line, so the running balance on the right matches the account rather than starting from zero.
The credit note explains the gap. KES 6,400 for damaged bags was applied in August. It is on the statement and listed under Credit notes, so the question answers itself.
The portal payment is already there. The KES 50,000 she paid from the invoice page on 10 September shows as an M-Pesa line the moment M-Pesa confirmed it.
DateEntryReferenceChargedPaid / creditedBalance
01 AugOpening balance58,000.00
01 AugInvoiceINV-1043120,000.00178,000.00
15 AugPaymentBank transfer80,000.0098,000.00
20 AugCredit noteCR-00126,400.0091,600.00
02 SepInvoiceINV-106192,400.00184,000.00
10 SepPaymentM-Pesa50,000.00134,000.00
30 SepClosing balance134,000.00
Which portal is which

Four ways outsiders reach your workspace. This page is about the first.

They are kept apart on purpose: each one has its own sign-in, its own reach, and nothing that lets a visitor of one wander into another.

DoorWho uses itHow they get inWhat they can do
Customer portalContacts at a customer you sell toEmailed single-use link, 30 minutesInvoices, statement, quotes, credit notes, PDFs, pay by M-Pesa or card
Quote email linkAnyone you email a quote toA signed link in the quote email, which expiresRead that one quote, download it, accept or decline it
Helpdesk intake portalAnyone with a support requestA public form, then a tracking linkRaise a ticket, follow it and reply to it
Employee self-serviceYour own staff without a loginA personal link and a PINLeave, time, payslips and support for themselves
What is in it

Built to be opened by people outside your organization.

Your name and logo

Every page carries your business name and the logo you uploaded. Without a logo it shows your initials rather than a generic icon, so the customer knows whose portal it is.

One customer’s records, only

Every page is filtered to your business and to that customer. Change the invoice number in the address bar to someone else’s and the page is simply not found.

Drafts stay private

Only issued invoices appear, and only quotes you have actually sent. Work in progress on your side is never visible on theirs.

PDFs of invoices and quotes

The same documents your team sends, downloadable at any time, so “please resend the invoice” stops being a request.

Quote answers that reach the author

Accept or decline, with an optional note. The answer is recorded under the contact’s name, the quote’s status changes, and whoever wrote the quote gets an alert straight away. An expired quote asks for an updated one instead.

A statement for any range

The last six months by default, any from and to dates on request, always with an opening balance carried in from before the range.

Part payments welcome

A customer clearing an invoice in two instalments pays what they can today. Each payment posts on its own and the balance tracks it.

Kept apart from staff sessions

If someone is signed in to the workspace as staff in the same browser, the portal refuses to open until they sign out. A staff session would otherwise colour what the portal shows.

Managed from the app too

Invite a contact, resend an invitation or revoke access from the mobile app as well as the web, with the same permission guarding both.

Customer portal: what it does today, and what we can add

What AWRA OpsHub does today

  • An emailed single-use sign-in link that expires in 30 minutes, with no password anywhere in the portal.
  • A confirmation step on the link so mail scanners that open links cannot use up a customer’s sign-in.
  • Revocation that ends a live session on the next click, and invalidates every link already sent.
  • Overview, invoices, statement, quotes and credit notes, filtered to your business and that one customer on every page.
  • Invoice and quote PDFs the customer can download at any time.
  • Quote accept and decline, recorded under the contact’s name, with the quote’s author alerted.
  • M-Pesa and card payment of all or part of an invoice, into your own connected accounts, posted only on the provider’s confirmation.
  • Your name and logo on every portal page, with initials when no logo has been uploaded.
  • Invite, resend and revoke from the web and the mobile app, behind one permission.

More we can add to your workspace

  • A statement PDF the customer can download or forward to their auditor, beside the on-screen statement.
  • Credit note PDFs in the portal, to sit beside the invoice and quote downloads.
  • Sales orders and delivery progress in the portal, so a customer can see where an accepted order has got to.
  • Online payment for invoices in other currencies, for a business that bills in US dollars or shillings of another country.
  • Raising a query on an invoice from the portal, opening a helpdesk ticket already linked to that customer and that document.
  • Contact details the customer keeps current themselves, such as a billing email or a tax PIN, with a change you approve.
  • Access that ends on a date you set, for a customer engaged for one project or one season.

Where we point you to a specialist

  • We will not mark an invoice paid because a browser came back from a checkout page. The provider’s own confirmation is the only thing that moves the balance, and we would keep it that way on request.
  • We show the customer your records; we do not settle a dispute about them. Whether a charge is owed under your terms is between you and your customer, and your own counsel where it comes to that.

Each row in the middle column extends a portal that already has the sign-in, the per-customer filtering and the payment posting to build on. Tell us which one your customers ask for most.

Customer portal

Customer portal questions

How does a customer sign in?
With an emailed link rather than a password. You invite a contact by name and email against one of your customers, and they receive an invitation with a sign-in link. Each link works once and expires after 30 minutes. To come back later they enter their email on the sign-in page and a fresh link is sent. There is no password to set, reset, share or leak.
Why does the sign-in link open a page with a button instead of signing straight in?
Because many company mail systems scan every link in an incoming message by opening it. If opening the link signed the customer in, the scanner would use up the single-use link before the customer ever clicked it, and they would see an expired-link message. The Continue button means only a person completes the sign-in.
What can a customer see in the portal?
Five sections. An overview of what they owe, what is overdue and any quote waiting for their answer. Their issued invoices, with lines, tax, payments and balance, and a PDF of each. A statement of invoices, payments and credit notes for any date range, with an opening balance and a running balance. The quotes you have sent them, with PDFs and Accept and Decline while a quote is open. And the credit notes issued to their account. Draft invoices and unsent quotes are never shown.
Can customers pay from the portal, and where does the money go?
Yes, by M-Pesa or by card through Paystack, using the M-Pesa and Paystack connections your own business has set up, so the money goes to your till or your card account rather than through us. A customer can pay the whole balance or part of it. The invoice is updated only when M-Pesa or Paystack confirms the payment, at which point the payment is recorded on the invoice, the collection is posted to your ledger and a receipt is sent.
Why is there no Pay button on some invoices?
The button appears only when the invoice is in Kenya shillings, still has a balance of at least one shilling, and your business has an active, fully set-up M-Pesa or Paystack connection. Both gateways are connected in shillings, so an invoice in another currency is not offered an online payment. Paying invoices in other currencies is something we can add.
Can one customer see another customer’s invoices?
No. Each contact is tied to one customer of one business, and every page and every download is looked up through both of those, never through the number in the address alone. Changing an invoice number in the address bar to one belonging to someone else returns a not-found page.
What happens when we revoke someone’s access?
Their sign-in is switched off and every link already sent to them stops working. Access is checked again on every page, so if they are signed in at that moment they are signed out on their next click rather than when their session would have expired. You can invite them again later.
How is this different from the helpdesk portal and the employee portals?
The customer portal is for the people you sell to and is about money: invoices, statements, quotes and payment. The helpdesk intake portal is a public form for anyone with a support request, followed by a tracking link. The employee self-service portals are for your own staff without a login, for leave, time and payslips, opened with a personal link and a PIN. Each has its own way in and none of them leads to another.
Fewer calls to accounts

Let customers find their own balance, and pay it.

Invite your first customer contact, and the next “can you resend that invoice” is answered before it is asked.