Provisioning partners
How to give an external partner the right access, and how their workspace behaves
Provisioning partners
A partner is an external associate (for example, a contact at a partner firm such as UT Financial Services) who helps Eden deliver client work. Partners sign in to the team surface with a scoped, read-only workspace. They are never members of a client organization: the client portal, its readiness intake, and its billing are for founders. A partner's firm is an affiliation on their profile, not a workspace.
What a partner sees
- Only the clients explicitly assigned to them. Clients that are open to all staff are still hidden from partners.
- For each assigned client, the Partner role grants read-only view of: clients, assessments, data rooms, documents, and project boards. View-level data-room access shows files without downloads.
- Their home page lists each assigned client with the engagement board's progress, items waiting on the client, data-room activity, and assessment status, so the work to facilitate is visible at a glance.
- Before any client material opens, the partner signs one firm-level NDA covering every client they can access.
Steps to provision a partner
- Create the account. People, then invite with the role Partner. This routes them to the team surface, assigns the shared Partner staff role, and pins them to assigned clients only.
- Assign their clients. Open the person, then the Client access card. For each client they support, choose Role access. This applies the Partner role's read-only levels to that client and nothing else.
- Check the "Sees" line. Each assignment shows exactly which surfaces the partner gets for that client. Anything listed under "Hidden" is invisible to them, including that client's data room.
- Prefer Role access over Custom. Choose Custom only to narrow a specific client further. Custom starts from the Partner role's levels; setting a surface to hidden removes it for that client only.
Common mistakes
- Custom grant missing a surface. A custom assignment that leaves Data rooms on hidden removes that client's room from the partner's directory with no error. The "Sees" line on the assignment is the check.
- Adding the partner to a client organization. That creates a founder login: they will see the readiness intake for that one organization and never the cross-client rooms. Remove the membership and assign them on the team surface instead.
- Expecting edits. The Partner role is read-only by design. If a partner needs to work tasks, that is a member role with a scoped staff role, not a partner.