Skip to main content
Start your first project →

Site Access: portal users and the site portal

Business and above

Open your project and click the Access tab (Business and above). Everything here is per-project: enable it with the Project rollout toggle first, then build your portal-user list. Portal users and Site access managers sit further down the page — on a phone, tap the Jump to section button at the top of the page to go straight to them.

Add portal users

  1. In Portal users, enter their name and company, and pick their type and role.

    Types cover workers, subcontractors, visitors, deliveries, clients, consultants and inspectors; the role decides whether they're a worker or a contractor manager.

  2. Click Add portal user.

  3. Click Copy on their row and send them their personal portal link.

    Already active on another project? Use Assign existing portal user instead of re-creating them.

Manage the list

Each row shows an On site / Off site pill, with Edit, Remove from project and Deactivate. Deactivating frees an account-wide slot without deleting their identity or recorded sign-off and attendance history; removal just takes them off this project.

On Business and above, use Edit in the project's Access tab → Portal users to change a person's type. Worker document sign-off is available to active workers and subcontractors assigned to the project. Changing someone to a visitor or consultant removes their worker sign-off tasks and prevents new signatures, while keeping their existing sign-off history for your records.

Next to Copy is Rotate link (owners and admins only). Use it when a link may have been shared or leaked: it issues a new link and stops the old one working, then send the new link with Copy.

Links unused for 90 days are switched off automatically, so a forwarded copy cannot stay valid indefinitely. Any use resets the clock, so regulars are unaffected. A worker retired this way keeps their history, and drops off the Portal users list — add them again with Add portal user to issue a fresh link (they will re-sign the current RAMS, since it is a new identity).

What they see: a phone-friendly site portal with the project's tasks, documents, COSHH information and site files. Attendance shows up under H&S attendance.

Delegate to a site access manager

Under Site access managers, choose an account member and click Assign manager. They get project-scoped visibility of attendance and pending access requests — useful for the person actually running the gate — without account-wide admin rights.

A manager assignment lasts only while that person is on your team. Removing them from the Team page ends every Site Access manager assignment they hold, along with the attendance and access-request notifications that come with it. If you invite them back later they start with none — assign them again here with Assign manager.

From the mobile app (owners and admins)

The Site Book mobile app's project Access tab mirrors the owner side of this page: the portal-user list with each person's link, Rotate link for a leaked credential, and the Site Access settings (the on/off switch, attendance notifications and the RAMS sign-off requirement). Open the project in the app, tap Site access, then Portal users or Site Access settings.

On the mobile list, the personal invite link is only shown to owners and admins — exactly like this page. Site access managers can review the roster from the app, but links are hidden on their rows.

Owners and admins can also manage the roster from the app: each row shows an On site / Off site pill (from the same attendance list as the Access tab), and Share link sends the person their personal link. Add portal user creates a new identity, Edit changes their details, Remove from project takes them off that project, and Deactivate retires the identity account-wide — each destructive action asks you to confirm first, with the same effects as on this page. The settings screen's on/off switch and RAMS toggle save immediately; the attendance-notification toggles save together when you tap Save attendance notifications.

Site Control subscribers also manage the Smart Gate from the app: create or regenerate the site entrance QR (regenerating stops the old poster's code working at the gate, the same as on the web) and print the entrance poster.

On Site Control, open the project's Site access tab in the app and tap Smart Gate. As well as the entrance QR, you can configure the entrance poster (paper size, which site details print, and up to four custom sections) and tap Download poster PDF — the app saves that configuration and shares the print-ready PDF. The Gate sign-in policy picker sets how contractors who scan the QR are handled (Balanced, Controlled, Trusted firms or Open, the same four modes as this page); the live policy is always shown on this page.

Frequently asked questions

How do I reply to or close an RFI in the contractor app?

For a project whose owning account is on Site Control, open the project in the contractor app and tap RFIs, then open the request. Add a reply with Add comment, attach a file with Attach file, or use Close RFI when the request is resolved. If your project access or contractor identity changes while you are choosing a file or sending a reply, reopen the RFI under your current identity. Check the thread and attachments before trying again: a request already sent may have been saved even if its confirmation did not reach the app.

Can I attach a file when I answer an RFI on the web?

RFIs are a Site Control feature. Open the project's Site Info tab (under Setup if you use the New project view), find the request under RFIs and click Answer. The Answer attachment URL field accepts an external link only — an https:// address for a drawing or document hosted somewhere else, such as your client's file share. A link to a file stored in The Site Book (a site file, a plant photo or another RFI's attachment, for example) is refused with an error and the answer is not sent. That stops a reply from exposing an unrelated private file to the contractors who read the RFI. To share one of your stored files with them instead, an owner or admin adds it under Site files on the same Site Info tab, so it goes through the normal portal visibility controls.

Can I answer or reopen an RFI that has been closed or voided?

No. RFIs are a Site Control feature: on the project's Site Info tab (under Setup if you use the New project view), Answer and Close are shown under RFIs only while a request is Open or Answered — you can add a follow-up answer to an Answered one. Once an RFI is Closed or Void, the dashboard and the contractor app both treat it as final: it cannot be answered, closed again or reopened from either. If you see "This RFI has been closed or voided" after clicking Send answer or Close, someone closed it (or the contractor did, from the app) after your page loaded — reload the page to see its current status. Your answer was not saved, so nothing half-sent is left behind. A contractor who taps Close RFI in the app on an RFI that is already closed or voided sees a message saying so, and nothing changes. If the project is linked to Procore, Procore's status takes precedence for a linked RFI: one reopened in Procore reopens here on the next sync.

Does using the contractor app create a company account for me?

No. Your contractor access stays linked to the sites you have been given access to. Opening an internal company link does not create a separate company account or give you access to company management screens. If you also need internal team access, ask the company owner or an admin to invite you to their team.

How many portal users do I get?

Business includes 50 active site portal users across your account (Site Control is unlimited). The Portal users section shows both counts — this project and account-wide. A worker added to a project gets a worker portal identity and counts in the active total while they have active project access, including through crew sign-off. Worker setup is designed never to stop site work: if adding a project worker crosses the included allowance, the account cap is raised automatically and the overage is recorded for a capacity conversation. Other manual additions or reactivations at a reached cap ask you to deactivate someone or contact us for an agreed limit increase. Deactivating someone frees capacity without deleting their identity or recorded sign-off and attendance history. There is currently no published per-user add-on rate.

How does a portal user log in?

They don't need an account — each portal user gets a personal magic link (Copy it from their row and send it). It opens their site portal with the project's details, documents, COSHH information and files.

What does “active sites” mean in the contractor app?

The workspace picker shows an active-site count beside each linked Site Access identity. It includes jobs where Site Access is switched on, jobs where that worker has a current document to sign, and jobs sharing view-only COSHH information. A current sign-off-only job still counts even when the wider Site Access tools are not switched on. The count matches the sites you can open: an archived job can still count while its active grant provides Site Access or view-only COSHH information. Removed project access and deactivated portal identities stop counting.

A portal link was shared or leaked — how do I cut it off?

On the worker's row in Portal users, click Rotate link (owners and admins only). This creates a new link and stops the old one working straight away, so a forwarded or bookmarked copy no longer opens the portal — and any contractor-app sign-in made with the old link is disconnected too. Then Copy the new link and send it to the worker; opening it restores their access (including re-linking the app). The worker's identity, sign-off and attendance history are kept — only the link changes. Rotate the link instead of Deactivate when you want to keep the worker but replace the link.

Why is the contractor app checking my access again?

When your linked worker identity or project access changes, the contractor app checks your current access before showing the site details. If it switches to another worker identity automatically, it clears the previous identity's saved site information first. This also applies when an earlier identity becomes available again, so you only see information for the identity you are using now.

How do I upload paperwork in the contractor app?

On projects whose owning account has Site Control, open the project in the contractor app, tap Credentials, choose My paperwork or — if you manage the contractor company — Company paperwork, select the paperwork type, then tap Upload and choose a PDF or image from your phone. If you lose connection, the app saves the upload for the next sync and shows a waiting message. Leave that queued upload to sync instead of choosing the same file again; if the file already reached the server, sync finishes attaching that saved file to the credential. If your worker identity or project access changes while you are choosing or uploading a file, you may need to reopen Credentials and choose the file again once access is restored. Uploads already saved for later can continue in the background while you remain signed in and have access.

Do portal links expire?

There is no fixed expiry date, but a link that goes unused for 90 days is switched off automatically. Any use resets the clock — opening the link, signing a document, checking in at the gate (including a remembered device), acknowledging the site induction, or using the contractor app. So a worker on your site regularly is never affected; this only retires links nobody has touched for three months. If you think a link has been shared, use Rotate link to replace it straight away rather than waiting.

A worker's link stopped working and nobody deactivated them

It was probably retired for inactivity — links unused for 90 days switch off automatically, so an old forwarded copy cannot sit valid forever. Nothing is lost: their old identity, sign-off records and attendance history are all kept and still appear in your audit pack. To bring them back, add them again in Portal users (Access tab): enter their name and company and click Add portal user, then Copy their new link and send it. A retired person does not appear in the list, so there is no row to rotate — adding them creates a fresh identity with a brand-new link, which is deliberate, because the retired link must stay dead. One thing to expect: because it is a new identity, they will be asked to sign the current RAMS again before they can check in.

Can I let a team member run site access without making them an admin?

Yes — under Site access managers, assign an account member to this project. They get attendance and access-request visibility for this project only; full portal-user management stays with owners and admins.

Is Site Access on Pro?

No — the Site Access management surface (portal, attendance and files) is Business and above. Worker document sign-off via the crew link works on every plan and does not require those management screens. Putting a worker on a project still creates their worker portal identity for the job and includes them in the active portal-user count while assigned.

What happens when a required RAMS sign-off blocks Smart Gate check-in?

The worker's access can be approved while attendance stays off site. The gate page keeps that approved request ready: complete the required RAMS sign-off from the worker's site portal, return to the open gate page and choose Try check in again. The continuation uses the same private request and does not upload a second CSCS card or create a duplicate access request. If delivery was interrupted, it safely retries the worker's approval email before continuing. It then checks that both the worker and their project access are still active, and a successful check-in sends the project's configured attendance notifications.

Related guides

Didn't answer it? Email [email protected] — we'll get back to you by email.