Ledgr/Documentation/Portals & self-service

Portals & self-service

Four surfaces Ledgr hands to people who do not work for you — your customer, your employee, your supplier and your driver. None of them takes a seat on your plan, because none of them is a user of your Ledgr.

Plan.

Each portal follows the module it belongs to: the customer portal comes with invoicing (on every plan), employee self-service with payroll, the supplier portal with procurement, and the driver app with logistics. See pricing.

The seats you are not paying for.

A portal link is not a login. Nobody in this guide has an account, a password or a place in your user list, and none of them counts against your plan's seat limit — however many customers, suppliers, employees and drivers you invite.

The customer portal

Emailing an invoice includes a link. Opening it gives your customer the invoice exactly as you see it — the same single layout used by the preview, the PDF and the emailed attachment — plus:

  • A PDF to download.
  • A Pay now button, if you have your own PayFast credentials set up in Settings → Integrations. The money goes to your account and the invoice settles itself when PayFast confirms it.
  • On a quote, Accept or Decline buttons.
  • A statement of everything outstanding, if you send them a contact link rather than an invoice link.

Quote acceptance is the one worth switching on

Before this existed, a quote was marked accepted because a salesperson said so. Now the customer decides, and Ledgr records who typed their name, on which quote, and when. The typed name is the signature.

The page works with no JavaScript at all, because it has to survive whatever browser the customer's email client hands it to. Anybody holding the link can decide — the same trust model as "view and pay online" — but once a quote is decided the link cannot re-decide it, so a forwarded email cannot reopen a settled question.

What Ledgr deliberately does not record.

No IP address and no browser fingerprint. Both are personal information under POPIA and would need a purpose and a retention position of their own. What makes the acceptance evidential is that the answer came back through a link signed for that one quote, at a recorded time.

Accepting also moves the deal it came from, so your pipeline reflects the customer's decision rather than somebody's memory of it.

Employee self-service

Each employee gets their own link, which gives them:

  • Every payslip, current and historical, as a PDF.
  • Their IRP5 when it is issued.
  • Leave balances — annual, sick and family responsibility — and a form to request leave.
  • Their deductions and what they are for.
  • A way to submit a change of address or banking details for your approval, rather than by WhatsApp message to whoever runs payroll.

This is the tab that stops payroll day being interrupted. It is also the reason payroll never needs to email a payslip as an attachment to a personal address.

The supplier portal

Procurement used to only point one way: Ledgr could send a purchase order and had no way of hearing back, and a supplier's invoice arrived as a PDF for somebody to retype. The supplier portal closes that loop. Your supplier can:

  • See requests for quotation and submit a priced, multi-line quote.
  • See purchase orders awaiting acknowledgement, and confirm them with a delivery date.
  • Submit their invoice against a purchase order.
  • See which of their invoices are received, queried or paid, and their statement balance with its ageing.
A supplier can never create a liability.

An invoice submitted through the portal arrives as a draft bill. It posts nothing to your ledger and appears in nobody's payables until one of your people accepts it. Nothing a supplier does through this portal moves money, moves stock, or changes a figure you have already acted on.

The quiet benefit is the matching. A bill somebody retypes from a PDF has no line breakdown to check, so the three-way match falls back to comparing totals — which passes an invoice whose total is right and whose items are wrong. An invoice submitted through the portal carries the purchase-order line on every line as a side effect of how it was submitted, so the strictest payables control in Ledgr becomes the default rather than the diligent case. See procurement.

The driver app

Drivers get a token scoped to one driver record, used by a phone app rather than a browser link. A driver sees their trip, the stops in order, and captures at each one: who received the goods, their signature, a photograph, the quantities actually handed over, and a reason code if something went wrong — load shedding among them, because it is the most common reason a South African delivery is turned away.

It is built for a kerbside on a bad connection: one request per screen, reason codes that arrive with their labels so nothing has to be looked up, and every capture safe to send twice. Logistics & fleet covers what the proof establishes and how it is graded.

Links, expiry and taking access away

PortalHow they get inHow you take it away
CustomerA signed link in the email, scoped to one invoice or one contact.Reissue the document's access; the old link stops working immediately.
EmployeeA signed link scoped to one employee record.Revoke from the employee's record. Ending employment ends access.
SupplierAn invitation from the supplier's contact record; the token travels in a header, not the address bar.Revoke from the contact.
DriverA token issued to the driver's phone, sent as a normal authorisation header.Revoke from the driver record — it takes effect on the next request, even on a phone already holding a token.

Every one of them is scoped to a single record and a single business. A link to one invoice cannot be edited into a link to another, and none of them can reach anything else in your Ledgr. Read security & POPIA for how that is enforced.

Treat a customer or employee link like a document, because that is what it is.

Anyone holding it can open what it points at, exactly as anyone holding a posted invoice can read it. That is the intended behaviour and it is what makes "view and pay online" work without asking your customer to create an account. Where something must not be forwardable, it is not put in a link — which is why the supplier and driver tokens sit in a header.

Let them serve themselves

Four surfaces, no seats, no passwords to reset.