For anyone who has been asked “what will our partners actually see?” and wants the rules, not a screenshot.Everything else in these docs is written from your side of the program. This page is the other side: what a partner lands on, what is hidden from them without you configuring anything, what one of their colleagues sees of their work, and which setting decides each of those. It is the question that comes up in every demo and every security review, and the answer is a model with only a few moving parts.
What you’ll achieve
A precise mental model of the partner’s view: the three boundaries that are always enforced, the one visibility choice you actually make, and where each decision lives. Enough to answer a partner’s IT team, or your own, without guessing.What a partner needs on their side
Nothing you have to buy, install, or migrate for them.
What they do need is a work email address that you have given access to, which is the whole onboarding step.
See Invite partners and their teams.
The three boundaries that are always up
These are not settings. They hold before you configure anything, and there is no switch that opens them.- One partner never sees another partner. Partner-level isolation is enforced on every partner-facing read, independently of segments, experiences, and permissions. Two resellers on the same experience, looking at the same tab, see their own pipeline and nothing of each other’s.
- A record that is not shared with them does not exist for them. Partners see the CRM records attributed to them, plus what you deliberately share on a record. Your direct pipeline is not filtered out of their view, it is never in it.
- Only the fields you open are visible, and fewer are editable. A field must be made visible on the embed before it can be made editable, and anything you have not opened stays hidden or read-only. See Set up a reseller pipeline.
gmail.com address can never inherit a partner’s access.
Inside one partner: who sees whose records
This is the one visibility question that is genuinely yours to decide, and it is the one most programs get asked about first. When several people at the same partner have portal access, either they all see everything shared with their company, or each sees only what they are a collaborator on.
Notifications follow the same line, so a contact is never emailed about a record they cannot open.
You set the baseline organisation-wide and override it per segment.
Where a contact matches several overriding segments, the most permissive one wins: one segment granting See all shared records is enough, and the others do not have to agree.
See Create a dynamic segment and Layer segments to progressively unlock.
The same cascade carries Invite colleagues, which decides whether a partner can bring their own coworkers in rather than asking you.
What decides everything else
Six controls, each in one place.
Tiers change what a partner is entitled to rather than what they can technically reach, so use a segment, not a tier, when the intent is to hide something.
See Tiers.
Introw does not inherit your CRM’s sharing model
Worth being explicit, because it is assumed in most security reviews. Salesforce sharing rules, HubSpot teams, and record-level CRM permissions govern who inside your company sees a record in your CRM. They do not carry over to partner-facing reads, because a partner is not a CRM user and no CRM licence is involved. Partner visibility is decided entirely by the model above: attribution, what you shared, the experience, segment permissions, and the fields you opened.What they see when they never open the portal
Partner adoption does not depend on the portal being opened, so plan for the partner who lives in their inbox.- Email carries deal movement, tasks, approvals, announcements, and course reminders, and a reply lands back on the record for everyone on it. See Every notification Introw sends.
- Slack and Teams carry the same signals into a shared channel, where a partner can register a deal without opening anything. See Channels.
- Their own CRM card and assistant put your shared deals inside their stack, for the partners who want that. See Partner Connect.
Whose brand they see
Yours, on every surface a partner touches. The portal takes your logo, colours, and fonts; the address can be a domain of your own; and notification email can be sent from your own domain. One honest caveat: partner-facing surfaces carry a small “Powered by Introw” mark unless you have the white-label add-on, which removes it from the portal, forms, the asset library, and generated certificates. See Branding, Custom domains, and Email domain.Check it yourself
The honest test is to look at a real partner’s portal rather than an editor preview.1
Preview as a specific partner
In the experience builder, Preview lists the partners on that experience and opens the one you pick in a new tab, rendered with their pipeline, tasks, tier, and assets.
It shows the published state, not your unsaved draft.
See Draft, publish and preview.
2
Keep one partner as your test partner
Give an internal address portal access on a copy of the experience and use it as the account you sign in as.
It is the only way to see the login, the emails, and a collaborator-only view exactly as a partner does.
3
Confirm the two answers you will be asked for
Open a deal as that partner and confirm only the fields you opened are editable.
Then check a second contact at the same partner sees what your See all shared records decision says they should.
Troubleshooting
A partner says they cannot see a deal that is theirs
A partner says they cannot see a deal that is theirs
Check attribution on the record first: an unattributed deal is invisible to them by design.
If attribution is right, check whether their contact is collaboration-restricted and simply is not a collaborator on that record.
A partner sees a tab that is empty
A partner sees a tab that is empty
The tab is on their experience but the section behind it has nothing for them, which is what previewing as that specific partner is for.
See Every portal section.
One contact at a partner sees more than another
One contact at a partner sees more than another
They match different segments, and the permission cascade resolves most-permissive.
See Layer segments to progressively unlock.
A partner contact cannot sign in at all
A partner contact cannot sign in at all
Portal access is off on the contact, or the CRM property that drives access does not have the value you mapped.
See Set up portal access.