Skip to content

Vendor external portal

StageEstimated
StatusDeferred
Design statusIn review
Estimate3w (L)
ConfidenceLow
LinearPIN-108 ↗ PIN-520 ↗
Linear statusBacklog
CycleC15-C16
DesignDesign ↗
Linear epicProcurement, Vendors & Compliance
ModuleVendors ↗

Design — canon pending

No design canon yet, and the surface still needs scoping (see Notes / Open question); routed to Conor / design — not backend-only.

Priority: Low

Scope

Two narrow, token-based external-facing surfaces (not a full logged-in vendor portal): a public no-auth upload page where a sub submits an insurance certificate against a token link, and a project-side Share action where a PM picks files/drawings and generates a read-only, expiring, no-login link to send to outside vendors. (Source: PIN-108, PIN-520.)

Acceptance criteria

  • Public route (outside auth), reached via a per-org token link; validates the token (exists, not expired, not already used)
  • Upload page shows the project + org name and required policy types; friendly error page for an invalid/expired token
  • Certificate upload plus a metadata form (carrier, policy number, effective/expiry dates, limits)
  • Submitting creates a document linked to the insurance record and triggers the compliance check, then shows a confirmation
  • Separately: PM multi-selects project files/drawings (per-folder select-all) from the project's Documents tab
  • Generates a read-only, expiring, no-login share link for the selected files; preview before sending; copy-link action

Conor's comments

Needs to be scoped properly

Notes

Net-new; a share link can currently expose internal docs. PIN-108 (external sub upload portal, Backlog) and PIN-520 (Project Share tab — expiring links to outside vendors, Backlog) are the closest Linear coverage, but both are narrower than this page's full logged-in vendor-portal vision — flagging for review; a broader ticket may need to be opened.

Open question for Conor

Confirm what a vendor should and should not see