Skip to content
Van Oosten Advies B.V.

Last updated: September 21, 2026

Portal customer switches in CustomerGate 365

A buyer who purchases for two companies of the same group signs in once and switches between the two in the customer portal. Portal Customer Switches is the log of every attempt to move a session to another customer, granted and refused. You open this list to see the refused rows, which is why it is sorted that way by default.

What this is for

Two companies of one group, one buyer, one e-mail address: in the trade that is the ordinary case. The app always allowed it, because a portal user is the pair of an e-mail address and a customer, and each link has its own role. The same person can be a Buyer at one company and a Viewer at the other. What was missing was the way to switch between them within one session.

Link Another Customer

Linking is done by inside sales, with Link Another Customer on the portal user card, in the client. There is no web service for it: who may reach which company should not be something a website can arrange for itself.

  • The action first asks for the customer from the customer list and then for the role of that link.
  • The confirmation names both companies with their number and name, and says what the person will see afterwards: the quotes, orders, shipments, invoices and documents of both. A question that only asks whether you are sure gets clicked away; this one does not.
  • If the address is already linked to that customer and active, the action is refused. If the link was revoked, you are asked whether to restore it.
  • An anonymized address no longer identifies anyone, so no second company can be hung on it.
  • There is no second link table. Portal Users is the link table, with its own erasure, cleanup and export; a second table with the same fields would one day grant access the first had revoked.

The active customer lives on the session

Which customer is active right now sits on the session row in Business Central, not in a cookie at the website. That is the whole security of the feature: the website cannot decide whose data it sees, it can only ask to switch to a customer that Business Central can confirm is linked to the signed-in address.

  • The link must exist, be active and not be anonymized.
  • The customer must be allowed in the portal: not Privacy Blocked and not blocked for All.
  • The role of the new session comes from the link that was switched to, not from the session it came from.
  • After a refused switch nothing has changed. The session still reads the data of the customer it was on; there is no half-completed switch.

The log

Attempted At
When the attempt was made. The newest are at the top.
Outcome
How the attempt ended. See below.
E-mail Address
The portal user who tried to switch.
From Customer No.
The customer the session was on before the attempt.
To Customer No.
The customer number the website asked for. This is what was sent, not what exists: a number that matches no customer is exactly the row worth looking at.
IP Hash
A pseudonymized hash of the IP address the attempt came from. Several refusals with the same hash are one person trying; many different hashes are something else.

Show Refused Only puts the filter on, Show All takes it off. Nothing here can be changed and nothing can be deleted, not even by an administrator: a log you can take rows out of is not a log.

The four outcomes

Switched
The switch succeeded. A buyer moving from one company to the other ten times a day is an ordinary day.
Not Linked to This Customer
The session's address has no link to that customer number. This is the suspicious one of the four, because that number came from somewhere and not from us. These rows turn red.
Link Revoked
The person was allowed in once. Usually a colleague who left and whose access was switched off, or somebody clicking on an old tab.
Customer Not Allowed in the Portal
Blocked for All, or Privacy Blocked. Not an attempt at anything, but the consequence of a choice on the customer card.

The website is only ever told that the switch was refused, without a reason: an endpoint that says why something is not allowed thereby says that a customer number exists, or that an address was once linked to it. Here the balance falls the other way, because here sits a person who has to be able to look into it.

Reading a run of refusals

One refusal says little; somebody clicked on an old tab. What you are looking at is a run. Not Linked to This Customer on customer numbers that have nothing to do with each other is somebody probing which numbers exist, and the same IP hash next to them means it is one person. Link Revoked on one address usually means a colleague has simply left and a tab is still open somewhere. Customer Not Allowed in the Portal is almost always a block on the customer card that nobody connected with the portal.

Privacy

After the retention period the cleanup job takes the e-mail address and the IP hash out of the row. The two customer numbers, the moment and the outcome stay: once the address is gone, that row is about two companies, and where access to another company's data is concerned that is the trace that should outlive the person in it.

The log is part of Export Personal Data on purpose. It is the only place where it is written down that somebody tried to reach another company's data, and that is exactly the sort of thing a data subject has a right to see.

Related help

  • Portal Users

    Who may see which customer's data, and revoking that access.

  • Account Requests

    Requests for a portal account: select the customer, choose a role, approve.

  • Privacy tools

    Retention, the cleanup job, and export or erasure per e-mail address.