# The client panel from the inside

Canonical URL: https://thorfyn.com/en/notes/the-client-panel-from-the-inside

> Who approves a release, what stays on record and how long each access lasts, read from the code that runs, with the file behind each number.

Who approves a release, what stays on record and how long each access lasts, read from the code that runs.

- Running system
- Written by Matheus Pavaneli (https://thorfyn.com/en/about)
- Published Oct 8, 2026
- Reviewed Oct 8, 2026
- 1 min

## Two ways to approve

Each client chooses who decides. In client mode a release waits for the client's own approval, and the admin cannot publish without it. In house mode the admin approves and publishes, and the client cannot publish.

## How a client gets in

There is no self sign-up. The admin creates the client and the invite. The invite works once, and its token is kept only as a hash.

**7 days** — life of a single-use invite. Only its hash is stored. (how to check: `packages/portal/src/invites/inviteStore.ts`, `INVITE_LIFETIME_MS`)

After that the client signs in by a link sent to the e-mail, with no password, and a passkey is offered after the first access.

**15 min** — life of the sign-in link sent by e-mail. (how to check: `apps/portal/src/auth.ts`, `MAGIC_LINK_SECONDS`)

## What stays on record

Activity is append-only: the database refuses to change or delete a line, and each record carries a protocol number.

## See how the house protects access

The security page lists each claim with the file that proves it.

- See the security page: https://thorfyn.com/en/security
- Next note: https://thorfyn.com/en/notes/the-exit-package
- Questions and requests: hello@thorfyn.com
- Back to the home page: https://thorfyn.com/en
