Flagship Offering

Self-Service Portals

A governed external portal that lets your members, partners, and customers self-serve.

Modern laptop displaying a secure self-service portal interface with progress steps and status dashboard, overlaid with soft holographic security and data-flow elements in a clean professional setting

A self-service portal is a secure external website — built on Microsoft Power Pages or Azure, where your customers, members, distributors, or partners can log in and do things themselves: submit requests, check status, manage their data, and find answers. Some journeys need an authenticated account, some are better as a secure anonymous submission, and some start with one of your own reps. Kumo designs, builds, and governs portals that handle all three and survive enterprise security review.

Why organizations build portals

Most start the same way: a team buried in external email (client requests, vendor onboarding, member updates) with a spreadsheet or shared inbox standing in for a real system. A governed portal replaces that with structured self-service, and the data lands in Dataverse where your team, and eventually your AI, can use it. Client, vendor, member, or internal, the pattern holds and the architecture scales from a single team up to enterprise multi-portal suites.

What a portal actually does

“Portal” hides the real work. The capabilities that carry the load:

  • Guided intake: staged forms with inline validation, save-and-resume, and review before submit.
  • Document upload: files attach to the record, not an email thread.
  • Bulk entry: many records or line items at once, validated row by row.
  • Identity and fraud verification: automated checks before access is granted.
  • Status visibility: applicants and staff see the same record, so “where is mine?” stops being a phone call.
  • CRM and ERP integration: the portal writes into the systems you already run.

Self-service or assisted

Self-service is the default, not the only path. A user can start on their own, or one of your team can start it for them and hand it off securely. Either way it lands in the same record, under the same validation and audit trail. One process to govern, two ways in.

What makes a portal succeed

Three things, in order: the data model (get Dataverse right and the rest follows), the security model (external access the CISO signs off on), and the first journey (launch with the workflow that hurts most, not all of them at once).

Value

Why it matters

One front door for external parties

Requests, onboarding, documents, and status checks move out of shared inboxes into a single governed experience your team controls.

Onboarding that takes days, not weeks

Guided intake and inline validation get customers, vendors, or members set up faster and with fewer errors. In one enterprise rollout that meant onboarding dropping from 12 to 18 days down to about five.

Fewer bad actors, caught earlier

Automated identity and address verification screens every submission before an account exists, so fraud and duplicates are stopped at the door instead of found later. One deployment blocked 100+ fraudulent applications in its first ten weeks.

Volume without added headcount

Self-service and bulk entry let a portal absorb spikes that would otherwise bury a team in manual work. One rollout processed 700+ submissions through the same governed pipeline.

Governance that passes review

Authentication, role-based access, and auditability are designed in from day one, not bolted on after the security team objects.

Two ways in, one process behind them

A user can start on their own, or your team can start it and hand it off. Either path lands in the same record, under the same validation and audit trail.

Approach

How it works

1

Map the foundation

We work through the details, determining what types of users, what workflows we want to facilitate, and the data and security architecture to make it work.

2

Build and pilot

A working portal in front of real external users early, refined in weekly cycles.

3

Operate and extend

Post-launch support, adoption tracking, and a backlog path for the next capability.

Inside the build

What it actually looks like

Screenshots from production work Kumo built and runs. Client branding and customer data are redacted.

Behind the portal, every application runs through automated checks: email verification, name verification, existing-account matching, and address verification, so staff review clean data instead of chasing it.
A guided, multi-step intake collects exactly what's needed at each stage, starting with primary contact details, so applicants never face one overwhelming form.
Structured fields with built-in validation capture business, address, and billing details correctly the first time, replacing back-and-forth email and manual spreadsheet entry.
Dropdown-driven inputs standardize how business type, structure, and category are recorded, keeping the data clean for downstream systems and reporting.
FAQ

Questions we hear a lot

What is a self-service portal built on Power Pages?

It is a secure external website running on Microsoft Power Pages, connected to Dataverse data inside your own tenant. External users authenticate, see only the data their role allows, and complete tasks that previously required emails or phone calls to your staff.

How long does a portal project take?

A first working portal is typically live in front of pilot users within a few months, with capability added in releases after that. Scope drives the timeline — the fastest path is starting with the one or two journeys that generate the most inbound email today.

Do portal users need Microsoft licenses?

No. External users authenticate through Power Pages' own identity options — including Entra External ID or local accounts — and are licensed through Power Pages capacity, not per-seat Microsoft 365 licenses.

Can a sales rep start an application on a customer's behalf?

Yes. A rep can open an application in the back office and share it with the customer, who receives an email containing a unique application key. Entering that key plus a one-time passcode sent to their address opens the in-progress application — no account setup required. Work is saved for up to seven days, so the customer can leave and come back without starting over.

How does a portal prevent fraudulent submissions?

Verification runs automatically on every submission, before an account is ever approved. The portal checks that the email address is real and reachable, verifies the applicant's name, matches the submission against existing accounts to catch duplicates and impersonation, and validates the business address — flagging residential addresses on business applications. Results are written to the record so staff review exceptions rather than every application.

Can external users submit without creating an account?

Yes. Not every journey should require a login. The portal supports secure anonymous submissions for one-time intake alongside authenticated access for high-volume users who need order history, saved lists, and status tracking. Which model applies to which journey is a design decision we make with you.

Can users upload documents and submit multiple records at once?

Yes. Applicants can attach supporting documents directly to a submission, and bulk or multi-record entry lets a user add many rows — facilities, locations, or line items — in one pass, with automated validation applied to each. The final step is a review-and-submit screen that shows everything captured before the applicant signs.

Can a portal integrate with our existing CRM or ERP?

Yes. Dataverse connects natively to Dynamics 365, and integration with other systems happens through Power Automate, Azure Functions, or direct APIs — the portal becomes the front end of the systems you already run.

Sound like your situation?

Start with a free Envisioning Session — one hour of strategic ideation tailored to your goals.

Book an Envisioning Session