V5 Ultimate
Module · Customer Portal

Customer portalyour customers and their auditors, self-served.

A branded portal where your customers see only their orders, their lots, their CoAs and their pack docs. Their auditor logs in to see the same view, read-only, with no email chain.

Start free — no card
Secure sign-in · scoped to their account · 21 CFR Part 11 · ISO 9001

Stop emailing PDFs. Give your customers a window.

Customer service spends hours every week answering "where's our order?", "can you resend the CoA?", "what lot was in the shipment?". The V5 customer portal answers all three in real time — under your brand, your domain, your terms — and never leaks a row that isn't theirs.

−80%
Inbound CoA tickets, month one
2 clicks
From shipment to source BMR
0
Cross-tenant rows reachable
Forever
Audit log of every view
What your customers actually see

One secure sign-in, everything about their account in one place

Your customer's nominated contacts sign in to V5 Ultimate and land on a tabbed dashboard scoped to their account — orders, shipments, on-hand inventory, quality documents, complaints and integrations. They never see another customer's data, your costs, or your internal workflows.

  • Tabs for Overview, Orders & shipments, Inventory, Quality, New complaint, Integrations and Help
  • Filter orders by status — draft, confirmed, picking, packed, partial, shipped, closed, cancelled
  • Footer reminds them it's running on a 21 CFR Part 11 & ISO 9001 platform
  • You can "View as customer" from the admin side to see exactly what they see
app.v5ultimate.com/portal
V5
Customer Portal
Orders & shipments
Every sales order on your account, with shipment status and links to per-lot traceability.
StatusLast 30 days
DRAFTCONFIRMEDPICKINGPACKEDPARTIALSHIPPEDCLOSEDCANCELLED
SO-2026-3318 · 12 linesSHIPPED · Jun 18
SO-2026-3307 · 4 linesPICKING
SO-2026-3284 · 7 linesCLOSED
Running on V5 Ultimate — secure customer collaboration.
21 CFR Part 11 · ISO 9001
Customers
Cornerstone Generic Distributors
Admin view
AddressesDetailsContactsReport accessPortal inventoryShipping prefs3PL billing
Multiple contacts per customer, with per-role defaults that drive PO / SO / notification routing.
Cornerstone Generic Distributors
Primary · purchasing@cornerstonegen.com
ACTIVE
Marco Bianchi
AP Specialist · Accounts Payable · ap@cornerstonegenericdistributors.com
ACTIVE
Priya Raman
Buyer · Purchasing · purchasing@cornerstonegenericdistributors.com
ACTIVE
You decide who gets in

Invite the right people, give each the right access

Every customer record holds as many contacts as you need. Tag each one with a role — buyer, AP, QA, receiving — and invite them to the portal in one click. Roles drive what they see and which notifications they receive, so AP only gets invoices and QA only gets CoAs and complaints.

  • Unlimited contacts per customer, archive without losing history
  • Per-role notification routing for orders, shipments and quality
  • One-click "Invite" sends a secure activation link
  • Revoke or re-activate access any time
Scoped exposure · zero spillover

They see exactly what you expose. Not one row more.

Row-level security scopes every query at the database — not in application code, where a single missed WHERE can leak the whole multi-tenant table. There is no admin button to override it.

What they see
  • Open orders, promise dates, in-progress batches
  • Shipment ETAs and carrier tracking
  • Lots & serials shipped to them — only theirs
  • CoA, SDS, allergen, kosher / halal certs by SKU
  • Recall notifications scoped to their lots
  • Their own POs, contracts, terms
What they don't see
  • Any row of any other customer — enforced at the DB
  • Your COGS, margin, supplier names or prices
  • Internal deviations, CAPAs, non-conformances
  • Your other lots, batches or WOs
  • Operator names or kiosk-level activity
  • Anything your tenant admin hasn't ticked 'expose'
What you control
  • Per-document expose toggle (CoA yes, deviation no)
  • Per-customer feature flags (trace, portal API, SMS)
  • Per-user role within their own org (admin / viewer)
  • Auditor read-only role with scoped one-time token
  • Quiet-hours and channel preferences per recipient
  • Audit trail of every view, download, attempted access
Two-click trace · forward and back

Customer pastes a lot. Portal returns the chain. Scoped to what they're entitled to see.

1
Customer pastes the lot they received

LOT-PA4-26-0218 · ‘arrived June 4, our QC needs the CoA + source batch’

2
Portal returns the forward trace, scoped

Shipment SHP-22914 → Pack-out WO-PCK-44182 → Bulk WO-MFG-44159 → BMR-44159.v3 → CoA-B44871 (signed)

3
One click opens the CoA, byte-identical to release

Rendered from the immutable eBMR snapshot. Original SHA-256 verified. ‘Re-issued 2026-06-04’ stamp.

// portal trace result · scoped to customer NORTHVALE-PHARMA
shipment SHP-22914 · shipped 2026-06-02 · UPS 1Z9V8… delivered
pack WO WO-PCK-44182 · 12 cases · serials SR-{}
bulk WO WO-MFG-44159 · 220 kg blend · operator REDACTED
BMR BMR-44159.v3 · signed 2026-06-01 by QA-12 · SHA-256 ✓
CoA CoA-B44871 · 14 specs · all within range
deviation DEV-44159-02 · not exposed (internal-only)
CoA · CoA-B44871
SHA-256 ✓ matches release snapshot
SpecRangeResultPass
Assay98.0–102.0%99.4%
Moisture≤ 0.50%0.31%
pH (10% sol.)5.5–7.56.2
Heavy metals≤ 10 ppm< 2 ppm
TAMC≤ 1000 cfu/g12 cfu/g
E. coliabsent / 10gabsent
Released by QA-12 · 2026-06-01 14:22 · Part 11 e-sig ID 0x8F…
Re-issued to portal · 2026-06-04 09:17 · viewer m.tan@northvale
The document never drifts

The CoA they see in 2028 is byte-identical to the one you released today.

The portal does not render from a separate template engine that can change between then and now. It renders from the immutable eBMR snapshot taken at release — the same snapshot QA signed. A re-issue stamp makes clear when they re-pulled it; the underlying record is hash-verified.

  • Renders by SKU, lot, serial, shipment, or PO
  • SDS, allergen, kosher / halal, organic — same snapshot model
  • 18-month-old CoA? Same document, plus a re-issue stamp
  • No 'we couldn't find the CoA we sent in 2023' findings
Their auditor logs in. Same data. Read-only.

The email chain that used to take a week is now a link.

One-time token · scoped to one audit run
POST /portal/auditor-invite · audit=AF-2026-0188 · expires 14d
→ portal.northvalepharma.com/audit-invite/{tok-9f8a…} · auditor: BSI · email m.foster@bsi.com
View · BMR-44159.v3, CoA-B44871, lot LOT-PA4-26-0218 — read-only
Attempt · view DEV-44159-02 → BLOCKED · not in scope
Submit · audit run AF-2026-0188 complete · token auto-expired
Scoped to one run

Token authorizes one audit, not the workspace. Expires by date and on submit.

No per-seat licence

Customer auditors and 3rd-party regulators don't need an app account.

Same audit trail

Every view, every blocked attempt, every signature is logged with full context.

Findings → CAPA

An auditor fail still auto-opens a finding and a linked CAPA on your side.

Push · order PO-2026-3318 entered QC release · 14:22
CoA-B44871 signed by QA · auto-emailed to your buyer + visible in portal
View · m.tan@northvale viewed CoA-B44871 · 14:24 · audit-logged
ETA changed · SHP-22914 now ships Jun 19 (was Jun 18) · SMS sent
Attempted access · cross-customer lot · BLOCKED · access denied logged
Recall notice · lot LOT-PA4-26-0211 · sent to 3 affected customers only
Live notifications · live delivery audit

Every view, every download, every blocked request — audited.

When a customer's auditor asks "who saw that CoA, when?" you answer in three clicks. Cross-tenant access attempts are recorded too — useful evidence that your isolation works. Channel preferences live per recipient: email, SMS, quiet hours per timezone, one-click opt-out.

Shipment dispatched
Email + SMS
ETA changed
SMS only
CoA available
Email
Recall notification
Email + SMS + portal banner
REST · webhooks · same auth model as the UI

Customers who want to wire your data into theirs don't need a meeting. They need a key.

# GET orders for THIS customer only
curl https://portal.northvalepharma.com/api/v1/orders \
  -H "Authorization: Bearer pk_live_…" \
  -H "Accept: application/json"

# 200 OK
[
  { "po": "PO-2026-3318",
    "status": "in_production",
    "promise_date": "2026-06-18",
    "lots": ["LOT-PA4-26-0218"] },
  { "po": "PO-2026-3307",
    "status": "qc_release_pending",
    "coa_url": "/api/v1/coa/CoA-B44871" }
]
# Webhook · signed, replayable, idempotent
POST  https://erp.northvalepharma.com/v5-hook
X-V5-Signature: t=…,v1=…
Content-Type: application/json

{ "event": "shipment.dispatched",
  "id":    "evt_2026_06_02_44918",
  "shipment": {
    "id":   "SHP-22914",
    "po":   "PO-2026-3284",
    "carrier": "UPS",
    "tracking": "1Z9V8…",
    "lots": ["LOT-PA4-26-0218"]
  } }
Scoped per customer

Same RLS as the UI. A key cannot see another tenant.

Rotatable + revocable

Generate, rotate, scope, revoke — all in the portal admin.

Webhook retry + DLQ

Failed deliveries retry with backoff; dead letters surface.

OpenAPI spec

Hand it to their dev team. Done in an afternoon.

Who logs in

Three of the most common customers, one portal model.

−80% tickets
Distributor

Stops calling for CoAs — pulls them by lot from the portal. 80% drop in inbound 'where's my doc' tickets in the first month.

Seconds, not days
Retailer / brand auditor

Branded portal with the manufacturer's logo. Retailer QA sees only their lots. Trace queries answer in seconds, not days.

Zero spillover
DTC brand owner (co-man relationship)

Brand owner sees their batches, certificates and compliance state. Cannot see other customers of the same co-manufacturer.

What happens when…

Edge cases your compliance lead asks about.

Situation
Customer wants their logo on the portal
BehaviourWhite-label is per-tenant: logo, primary colour, subdomain. Branded email goes from a customer-friendly from-address — set up by you, no support ticket.
Situation
Customer asks to see a competitor's lot
BehaviourRow-level security scopes every query to the customer's own data. There is no admin button to override this. Cross-tenant attempts are logged.
Situation
Customer needs an old CoA from 18 months ago
BehaviourCoA renders from the immutable eBMR snapshot — the document is byte-identical to the one they got at release, plus a clearly stamped re-issue date.
Situation
Customer's auditor needs access for one week
BehaviourIssue an auditor invite scoped to one audit run, expiring on a fixed date and on submit. Read-only. No app account, no per-seat licence.
Situation
Customer churns
BehaviourTheir portal access is revoked instantly; their data stays in your tenant; the audit trail of who viewed what stays intact for retention purposes.
FAQ

The questions always come up.

Is the portal a separate product?

No — it's a view on the same database, scoped by row-level security. The documents customers see are the live documents in your QMS, not exports that drift out of sync.

Can customers download data via API?

Yes — a scoped REST + webhook API per customer for orders, shipments, CoAs and trace queries. Same auth model as the UI: a customer key cannot reach another tenant's row.

How is this different from emailing PDFs?

PDFs in inboxes are lost in hours; portal access is queryable forever, signature-verified, and audit-logged. Findings like 'we couldn't find the CoA we sent in 2023' disappear.

Do we own the customer's portal data?

Yes. The portal is a view on your tenant. If a customer churns, their access is revoked; the data stays with you, including the audit trail of every view.

Your brand. Their window. Your audit trail.

A read-only window for every customer and every auditor — branded, isolated at the database, audit-logged forever.

Engineered on
21 CFR Part 11 e-signatures
Immutable audit trail
Multi-tenant RLS isolation
GS1-128 license plates
Two-way ERP adapters
Instead of an FAQ

Just ask V5 — it knows the product cold.

Pick a question or type your own. V5 answers grounded in how customer portal — orders, traceability, certificates, notifications | v5 ultimate actually behaves on the floor.

Got questions, or want to see it on your shop floor?

Ask V5 — our code-aware assistant — or spin up a workspace. Both are free.