Foundations

The affiliate portal from the program manager's side: access, control, and what stays private

The partner portal seen from the other side of the glass — how you grant and revoke access, give several people at one partner their own logins, preview the portal as any partner to troubleshoot, and enforce the wall that keeps your economics invisible.

A partner sees the affiliate portal as their space — offers, links, numbers, statements. From the program manager's side it is something else entirely: a controlled surface where you decide who gets in, what each person can reach, and where the wall sits between what a partner may see and what they never can. The partner-side tour covers the experience partners get; this guide is about the other side of the glass — the access model, the controls, and the privacy boundary that let you invite partners freely without ever exposing your program's internals.

Access is granted, not self-claimed

The first design decision worth understanding is that portal accounts are created by you, not signed up for by the public. There is no open registration where anyone can create a login and start browsing your offers. A partner gets access because you added them and chose to invite them — which means your catalog, your rates, and your program's shape are never visible to a stranger who happened to find a signup page. This is the right default for a business relationship: access follows a decision.

In practice, inviting a partner is a byproduct of onboarding them. When you add a partner with a contact email, you can send their login invitation on creation, or invite them later once the relationship is ready. A clear status on each partner tells you exactly where they stand — no login yet, invited, or active — so you always know who can actually get in. The broader mechanics of adding and organizing partners live in the add and manage affiliates guide.

Several people, one partner

A partner is often not a single person. A media-buying team, an agency, or a sub-network might have three or four people who each need to sign in — a media buyer, an accounts person, a manager. A mature portal handles this without forcing everyone to share one password: each contact on a partner's record can be given their own independent login. Every one of those logins signs in as the same partner and sees the same portal, but you manage each person separately — provisioning access, resetting a password, or resetting multi-factor authentication for one individual without touching the others.

This matters more than it first appears. Shared credentials are a security liability and an offboarding nightmare; when the media buyer leaves, you want to cut their access, not force the whole partner to reset. Per-person logins make that clean.

Seeing the portal as a partner

The most useful support tool a program manager has is the ability to open the portal as a specific partner and see exactly what they see. When a partner says "I can't find my link" or "my creative is missing," describing the problem over email is slow and error-prone. Stepping into their view resolves it in seconds, because you are looking at precisely the same screen they are.

A well-designed version of this feature has a few important properties. It works whether or not the partner has ever logged in, which makes it a way to preview what a new partner will see before you send their invite. It is limited to administrators, not general staff. It is time-limited and recorded — the session shows up in your activity log and on the partner's own history — so acting on a partner's behalf is never invisible. And critically, it never touches the partner's own credentials: you are viewing as them, not logging in as them. Powerful, but accountable.

What a partner can reach

Inside the portal, a partner works with a deliberately narrow set of things: the offers they can promote, the tracking links they build for those offers, the creatives attached to them, their own performance, their conversion notifications, and their statements. Two access ideas shape the offer experience.

The first is the split between offers a partner already runs and offers they could apply to run. Some offers are open to everyone; others are private, visible only after you approve a partner for them. A partner can browse the promotable catalog and file an application for a gated offer, which lands on your approvals queue — the same queue that governs new-partner sign-ups and pixel submissions, covered in the approvals guide. You decide; the partner sees the outcome reflected on the offer.

The second is that creating a campaign for a partner grants access automatically. When you pair a partner with an offer directly, that offer simply appears in their portal — no application, no approval step on your side. This gives you two clean paths to access: open the offer for application, or provision it directly by creating the campaign.

Creatives, delivered clean

The portal is also how approved assets reach partners. Rather than emailing banners and hoping the partner uses the current version, you publish creatives against offers and the portal gathers them for each partner automatically. Where you have prepared a creative's links for tracking, the partner can download a copy with their own links already embedded, so the asset is ready to run with correct attribution and no manual link-pasting. The full workflow for preparing and publishing assets is in the creatives guide.

The wall that makes it all safe

Everything above rests on one boundary, and it is worth stating plainly: a partner never sees your economics or another partner. The portal reports payout — what the partner earns — and nothing about what an advertiser pays you, your margin, or your profit. It shows the partner their own traffic and their own conversions, never another partner's offers, links, stats, or contacts. And it hides offers you have not made visible, so a private offer stays private until you grant access or create a campaign.

This separation is not a set of settings you have to remember to switch on for each partner. It is enforced by the role the partner's login carries. That is the whole point: because the wall is structural rather than configured, you can onboard partners quickly and generously, confident that none of them can reach across it. A program that had to hand-configure privacy per partner would either move slowly or eventually make a mistake; a program where the boundary is built into the login does neither.

Onboarding a partner in practice

Put the pieces together and onboarding a new partner becomes a short, repeatable sequence rather than a scramble. You add the partner and, when the relationship is ready, send their invitation. If several people on their side need access, you provision a login for each contact rather than handing round a shared password. Before the invite even goes out, you can preview the portal as that partner to confirm they will see the right offers and creatives — catching a missing asset or an unpublished offer while it is still your problem to fix, not theirs to complain about. Then you either open the relevant offers for application or, more commonly, create the campaigns that grant access directly, so the offers are waiting for them the moment they log in. A partner whose first session is complete and correct — links ready, creatives present, numbers already tracking — starts the relationship trusting the program, and that first impression is worth more than any recruitment pitch.

This is also where the audit trail earns its place. Because invitations, access grants, and preview-as-partner sessions are all recorded, you can always reconstruct exactly who was given access to what and when — which matters both for your own peace of mind and for the day a partner or an auditor asks.

Why the control model matters

The access model is easy to overlook when you are choosing a platform, because it is invisible when it works. But it is exactly what determines how fast and how safely you can grow a partner base. Grant-based access keeps your catalog out of strangers' hands. Per-contact logins keep credentials clean as partner teams change. Preview-as-partner turns support from guesswork into a lookup. Campaign-based provisioning and an approvals queue give you two deliberate paths to access. And a structural privacy wall lets you scale without scaling your risk.

The partner experience and the program-manager's controls are two views of one system, designed to fit together. The partners feature overview shows how relationships, approvals, and access sit in one place, and a demo will walk both sides of the portal through on a real workspace with you.

See it on your own program.

Book a demo and we'll stand up your workspace, wire your tracking domain, and walk this through on your kind of data, with you.