Loading...
Help Center / Apps & Extensions / Portals FAQ

Portals FAQ

Portals FAQ

Answers to common setup and operating questions about Portals.
For what the app is and how to set it up from scratch, see the
Portals Overview.


Setup

Do I need to configure anything before the catalog shows portals?

No. Once Portals is enabled, the Catalog automatically lists every portal whose owning app is licensed for your organization. You do not need to register portals individually. If you license a new app that owns a portal, its portals appear in the Catalog the next time you open it.

Who can access Portals, and which tabs are admin-only?

Any user with Portals app admin status or Super Admin status can access all tabs. Without app-admin status, a user sees only the Dashboard and the Catalog. All other tabs are admin-only: Recovery Analytics, Traffic Analytics, Identity & Recovery, Security, Audit Log, Branding, Custom Domains, and Settings.


Day-to-day

Does Portals own each portal’s on/off toggle?

Yes. The Catalog is where you enable or disable individual portals. The owning app controls the licence: a portal only appears in the Catalog when its owning app is licensed. Licensing lives with the app; the on/off switch lives in Portals.

What does “Identity & Recovery” actually control?

Two business-wide settings. First, the rate-limit thresholds for the shared OTP and magic-link layer: the sliding window (default 60 minutes, accepts 1–1,440) and the maximum requests per identifier per window (default 5, accepts 1–100). Second, how long recovery audit records are retained before the nightly prune deletes them (default 180 days, accepts 7–3,650). Whether a portal uses a magic link or an OTP code is fixed by the owning app, not a Portals setting.

What’s the difference between Recovery Analytics and Traffic Analytics?

Recovery Analytics charts the OTP and magic-link flow — nightly rollups of requested, sent, consumed, failed, and rate-limited counts over 7, 30, or 90 days, with a per-portal breakdown. Traffic Analytics measures visitors — page views, unique visitors, sessions, bounce rate, device mix, and top pages across portals. One tracks how portal login recovery is performing; the other tracks who is visiting.

How do I set up portal branding?

Go to Portals → Branding. Upload your logo, set primary and secondary colours, choose fonts, and add header and footer text. Changes apply immediately to every portal that uses the shared branded layout. Turn on Enable custom HTML to add custom CSS or header/footer HTML. Click Revert to defaults to restore factory settings and remove all uploaded images.

How do I map a custom domain to a portal?

Go to Portals → Custom Domains and click New custom domain. Enter the hostname and choose its purpose (the full platform, a specific portal, or careers). A verification token is generated automatically. Publish it as a DNS TXT record at _mangoapps-verify.<your-domain>, then return and click Verify. Once verified, activate the domain to start routing traffic. TLS certificate provisioning and edge routing are handled by the operations team.

Is the recovery audit log sufficient for compliance reviews?

Every recovery event is logged with a timestamp, IP address, user-agent, and a SHA-256 hash of the identifier — never plaintext email or phone. Retention is configurable (default 180 days, minimum 7) and enforced by an automatic nightly job. You can export filtered results as CSV, capped at 10,000 rows per export. For SOC 2 or HIPAA-style reviews this is generally sufficient; confirm specifics with your compliance team.

Can I ask the AI agent about my portals?

Yes. The Portals agent lives in Ask AI and answers questions like “How is portal recovery doing this week?” or “Which portals are enabled?”. It is read-only and admin-gated — non-admin users never see its tools. Turn it off in Portals → Settings by disabling Portals AI Agent.


When something looks wrong

The most common causes: the email address entered does not match the one on file, or the request was rate-limited. An admin can check by opening Portals → Audit Log and filtering by the identifier. If the event shows Rate limited, the visitor must wait for the current window to expire before trying again. A Sent event with no Consumed event means the link was delivered but never clicked — check spam folders.

Why am I locked out of the portal even though I haven’t requested that many codes?

The recovery layer has two separate rate limits. The request side caps how many times you can ask for a code (default 5 per 60-minute window). The verification side caps wrong code entries: 10 invalid attempts within 15 minutes locks verification for that identifier. Both are visible in the Audit Log.

I keep getting “Invalid code” when I try to verify — what’s going on?

OTP codes expire after a period set by the owning app. If the code has expired, request a new one. If you have entered 10 or more incorrect codes within 15 minutes, verification is temporarily blocked. Wait 15 minutes and request a fresh code.

A portal I’ve licensed isn’t appearing in the Catalog — why?

The Catalog lists only portals whose owning app is licensed and enabled for your organization. Confirm the owning app is enabled in Admin → Apps Marketplace. Some portals may not be obvious: Guest Pass Check-In requires the Guest Pass app, Customer Support Portal requires Service Desk, and Candidate Portal requires Job Board.


Licensing and limits

Does Portals require a licence?

Yes. An administrator enables Portals from Admin → Apps Marketplace. It is disabled by default until then.

What are the limits I should know about?

Limit Value
Portals in the catalog 33 across 13 categories
Rate-limit window 60 minutes default (accepts 1–1,440)
Max recovery requests per window per identifier 5 default (accepts 1–100)
OTP verification attempts before lockout 10 within 15 minutes
Audit retention 180 days default (accepts 7–3,650)
Audit CSV export cap 10,000 rows per export
Logo upload PNG, JPEG, or WebP; max 2 MB
Background image upload PNG, JPEG, or WebP; max 5 MB
Favicon upload PNG or ICO; max 1 MB
Custom CSS Max 10,000 characters
Header text Max 500 characters
Footer text Max 1,000 characters
Custom header/footer HTML Max 50,000 characters each
Google Fonts available 20
Security window Default 24 hours (accepts 1–168)
Audit log page size 50 rows per page

More help

  • Portals Overview
  • Ask AI — the assistant answers Portals questions from these articles.