Product
Sharing findings without handing over the dashboard
PDF exports, share links, and client portals keep SlaySlop findings and next actions together without giving clients your dashboard login.
· by Henry Smith

I still default to screenshots when I am tired. Screenshots age badly and leak UI chrome you did not mean to share. SlaySlop's reports product copy is clearer than my habit: PDF exports, share links, and client portals keep findings and next actions together — no dashboard access required.
Agencies need that sentence during handoff. Clients need evidence. They rarely need your billing settings or unrelated properties sitting in the same sidebar.
Outcome you want
The client can open a portal or PDF, see categorized findings with next actions, and reply without you pasting passwords into email. Your dashboard stays yours. Their questions point at named checks like TLS configuration or Viewport configuration instead of "that red thing in your theme."
Boundaries
Share only findings from permissioned scans. Read-only observation underneath. Not a pentest report template that pretends to be offensive testing. Do not invent pricing in the portal narrative; point at the pricing page when commercial questions appear. Minimize personal data in exports. Do not paste WHOIS contact fields into a public case study.
Loading diagram.
Happy path I actually use
- Keep the client site connected under a workspace you manage.
- Triage findings internally first so the portal is not a jump scare of unsorted noise.
- Share a portal or PDF with the agreed audience.
- Attach owners and due dates in your PM tool, referencing check names from the glossary.
- Rescan after fixes and refresh what the client sees.
- At offboarding, remove shares the same week you remove repo access.
share_packet:
property: https://www.example.com/
medium: portal|pdf|share-link
includes: findings, evidence, next actions
excludes: billing, team seats, unrelated properties
environment_label: production# Habit check before you send anything
# Prefer portal/PDF over raw dashboard screenshots
ls ./exports/client-acme-2026-09-07.pdfWhy dashboards are a bad handoff gift
Dashboards invite curiosity clicks into settings you did not brief. They also create support load when a client toggles schedules or invites a contractor you have never met. Portals constrain the conversation to findings and actions. That matches how I want warranty calls to go: short, evidenced, boring.
Monitoring can continue underneath. Uptime probes and scheduled rescans tell you when something goes down or a fixed problem comes back. The portal is how the client sees outcomes without inheriting the control plane. If they need ongoing visibility, keep the share alive on purpose—not by accident through a shared password manager note.
Pitfalls
Emailing CSV dumps without context. Next actions exist for a reason. A spreadsheet of check IDs without owners is how tickets vanish.
One shared login for "the agency and the client." Offboarding becomes impossible. Audit trails become fiction.
Screenshots cropped to hide severity, then arguing later. Share the finding properly or accept the risk in writing.
Forgetting environment labels. Staging portals mistaken for production waste trust and burn a week of clarification.
Mixing multiple brands in one share "to save time." Clients notice. Counsel notices faster.
What I put above the fold in a share
Property hostname, scan time, environment label, and the top next actions with owners. Findings without owners become unread literature. Portals already keep findings and actions together; your process still has to name humans. I still reach for that boring header every time because it prevents half the follow-up email.
Screenshots as a last resort
If a portal cannot be used for some contractual reason, export a PDF first. If you must screenshot, crop to the finding and evidence, include the hostname and timestamp in the caption, and delete the image from chat exports after the ticket exists. I still reach for curl when I need a header snippet, but I do not pretend a header snippet is the full categorized report.
Multi-brand agencies
One portal per property beats one mega-share with filters nobody understands. Clients search their own brand name in email. Make the share title match that name and the production hostname.
Related next step
Soft links: Reports and portals, Monitoring, Website scanner. Soft close: when the client asks for access, offer a portal from SlaySlop before you offer a seat.