guide

Client Portals vs Workflow Orchestration Platforms: What Changes When External Parties Act Inside a Process

What changes when a client or supplier has to act inside your process, not just watch it? This guide compares four client portals with four orchestration platforms on how outsiders get in, whether you pay for them and what the audit log records, from vendor sources read 14 and 15 September 2026.

The Bottom Line: Choose a client portal when outsiders mainly exchange documents and check status; even Moxo, an orchestration vendor, wrote on 3 August 2026 that "There are lighter, cheaper client portal tools that will do the job" for that need. Choose orchestration when an outsider's action is a step with an assignee, a deadline and a record that has to stand up later, as Camunda 8.9 user-task docs and Moxo's Description of Services (both read 15 September 2026) describe. Two tests settle most cases: what the billing unit counts (in pricing pages read 15 September 2026, the portal products charged per plan, contact, request or internal member, Moxo AI charged per flow and Pipefy did not bill guests), and what the audit log calls the person who used a link.

A Portal Shows the Process; Orchestration Assigns a Step

The cleanest way to draw the line: in a portal the outsider pulls, and in orchestration the process pushes. A client portal gives an outside party a place to see documents and status and act when they get round to it. An orchestration platform gives that party a step with an owner, a deadline and a record, and chases them when it runs late. Moxo, an orchestration vendor, draws the same line on its blog: "Portals give external parties a place to access documents and status updates. They're interfaces, not processes." (3 August 2026). Portal vendors describe their own scope modestly: Content Snare's pricing page names its feature a "Simple client portal", and SuiteDash says its FLOWs sequences run "all within one linear interface" (both read 15 September 2026).

This guide compares four client-portal products with four orchestration platforms, from vendor sources read 14 and 15 September 2026. Only Moxo AI, not Moxo Classic, is covered. The mistake buyers make is treating this as a feature comparison. Once someone outside your company acts, it becomes a question of identity and accountability: how they get in, whether you pay for them, and what the record says they did.

How External Parties Get In, by Vendor

Nearly every product here offers some form of link-based access, and the differences hide in details few buyers read. In vendor documentation read 15 September 2026, stated link lifetimes run from Assembly's "three days or one use, whichever comes first" to Rocketlane's single-use token "valid for 7 days", and Moxo's Description of Services says "link validity is configurable". Configurable is flexible, and it also means someone on your side has to pick a number and defend it. The first four rows below are portals and the last four orchestration platforms; every cell comes from vendor documentation or pricing pages read that day, and "Not documented" means not found in those sources.

Product How an outsider gets in Link validity Account required External users billed Audit of external actions
SuiteDash Client login; Form Cannons email a form link Not documented Portal: "a unique set of login credentials"; Form Cannons: "no portal login required" No: "UNLIMITED Clients & Staff for all Plans" E-signature audit trail
Assembly Magic link, Google OAuth or password "three days or one use, whichever comes first" Active contacts sign in; e-signing needs "No logins" Counted as active contacts; no "per-client charges" "Audit log" on Advanced
Content Snare "unguessable link"; optional PIN code or account Not documented Not by default No: "Unlimited clients / recipients" Not documented
Rocketlane "Customer Login via Magic Link" Single-use token "valid for 7 days" Magic-link login No: "Unlimited customer members" Only "Financial Audit Logs" listed
Moxo AI Magic Link to a task, or branded portal dashboard "link validity is configurable" Magic Link: "no account required"; dashboard: passcode or SSO "Unlimited seats"; externals not documented "Audit log", listed under Scale
Pipefy Public form; tracking link by email Not documented No (article dated 13 July 2022) No: plans count "admins and members" Not documented
Kissflow Portal invitation; "Only Enterprise accounts can create portals" Not documented Portal user, activated if licences are available Conflicting (below) Not documented
Camunda 8.9 Public start form ("Camunda 8 SaaS only", "Tasklist V1 only") Not documented No: "eliminating the need for authentication" Not documented Not documented

Kissflow's docs conflict on licensing: the portal overview says "Portal eliminates the need to add external users to your Kissflow account", but invitees activate only if "there are available user licenses" (both read 15 September 2026). Ask before you invite a long list of suppliers.

Pricing Units Show Which Participant Is Counted

A vendor's billing unit tells you who it thinks the customer is. In pricing pages read 15 September 2026, four of the six products below do not bill outside parties, Assembly counts them as active contacts, and for Moxo AI their treatment is not documented.

Product Pricing unit Entry figure (15 Sep 2026) Outside parties
SuiteDash Flat per plan, "NOT per user" START $19/month Unlimited clients
Assembly Active contacts and internal users Starter $29/month billed annually or $49 monthly; 50 active contacts, 1 internal user Counted as active contacts
Content Snare Active requests and users Basic $35/month billed annually; 20 active requests, 2 users "Unlimited clients / recipients"
Rocketlane Internal team members Standard $49 per team member/month billed annually, minimum 5 "Unlimited customer members"
Moxo AI Flows per year Team "$500 /mo" or "$5,000/yr"; "100 flows/yr · $100 of AI/yr · Unlimited seats" Not documented
Pipefy Internal users Free Starter up to 10 users; Business "per-user billing" via sales Guests not charged

Moxo is the odd one out: it counts the process, not the people. Its pricing page, read 15 September 2026, lists magic links on Team but Branching, the Portals group and the Audit log under Scale, along with Triggers, Webhooks and REST APIs. At Team's "$5,000/yr", a team running 20 flows a year would pay $250 per flow (AutomationAtlas arithmetic). Per-flow pricing rewards a few rich processes with many participants and punishes a long tail of simple ones, which is roughly the split between orchestration work and portal work.

What Orchestration Adds When Outsiders Act Mid-Process

Orchestration documentation treats an outsider's action as a routed step with an assignee, a completion rule and a deadline. Moxo's Description of Services (read 15 September 2026) says "Roles resolve to real participants at Flow start", "Group assignments support completion modes (any one, all, or majority)" and "Steps can carry due dates with configurable reminders and escalation routing." Camunda 8.9 user tasks take assignee, candidateUsers and candidateGroups, plus dueDate and followUpDate. Pipefy's SLA rules, "Available on all plans" per an article dated 12 August 2026, can exclude holidays and set working hours.

Approval alone does not separate the categories, and vendors on both sides blur it. Content Snare lists an "Approval system" on its plans, with a rejected answer's status that "changes to Redo", and Rocketlane lists "Customer Approvals and Collaboration" (both read 15 September 2026). The sharper test is what happens when nobody acts.

Firsthand: synthetic Moxo AI runs

AutomationAtlas ran synthetic tests in Moxo AI; the test workspace is no guide to what the Team tier includes. In a synthetic job-intake-to-approval run on 14 September 2026, starting the flow required a person on every role, and the start dialog said external assignees "get a secure link by email, no account needed"; the task email reached an AutomationAtlas test mailbox. On 15 September 2026, the Approval step's "On rejection" control offered "Revise and resubmit", "Let the approver decide", "Run rejection steps" and "End the flow".

The most useful thing we saw was in the audit log. Moxo's log has an Actor column, and in synthetic runs on 14 and 15 September 2026 it labelled rows "AI Agent", "System", "Public link" or the person's name; 17 rows were read for one flow on 14 September. In the 15 September run the label followed the route rather than the account. The form step was assigned to AutomationAtlas's own administrator account, yet opening it through the task link was logged as "An external participant opened a magic link for the first time." under "Public link", while the same person's completion of the step was logged under their name.

That matters well beyond Moxo. A magic link authenticates an inbox, not a person: whoever holds a live link can generally use it, and the log can only record that the link was used. Moxo's labelling is candid about that. So when you evaluate any product in this guide, don't stop at "do you have magic links?" Ask what the audit log calls the person who used one, and what else ties the action to a named human.

"External Task" Does Not Mean an External Party

In Camunda, an external task is work handed to software, not to a person outside the organisation. Camunda 7.24's user guide says that with external tasks "the process engine publishes a unit of work to a worker to fetch and complete" (read 15 September 2026). Mix the two up in a requirements document and you will shortlist the wrong tool. Camunda 8.9's route for outsiders is a public start form, which "allows anyone to start a process", although "Public start forms are not available when using Tasklist V2 mode". Starting a process is not the same as acting inside one: no Camunda page read showed an unauthenticated outsider completing a later user task.

When a Plain Portal Is Enough

A plain client portal is enough more often than orchestration vendors would like, and Moxo, to its credit, says so on its own blog: "If it's linear and simple, basic tools work." (25 August 2025), and, for teams looking for "just a portal", "There are lighter, cheaper client portal tools that will do the job." (3 August 2026). The 2025 post continues "If it involves multiple parties, approvals, documents, and decisions, you need orchestration.", so these are vendor positions; no neutral study of the threshold was found. A practical rule of thumb: if an outsider's delay only hurts them, a portal will do. If it stalls your team or leaves a gap in a record you may have to defend, you need something that chases.

Selection Framework: What the Outsider Must Do Decides

Decide by what the outsider has to do, not by what the vendor calls its product.

Situation Category that fits Examples
Outsiders download, upload and check status; no decisions Client portal SuiteDash, Content Snare, Assembly
One reviewer approves or returns a client's answers Client portal with approvals Content Snare, Rocketlane
Cost must not grow with the number of clients Either SuiteDash, Content Snare, Rocketlane, Pipefy
A decision needs any one, all or a majority of a group Orchestration Moxo AI
Outsider steps need due dates, reminders and escalation Orchestration Moxo AI, Pipefy (SLA rules), Camunda (due dates)
Anyone outside must start a request without an account Orchestration public form Pipefy, Camunda 8 SaaS (Tasklist V1)
The audit record must separate human, AI and system actors Orchestration Moxo AI (observed 14 and 15 Sep 2026)
System-to-system automation built by engineers Neither (Moxo: "Moxo may not be a good fit", 3 Aug 2026) Camunda external tasks

Editor's Note: The most revealing row we recently read in Moxo's audit log was about our own admin account. A form step was assigned to that account, but because it was opened through the task link, the log filed the opening under "Public link", and only the completion carried the admin's name. Moxo recorded the route, not the identity. I think that is the honest choice, and a useful warning for anyone building processes for outsiders: a link proves access to an inbox, not who clicked. The same log labels AI work "AI Agent" and automated steps "System", so human, AI and system actions stay distinguishable in one record. — Rafal Fila, ShadowGen

Written & reviewed by Rafal Fila · Last updated:

Tools Mentioned

Related Guides

comparison

Moxo vs Zapier in 2026: Human Approval Steps, External Participants and Pricing

Moxo and Zapier both put a person in front of an automated decision, from opposite ends: Moxo builds the process out of human steps and attaches AI, while Zapier pauses an automation for a reviewer through its Human in the Loop app. This guide compares approvers, rejection, AI approval, audit logs, governance and pricing, verified 14 and 15 September 2026.

comparison

Keystroke vs n8n in 2026: Agent-Built TypeScript vs the Visual Canvas

Keystroke, launched in July 2026 by Y Combinator W24 company Sprint Labs, is a code-first automation platform where AI coding agents write workflows as TypeScript in the user's repository. n8n, founded in 2019, is the most widely deployed source-available visual workflow platform, with 200,000+ users and a $2.5 billion valuation. This comparison covers the agent-authored versus canvas building models, durable execution, licensing (Elastic License 2.0 vs the Sustainable Use License), verified July 2026 pricing including Keystroke's usage metering, and the maturity gap between a days-old platform and an established ecosystem.

comparison

QuantumBPM vs Camunda 2026: Single-Binary Challenger vs the BPMN Incumbent

QuantumBPM (launched 2026, Coroid s.r.o., Slovakia) packages a BPMN 2.0 runtime and DMN 1.5 decision engine into one Go binary backed by Temporal and PostgreSQL. Camunda (Berlin, founded 2013) is the category incumbent: Camunda 7 (Apache 2.0, in maintenance) and the Zeebe-based Camunda 8 platform. This comparison covers product structure, architecture, DMN TCK conformance with recording dates, deployment, pricing, and vendor maturity, verified July 2026.

Related Rankings

Best Automation Platforms for AI Orchestration 2026

This ranking answers one question: how many real business applications can an AI agent act on out of the box? It evaluates nine platforms as of August 2026 on the reach they give an agent, not on the workflow logic they can express. That boundary is deliberate, because two neighbouring pages on this site answer different questions. Best Process Orchestration Platforms 2026 scores multi-step process control, error handling and state management. Best AI Agent Platforms 2026 scores building and hosting the agent itself. This page scores the layer between them: the connective tissue that lets an agent already built elsewhere reach the applications a business actually runs on. A platform that leads one of those pages can place low here, and two of them do. Scores derive from application and action catalogue counts, the exposure model each platform uses to publish those catalogues to an agent, setup effort, failure handling and cost per agent action. Every figure was retrieved from a vendor-owned surface on 11 August 2026 unless an earlier date is stated against it.

Best Durable Workflow Engines for Production in 2026

A ranked list of the best durable workflow engines for production deployments in 2026. Durable workflow engines persist execution state to a database so that long-running workflows survive process restarts, deployments, and infrastructure failures. The ranking covers Temporal, Prefect, Apache Airflow, Camunda, Windmill, and n8n. Tools were evaluated on production reliability, developer experience, scalability, open-source health, and documentation quality. The shortlist intentionally mixes code-first engines (Temporal, Prefect, Airflow) with hybrid visual platforms (Camunda, Windmill, n8n) to reflect how production teams actually choose workflow engines in 2026.

Common Questions

Can you automate a platform with no API using Zapier?

Not as a proper Zapier app. Zapier's help centre, updated 29 May 2026, says a private app can be built "for any service with a public API", and its fallbacks for a missing app are email parsing, RSS, webhooks, asking Zapier to add the app, or using a different app. Those let a no-API platform tell a Zap that something happened; none of them lets a Zap act inside the platform. The Zapier Agents Chrome extension can "run actions" on a page open in your own browser (help article updated 27 April 2026), but that is hands-on help, not a reusable Zap step.

How does Moxo keep humans in control when AI agents run a workflow?

Moxo keeps people on the decisions by design: approvals and other human steps are ones its product page says "only a person can close", and AI agents can fill preparer, advisor or reviewer slots around them (both read 15 September 2026). The checks on AI output are opt-in, though. In synthetic AutomationAtlas tests that day, an AI extract step's "Human review" and "Supervisor Agent" switches were both off by default, and the builder accepted the same role as a form's submitter and its approver.

What is Moxo?

Moxo AI (app.moxo.com) is a process orchestration platform from Moxo, formerly Moxtra, for work where several parties, approvals and documents meet. You build templates of human steps, AI steps and automations, each run is a Flow with its own data and status, and outsiders act through account-free Magic Links. Its only published price is Team, and the AI agents start on the custom-quoted Scale plan (moxo.com/pricing, 15 September 2026). It is not Moxo Classic, the older app.

How much does Moxo cost in 2026?

Moxo's only published price is Team: $500 a month in the monthly view or $5,000 a year in the yearly view, for 100 flows and $100 of AI a year with unlimited seats (moxo.com/pricing, 15 September 2026). Scale (500 flows and $500 of AI a year) and Enterprise are custom quotes. There is no free plan, no published overage rate and no stated trial length, and the dollar AI allowance has no published conversion to the credits Moxo's product logs.