Docs / Using the Network / External Access Portal

Customer guide

External Access Portal

Inviting a transporter, veterinarian, receiving abattoir, laboratory or auditor into a narrow, logged-in view of specific movements, permits or holdings — including submitting and reviewing offload-receipt evidence — and revoking access cleanly when it's no longer needed.

Audience: grant issuers, external recipients & internal reviewers 10 parts

What this guide covers: inviting an outside party to a narrow, read-only view of specific movements, permits, or holdings; accepting that invite; using the scoped access portal — including submitting offload-receipt evidence for a movement; how an internal employee reviews and decides that evidence; and revoking access.

What it doesn't cover: the separate accountant-access grant, general movement/permit recording, or the public verification links and live tracking shares covered in Location Verification & Movement Tracking. Those are for sharing a permit or a live position with anyone, no login required. This guide is about giving one named outside party an actual, revocable, logged-in view into specific records — a different, stronger kind of access.

1. Introduction

Why this exists

Some of the people who need to see a piece of your livestock movement data are not your employees. A transporter needs to confirm which movement they're hauling. A veterinarian needs to check a permit before signing off on an animal. A receiving abattoir wants to see a movement's status before the truck arrives. A laboratory or auditor may need to look up a specific record for their own compliance purposes.

None of these people should get a full Agribantu employee account — that would hand them far more than they need, and far more than you'd want to be responsible for. But a public, no-login verification link (as used elsewhere in Agribantu — see Location Verification & Movement Tracking) isn't always right either: sometimes you want the other party to actually sign in, so you know exactly who looked at what, and so you can revoke access the moment it's no longer needed.

External Access is that middle ground: a named person, invited by email, gets a scoped, logged-in portal that shows only the specific movements, permits, or holdings you named, and only the actions you explicitly ticked — nothing else in your organisation is visible to them, ever.

2. Key concepts

Key concepts

TermPlain-language meaning
GrantOne invitation, for one email address, naming a subject type, a set of allowed actions ("scopes"), and a specific list of resources (movement/permit/holding IDs) it applies to. Has its own expiry date.
Subject typeWho the recipient is, for your own record-keeping: Transporter, Receiver, Veterinarian, Laboratory, Auditor, or Other. Doesn't change what they can do — the scopes and resource list do that.
ScopeOne specific named action a grant allows — e.g. "Read movements." A grant only ever allows the exact scopes you ticked, never anything implied by the subject type.
Scoped resourcesThe exact list of movement/permit/holding IDs a grant applies to. A grant never gives access to "all of an org's movements" — only to the specific ones you named.
Invite linkThe one-time link you send the recipient (by text, email, or however you choose — Agribantu does not send it for you). Opening it while signed in with the matching email activates the grant.
The scoped portalThe dedicated, cut-down view the recipient lands on after accepting — no employee dashboard, no other Agribantu menus, just their own access summary and the resources named in their grant.
The invite link only works once to activate a grant — read this before sending one. The first time the recipient opens it while signed in with the matching email, the grant switches from Pending to Active and they're issued a scoped session that lasts for the grant's full validity window. If they later sign out, switch devices, or clear their browser, reopening the same link a second time will not work — it will say the invite has already been accepted, and a normal Agribantu login does not restore scoped access on its own. If a recipient loses access this way, the fix is for you to revoke the grant and create a new one — not to resend the same link. Tell recipients to stay signed in on the device where they accepted the invite for as long as they need access.
Part A

Creating an External Access Grant

For grant issuers. Org admins and owners should expand LITS in the left navigation by clicking its right-pointing chevron, then select External Access near the bottom of the expanded group, immediately above LITS Settings. Scroll within the navigation if the group extends below the screen. Authority officers use Authority Command Centre → External Access. Both entries lead to the same page; the system decides which organisations you're allowed to create grants for.

If you only see the LITS heading: the group is collapsed. Click LITS or its chevron to reveal its child menu items. External Access is not under Assets & Fleet.

A.1 What you're looking at

A table of every grant your organisation (or, for an authority officer, your jurisdiction) has issued: invited email, subject type, status, allowed scopes, how many resources it covers, and its expiry date.

A.2 Creating a grant

  1. Click New Grant (top right).
  2. Enter the invited email address — this must be the exact email the recipient will sign in with. Case and whitespace don't matter, but the address itself must match precisely.
  3. Choose a subject type: Transporter, Receiver, Veterinarian, Laboratory, Auditor, or Other. This is for your own record-keeping — it doesn't grant any capability by itself.
  4. Tick one or more scopes — only these named actions will be allowed, on only the resources you list below:
    • Read movements — status, dates, and permit number for the named movements.
    • Read permits — the named permits only.
    • Read holdings — the named holdings only.
    • Confirm offload — lets the recipient submit receipt evidence (condition on arrival, quantity received, any discrepancy, optional photo/signature document references) for a named movement once it has been loaded and dispatched. This is evidence, not a completed movement — see Part C.4 and Part D. An internal employee at your organisation must still review and approve it before the movement is formally marked received.
  5. Paste in the actual Movement IDs, Permit IDs, and/or Holding IDs (comma-separated) this grant should cover. At least one resource ID is required in at least one of these three fields. There is currently no picker to browse and select these visually — you need to already have the ID from elsewhere in Agribantu.
  6. Set an expiry date. This is the outer limit for the whole invite — after this date, the grant stops working permanently, whether or not it was ever accepted.
  7. Click Create grant.

The new grant appears at the top of the list with status Pending.

Only one open invite per email, per organisation, at a time. If you try to create a second grant for an email that already has a Pending or Active grant in the same org, Agribantu will stop you. Revoke the existing one first if you need to start over with different scopes or resources.

A.3 Sending the invite

Agribantu does not email the invite for you. Click the link icon (visible only while a grant is Pending) to copy the invite link to your clipboard, then send it yourself — by text message, email, WhatsApp, or however is convenient. Anyone who opens it will be prompted to sign in with the exact email address the grant was created for.

Part B

Accepting Your Invite

For external recipients. This part needs no prior Agribantu knowledge — it's written for the first time you ever open an invite link.

B.1 Opening the link

Open the link the organisation sent you. You'll land on a page titled External Access Invite.

  • If you're not signed in, you'll see "Sign in to accept this invite" with two buttons: Sign in (if you already have an Agribantu account) or Create an account (if you don't). Either way, use the exact email address the invite was sent to — signing in with a different email will not work.
  • Once you're signed in, the page automatically attempts to accept the invite — you'll briefly see "Checking your invite…", then either land straight on your scoped portal, or see an error if something's wrong (see Part G for what each message means).

B.2 After accepting

You're taken straight to your scoped access portal — see Part C. From this point on, as long as you stay signed in on this device, you don't need to do anything else; your access lasts until the grant's expiry date without needing to repeat this step.

Part C

Using Your Scoped Portal

For external recipients. Once your invite is accepted, this is the only part of Agribantu you'll ever see — there's no employee dashboard, no other menus, just your own scoped access.

C.1 The access summary

At the top of the portal, a card shows:

  • Granting organisation — who invited you.
  • Your role — the subject type you were invited as (Transporter, Veterinarian, etc.).
  • Access ends — the exact date/time your access expires, plus a plain-language "days left" count.
  • Active scopes — the specific actions you're allowed (e.g. "Read movements").
  • Assigned resources — how many movements, permits, and holdings are in scope for you.

An informational banner above this reminds you: "You are viewing scoped external access. Only the resources and actions your invite named are shown here — nothing else in this organisation is visible to you."

C.2 The movement list

If your grant includes movement access, a Movements table lists exactly the movements named in your grant — permit number, status (Pending, Loaded, In Transit, Arrived, or Cancelled), and departed/arrived timestamps. Click View on any row to open a detail card with the same four fields. No other movements in the organisation are listed here, regardless of how many exist.

C.3 Signing out

The usual account menu (top right) still lets you sign out. Once you sign out, reopening your original invite link will not sign you back in — if you need access again after signing out, ask the organisation that invited you for a new invite.

C.4 Confirming receipt of a movement

If your grant includes the Confirm offload scope, an opened movement's detail card shows a Confirm Receipt button whenever that movement's status is Loaded or In Transit — i.e. it has been dispatched but not yet marked received. The button does not appear for a movement that is still Pending (hasn't departed yet), or one already marked Arrived or Cancelled.

This submits evidence — it does not complete the movement. An internal employee at the sending organisation must still review and approve what you submit before the movement is formally marked received and the animal's recorded location changes. You are giving your account of what arrived; you are not the one who finalises the record.

Clicking Confirm Receipt opens a form:

  • Received at — date and time you took receipt. Required.
  • Condition on arrival — Good, Injured, Distressed, Deceased, or Other.
  • Quantity received — optional.
  • Discrepancy checkbox — tick this if what arrived doesn't match what you expected, then describe it in the text box that appears. Required if the box is ticked.
  • Notes — optional free text for the reviewer.
  • Photo document ID / Signature document ID — optional. These are not upload fields; they're for pasting the ID of a document already stored elsewhere in Agribantu, if one exists and was shared with you separately.
A pasted Document ID must already be a clean, fully-scanned file. Every file stored in Agribantu passes an automatic security scan before it can be referenced anywhere. If the ID you paste points to a file that is still being scanned, failed its scan, or doesn't exist under this organisation, your submission will be rejected with a clear reason — check with whoever shared the ID with you rather than retrying the same one repeatedly.

You cannot set or change where the movement is going, which permit it's under, or any other record-level detail — those are always taken directly from the movement itself, not from anything you type. Once submitted, you'll see a confirmation message and cannot edit or withdraw what you sent; if something was wrong, tell the organisation directly so their reviewer can reject it with a reason and you (or they) can re-check the shipment. A given grant can submit only one confirmation per movement.

Part D

Reviewing Offload Confirmations

For internal employee reviewers. This part is for people inside the organisation that issued the grant — not for external recipients, who only ever submit evidence (Part C.4) and never see this queue.

D.1 Where to review

Expand LITS in the left navigation and select Review Queue, then open the External Confirmations tab alongside the existing Event Reviews tab. A pending count badge shows on the tab itself when there's evidence waiting.

D.2 What each entry shows

Every submitted confirmation lists: the condition on arrival, quantity received (if given), any discrepancy and its description, notes, referenced evidence document IDs, a permit warning if the movement's permit has expired or gone inactive since dispatch, a GPS arrival-detected badge if an independent tracking share happened to also detect arrival (informational only — it never drives the decision), when it was submitted, and — once decided — when and with what outcome.

D.3 Approving

Click Approve to accept the evidence and formally complete the movement in one step: the movement is marked Arrived, and the animal's recorded location updates to the movement's destination. This is a deliberate, individually-audited action — there is no automatic or bulk approval, and nothing about the evidence (including a GPS arrival badge) ever approves itself.

Group movements cannot be approved yet. If the movement covers a group rather than a single animal, the evidence stays visible in the queue for reference, but the Approve button is disabled — group offload approval needs an immutable departure record this release doesn't yet build. Reject or leave it pending instead.

D.4 Rejecting

Click Reject and type a reason — a reason is required. Rejecting does not alter the movement itself in any way; it only records that this particular piece of evidence was not accepted. The external submitter is not automatically notified beyond what you separately tell them.

D.5 Who can approve

Approval requires both the standard review permission and movement-write permission, since approving is what actually completes the movement. An Authority officer reviewing compliance elsewhere in Agribantu cannot approve or reject a confirmation from the Authority side — that capability stays with your own organisation's employees only (see Part F for what Authority can see).

Part E

Managing and Revoking Access

For grant issuers.

E.1 Reading grant status

StatusMeaning
PendingCreated, invite link not yet opened and accepted by the recipient.
ActiveThe recipient has accepted the invite and can currently use their scoped portal.
ExpiredThe grant's expiry date has passed.
RevokedYou ended this grant manually.
A grant past its expiry date is always blocked from actual use immediately — this is checked live on every single request, not just when the status label updates. The Status column can occasionally still read "Active" for a little while after the expiry date if nobody has attempted to use the link since it lapsed — trust the Expires date shown in the list over the Status chip if the two ever seem to disagree.

E.2 Revoking a grant

Click the ban icon ("Revoke") next to any Pending or Active grant. Confirm in the dialog — this immediately blocks any active or pending session for that email. This cannot be undone. If the recipient needs access again later, create a brand-new grant (Part A); the old, revoked one can't be reactivated or edited.

E.3 There is no edit — only create and revoke

You cannot change a grant's scopes, resources, or expiry date once created. If you need to adjust any of those for someone who already has access, revoke the existing grant and create a new one with the settings you actually want.

Part F

Privacy: What You Can and Cannot See

As an external recipient, your scoped portal is deliberately narrow. You will only ever see:

  • The specific movements, permits, or holdings your grant named — never a full list of the organisation's records.
  • For a movement: permit number, status, and departed/arrived timestamps only.

You will never see: driver identity, vehicle registration, animal-level detail, live GPS position, financial information, other employees, or any other part of the organisation's Agribantu workspace — the scoped portal has no navigation to any of it.

If you submit offload-receipt evidence (Part C.4), it is visible only to your organisation's own internal reviewers (Part D) — not to any other external recipient, and not back to you once submitted beyond the confirmation message shown at the time.

As a grant issuer, the same narrowness protects you: a grant can never accidentally expose more than the specific scopes and resource IDs you explicitly typed in. There is no "grant everything" option and no scope that implies broader access than its own name describes.

A government authority official reviewing your organisation's compliance elsewhere in Agribantu can see, for a movement with submitted offload evidence: that a confirmation exists, its current status (pending, approved, or rejected), whether it flagged a discrepancy, and when it was submitted and reviewed. They cannot see the evidence itself — the condition reported, quantity, notes, discrepancy description, evidence document references, who submitted it, or who reviewed it — and they cannot approve or reject anything; that stays entirely with your own organisation's employees.

Part G

Troubleshooting & FAQ

I created a grant but nothing was emailed to the recipient.

That's expected — Agribantu doesn't send the invite for you. Click the link icon next to the Pending grant to copy the link, then send it yourself (Part A.3).

"An active or pending external access grant already exists for this email in this organisation."

You're trying to invite someone who already has an open (Pending or Active) grant with you. Revoke the existing one first (Part E.2) if you need to issue a different one.

The recipient says the link shows "This invite is unavailable."

This covers a few different underlying reasons on purpose, all shown with the same careful wording so the message never accidentally confirms whether a specific email was invited:

  • Invalid access token — either the link itself is wrong, or the recipient is signed in with a different email than the one the invite was sent to.
  • Access has been revoked — you (or another admin) revoked this grant.
  • Access token has expired — the grant's expiry date passed before it was ever accepted.
  • Access token has already been accepted — the recipient (or someone who had the link) already used it once. The same link can't activate a session twice.

I'm the recipient, and I signed out — now I can't get back in.

This is expected behaviour, not a bug. Contact the organisation that invited you and ask them to issue a new invite.

Can I edit a grant's scopes or expiry date after creating it?

No — revoke it and create a new one with the settings you want (Part E.3).

What does the "Confirm offload" scope let a recipient do?

It lets them submit receipt evidence for a named movement once it has departed — see Part C.4. It never lets them complete the movement themselves; an internal employee reviewer must still approve the evidence (Part D) before the record is formally updated.

The recipient submitted a Confirm Receipt but nothing changed on the movement.

That's expected. Submitting evidence only creates a pending item in LITS → Review Queue → External Confirmations — nothing about the movement itself changes until an internal reviewer approves it (Part D.3).

Why is the Approve button disabled for a confirmation?

Either it's already been approved or rejected, or it covers a group movement, which this release doesn't yet support approving directly — see the callout in Part D.3.

Can an external recipient submit more than one Confirm Receipt for the same movement?

No — one grant can submit exactly one confirmation per movement. If they need to correct something after submitting, tell your reviewer to reject it with a reason; there is no edit or resubmit option.

The recipient's Confirm Receipt was rejected because of the photo or signature document ID.

The pasted ID must point to a file that has already passed Agribantu's automatic security scan (Part C.4). Ask whoever shared the ID to confirm the file finished scanning cleanly, or share a different, already-scanned document instead.

I revoked a grant by mistake. Can I undo it?

No — revocation is permanent by design. Create a new grant instead.

Part H

Quick Reference

Where to find each feature

I want to…Go to
Create/view/revoke grants (org admin/owner)LITS → External Access
Create/view/revoke grants (authority officer)Authority Command Centre → External Access
Accept an invite (external recipient)Open the link the organisation sent you
View your scoped access (once accepted)External Access → My Access
Submit offload-receipt evidence (external recipient)Open the movement's detail card in your scoped portal → Confirm Receipt
Approve/reject submitted evidence (internal reviewer)LITS → Review Queue → External Confirmations

The golden rule, restated once more: a grant only ever shows exactly what its issuer typed in — the scopes ticked and the resource IDs listed, nothing implied and nothing more. An invite link only ever activates a session once; after that, staying signed in is what keeps access working, not the link itself. And submitted offload evidence is never, by itself, a completed movement — only an internal employee's approval makes it one.