Control which partners see your shipments
Partner Access is where an importer or forwarder tenant admin sees which partners share shipments into the workspace, and narrows individual users to a subset of them. The other direction — which partners can see your shipments — is set per company on that company's page, not here.
8 minute read · Updated July 27, 2026
Unchecked boxes mean more access, not less.
On the User Restrictions card, leaving every provider checkbox clear is not a lockout. It is full access. The screen states it twice: “Leave providers unchecked for normal access to all active providers” in the section header, and “No checked active providers means normal access to all active providers. Checked providers restrict this user to only those active providers.” next to the save button. Checking boxes is how you narrow someone.
How shipment visibility works, in plain language
Visibility runs in one direction at a time, and the two directions live on different screens. Getting them confused is the single most common reason a partner “still cannot see anything.”
- Outbound — you share
- On a company's page under Companies, a Shipment Visibility card carries a checkbox reading “Share matching shipments with <company>” and a Save visibility button. Turning it on lets that company see the delivery orders you own where they are named in a matching role.
- Inbound — a partner shares with you
- Every company that has done the same for you shows up on Partner Access as a Visibility Provider. Partner Access does not create outbound sharing; it lists what is coming in and lets you limit which of your own users can see it.
A partner is matched to a shipment through a visibility path — one path per role a company can hold on a delivery order. There are six: Customer, BCO, Broker, Forwarder, Warehouse, and Carrier. Each is counted and tracked separately, which is why a partner can be sharing on one path and not another.
Who can open the screen
Partner Access requires all three of the following. Miss any one and you are redirected to the unauthorized page rather than shown an empty screen.
- An active tenant workspace, not a platform or portal context.
- The Tenant Admin role in that workspace. A tenant manager cannot open it.
- An importer (BCO) or freight-forwarder workspace. Carrier and warehouse workspaces do not have this screen at all.
The header reads Partner Access under the label “Partner access configuration,” with the line “Normal access includes every active provider.” on the right. If you followed an old bookmark to the portal collaboration URL, it redirects here. If the page will not open at all, see why you cannot see a page.
Reading the Visibility Providers table
Four tiles sit above the table. Below them, Visibility Providers lists every company currently granting your workspace inbound access, sorted by name, under the note “Providers with active shipment visibility can be used for user restrictions.”
| Column | What it holds |
|---|---|
| Partner | The company name. A company with no name on file shows as Unnamed Organization. |
| Relationship | A role chip derived from the partner's classification: Carrier, Logistics Provider, Warehouse, Importer (BCO), Equipment Provider, or a plain Partner when nothing matches. |
| Visibility Paths | How many of the six paths that partner has active toward you. It is a count, not a list — the individual path names are not shown on this screen. |
| Last Update | When that partner's rules last changed, or No recent update. |
On a narrow screen the table collapses to one card per partner showing only Visibility paths and Last update. With nothing configured you get “No active visibility providers are configured for this workspace.” — and because restrictions can only reference providers in this list, the User Restrictions card below will have no checkboxes to offer.
The first two tiles, Visibility providers and Active providers, are both computed from this same list, so they always show the identical number. Do not read a difference between them as a signal — there can never be one. Restricted users counts your own team members who have at least one provider checked, and Last update is the newest change across all providers.
Restricting a team member
The User Restrictions card lists one block per active user in your workspace — anyone holding a Tenant Admin, Tenant Manager, Tenant User, or Collaborator assignment. Users are ordered by role and then by name, and a user who holds more than one role is shown at the highest one. If nobody qualifies you get “No active organization users were found for this workspace.”
- Read the badges first. Each block shows the person's name, their role, a Billing access chip where it applies, and one access badge: green All active providers or amber Restricted. Under it sits either “Inherits normal access to all active providers” or “Limited to” followed by the provider names, plus the date the restriction last changed.
- Check the providers to limit them to. Every provider from the table above appears as a checkbox labeled with the company name and “Limit this user to this provider.” Check one or several.
- Select Save Restrictions. The save applies to that one person. Each user block has its own button.
- Confirm the banner. A green Scopes updated banner appears at the top of the page reading “Restriction scopes updated,” with count chips such as Added restrictions, Removed restrictions, and Unchanged restrictions.
Saving replaces, it does not add.
The form submits exactly the boxes that are checked at that moment, and that set becomes the user's complete restriction list. Clearing every box and saving is how you give someone full access again — there is no separate “remove restriction” control, and the Removed restrictions chip in the banner is your confirmation that it happened.
The checkbox list only ever offers providers that are currently granting active access. If a partner stops sharing, that partner disappears from this screen, any restriction pointing at it stops being displayed, and the member's badge reverts to All active providers even though a stored restriction still exists underneath. The next time you press Save Restrictions for that person, the hidden entry is written away with everything else you did not check. If a restriction matters, confirm it after any change to the provider list.
Failures come back as a red Could not save partner access settings banner with the reason underneath. The ones worth recognizing are “That user must have an active assignment in your organization before scopes can be granted.”, “One or more selected owner organizations are no longer available for inbound collaboration.”, and “You are not authorized to manage collaborator scopes for this organization.”
Accepting a collaboration invite
When a partner detects a shared shipment history with your company, Conterminal can email a collaboration invite. The link opens a standalone page outside the app — you do not have to be signed in to read it.
- Open the link. Signed out, you land on Review Collaboration Invite, which names both companies, the recipient email, and how many Supporting delivery orders were detected. Select Continue with Magic Link to sign in; the invite token travels with you.
- Check the details. Signed in, the page becomes Accept Collaboration Invite and adds a Match modes line listing the paths that will be activated, or None recorded if the sender detected none.
- Enter a full name and accept. The Full name field is required. Select Accept Collaboration Invite. Acceptance activates a standing rule for each detected match mode, marks the invite accepted, switches your active workspace to the invited company, and drops you into the app.
The page states who may accept: “Existing org admins can accept immediately. If this organization does not have an active Conterminal> admin yet, the first accepted invite will create that admin membership for the signed-in email.” In other words, once your company has admins, only an admin address can take the invite — not whoever happens to have the link.
Signing in with the wrong address produces Sign In With The Intended Account and a message naming the address that is allowed, such as “This collaboration invite must be accepted using name@example.com.” The page shows the account you are signed in as next to the invite recipient and offers Sign Out And Switch Account. Nothing is consumed by the failed attempt.
An invite can only be accepted while it is queued or sent. Anything else lands on a status card: Invite Unavailable (“This collaboration invite is invalid, expired, or has already been cleared.”), Invite Already Accepted, or Invite Not Ready (“This collaboration invite is not in a state that can be accepted right now.”).
Approving access requests
This screen is carrier-only, despite the name.
The admin Tenant Access Requests screen is gated to carrier workspaces — its own header reads “Carrier Workspace Administration.” An importer or forwarder tenant admin, the same person who owns Partner Access, is redirected to the unauthorized page. If you run a BCO or forwarder workspace, there is no approval queue for you to work; incoming partner relationships reach you as collaboration invites instead.
Anyone can submit a request from Access Requests, which tracks your own submissions through pending, approved, and rejected. A successful submit shows “Access request submitted. Status is now pending review.” Submitting the same thing twice is refused with “A matching pending request already exists. Wait for review before submitting again.”
What a carrier admin reviews
The queue shows pending Join Tenant and Access Tenant requests for organizations where you are a tenant admin, oldest first, capped at 50. Each card carries the target organization, the requester's user ID, the submitted time, the request ID, and any proposed organization name. A Review Notes (optional) box accepts up to 2,000 characters and is shared with the requester.
- Approve
- Applies the requested tenant role assignment and reports “Access request approved and tenant role assignment applied.” A Join Tenant request grants Tenant User; an Access Tenant request grants Collaborator.
- Reject
- Closes the request with “Access request rejected.” The requester sees the rejected status on their own Access Requests page.
If someone else has already handled the request, the action fails with “Request is no longer pending or is outside your scope.” Reload before deciding again.
Status meanings: Active, Partial, Off, Recommended
These badges live on a company's Shipment Visibility card, not on Partner Access. Open the company from your company directory — the card only renders for a tenant admin looking at a company other than their own. The card header shows one badge for the whole relationship; the table under it shows one status per path.
- Active
- Every supported path for this company is on. As a per-path status it means that one path is on.
- Partial
- Some supported paths are on and some are not. This value only ever appears on the header badge — an individual row is never labeled Partial.
- Off
- A rule exists for the path but is not active. At the header level it means every configured path is switched off.
- Recommended
- No rule has ever been configured for this path. It is a suggestion based on the company's role, not a state you set.
Around the badge, Direction reads as your workspace name, an arrow, and the partner name. Paths is a fraction — active over supported, such as 1/2. Matched Jobs counts the delivery orders those paths currently match. Last Update shows Not yet until something changes. A Partner Access button in the corner jumps to the inbound screen; carrier workspaces do not get that button.
The control on this card is a single checkbox — “Share matching shipments with” the company — followed by Save visibility. It turns every supported path on or off together. There is no per-path control here, so saving from a Partial state flattens it: the whole relationship goes fully on or fully off. The checkbox starts checked for every state except Off, which means an unattended save on a Recommended relationship will switch sharing on.
Troubleshooting
A partner says they still cannot see the shipment
Check the outbound direction, not Partner Access. Open that company and confirm the Shipment Visibility badge reads Active and that the path matching their role on the delivery order is Active rather than Recommended or Off. A Recommended path has never been turned on.
“No active visibility providers are configured for this workspace.”
No partner is currently sharing into your workspace, so there is nothing to restrict anyone to. This is about inbound access only; it says nothing about what you are sharing outward.
A user sees more than they should
An empty checkbox list is full access. Open their block on User Restrictions, check the providers they are allowed, and select Save Restrictions. Confirm the badge flips from All active providers to Restricted.
A restriction I set is no longer shown
The list only offers providers with active inbound access. If that partner stopped sharing, the checkbox is gone and the member reads as All active providers again. Re-check the intended providers and save once the partner is back on the list.
“That user must have an active assignment in your organization before scopes can be granted.”
The person no longer holds an active role in your workspace, so a restriction cannot be attached to them. Restore their assignment first; saving again without that will keep failing.
“One or more selected owner organizations are no longer available for inbound collaboration.”
A provider you checked stopped granting access between the page loading and your save. Reload Partner Access and redo the selection against the current provider list.
“You are not authorized to manage collaborator scopes for this organization.”
Your role no longer allows this change. Partner Access requires the Tenant Admin role in an importer or forwarder workspace; a tenant manager cannot save restrictions.
“Only tenant admins can update shipment visibility.”
The Shipment Visibility card was reachable but the save was refused. Related refusals are “Shipment visibility is unavailable for this workspace.” for a workspace type that does not support sharing, and “Shipment visibility is only editable from a tenant company page.” when the card was opened from a platform context.
“An active rule with that collaborator and match mode already exists.”
That exact path is already on for that company. Nothing is wrong and nothing needs re-creating — check the path table on the company's Shipment Visibility card to confirm it reads Active.
“This collaboration invite must be accepted using …”
You are signed in as the wrong account. Select Sign Out And Switch Account and sign back in with the address named in the message. The invite is untouched.
“This collaboration invite is invalid, expired, or has already been cleared.”
The token no longer resolves. Ask the sending company to re-send the invite rather than reusing the old email.
“Request is no longer pending or is outside your scope.”
Another admin already approved or rejected that access request, or it belongs to an organization where you are not a tenant admin. Reload the queue.