Portal verification
How to Verify a COI Upload in a Client Portal
The upload is not finished when files are selected. Verify the destination record file by file: visible name, category, timestamp, portal state, and receipt reference should connect back to the exact package you intended to submit.
Reviewed September 2026 · Educational information, not insurance, legal, or cybersecurity advice
Freeze the intended package before opening the portal
Give the outgoing package a controlled version and list every expected filename and intended upload category. Open each file from the staged folder. Confirm that the visible document belongs to the correct project, displays the expected legal entities and dates, and is the document type represented by its filename. Keep superseded files outside the staged folder.
Use a neutral project reference rather than a policy number, tax identifier, personal address, or other sensitive value. The U.S. National Archives recommends descriptive, consistent, meaningful names and keeping components such as dates or versions in fixed positions. Its guidance governs federal records, not private contractor portals, but the control principle makes an intended-to-observed comparison much easier.
Record the portal or client label, package version, submission date, time zone, and internal owner. If the client supplied a current portal instruction, retain it with the project record. Category names can change, so a remembered label should not replace the option visible during the actual submission.
Compare every intended row with the portal display
| Comparison | Question | Conservative result |
|---|---|---|
| Expected filename | Is the intended file represented in the destination record? | Exact, formatting-only difference, mismatch, or not visible |
| Portal filename | Did the system rename, truncate, or normalize the displayed name? | Preserve both names; do not guess |
| Category | Does the visible destination category match the intended one? | Match, mismatch, or unknown |
| Status | Does the portal show selected, uploaded, received, processing, rejected, or accepted? | Use the exact observable state |
| Timestamp | Is there a final submission time rather than a local selection time? | Record the displayed value and time zone |
| Receipt reference | Is a transaction, confirmation, or acknowledgment available? | Preserve it in the authorized record |
Do not compare filenames by appearance alone. A hyphen, underscore, space, capitalization change, or portal-added prefix may be a formatting-only difference. A changed version, date, project token, document type, coverage scope, or extension may signal a substantive mismatch. Open the destination document only when the portal and your authorization permit it.
Compare the destination record
Match the intended package to what the portal actually shows.
Review up to twelve files without connecting to the portal or uploading a document here.
What counts as receipt evidence?
A success banner, confirmation number, automated acknowledgment, final uploaded-file list, or client response can each document a different fact. Preserve what actually appears. A browser page that lists selected files before the final submit button is preparation, not transmission. An “uploaded” row may show that bytes reached a system, but it does not necessarily mean the package entered review. “Received” is not automatically “accepted.”
A receipt record is stronger when it connects the project, package version, visible files, categories, timestamp, and transaction reference. If one file lacks a status or appears under the wrong category, treat the package as needing review even when the portal displays a general success message.
OWASP’s file-upload guidance is written for system owners and developers. It explains that upload workflows have security risks and should restrict allowed types, size, permissions, and storage behavior. For a contractor user, the practical implication is to follow the client’s approved portal and file rules rather than bypassing controls, repeatedly changing extensions, or sending sensitive evidence through an unapproved alternative.
Nine-step post-upload verification
- Preserve the staged package and manifest before entering the portal.
- Use the current authorized portal URL and sign-in process.
- Select the intended file from the staged folder, not a general downloads directory.
- Choose the category visible in the current written instruction.
- Complete the final submit action and wait for the destination response.
- Compare every expected filename with the final visible list.
- Compare every intended category with the destination category.
- Record the portal state, timestamp, and receipt reference without upgrading the wording.
- Schedule follow-up for missing, rejected, processing, or unacknowledged items.
Example verification matrix
| Expected | Observed | Category | Status | Action |
|---|---|---|---|---|
| project_certificate_gl_2026-09-03_v02.pdf | Same | Certificate / match | Received | Preserve receipt |
| project_ai_gl_2026-09-03_v02.pdf | project_ai_gl_v01.pdf | Endorsements / match | Uploaded | Stop; investigate stale version |
| project_waiver_wc_2026-09-03_v02.pdf | Not visible | Waiver / unknown | Not visible | Confirm whether final submit included it |
Privacy and access boundaries
- Never enter a portal password into a third-party checklist.
- Do not paste policy numbers, personal identifiers, or confidential contract text into filenames.
- Do not take or distribute screenshots if the portal or company policy prohibits them.
- Store the authoritative receipt in the organization’s approved location.
- Do not use a public link as a substitute for an authorized portal unless the client approves it.
- Follow retention, legal-hold, and access rules that apply to the project.
The Texas Department of Insurance explains that a job or contract number can be used for identification under the Texas rules it cites, but certificate text cannot use an external contract to imply unsupported coverage. That distinction is useful here: a project token may connect records, while the portal verification still must not become a coverage conclusion.
Frequently asked questions
The portal shortened my filename. Is it wrong?
Preserve both versions and compare the meaningful components. A display truncation may not change the stored file, but confirm through the portal if the hidden portion contains the date or version.
Can a general success banner cover all files?
Use it as one record, then verify the final file list. A row-level rejection or missing item should not be erased by a package-level banner.
Should I download the file back?
Only if the portal permits it and the action is authorized. The visible destination record may be enough for the administrative comparison.
Does the verifier certify receipt?
No. It organizes your observations. The portal or recipient supplies the underlying evidence.
Does accepted mean coverage is verified?
No. Administrative acceptance is not a policy interpretation or claim determination.
Sources and scope
- U.S. National Archives: Consistent file naming
- OWASP: File Upload Cheat Sheet
- Texas Department of Insurance: Certificates FAQ
The verification matrix is original administrative guidance. It does not authenticate a transaction, inspect a portal, or determine insurance coverage.