Short answer: A homeowner should see anything that is a fact about them — their claim stage, photos of their property, documents they signed, appointments, and the money. What stays internal is anything that is a fact about your operation: margin, subcontractor pricing, staffing, and unreviewed drafts. Write both as if they will be read.
I build CRM For Claims, and the question of what a homeowner should see on a claim almost always arrives dressed as a security question. Can we let them log in? Is that safe? What if they see something? Underneath it is usually something much more ordinary: somebody once forwarded the wrong file, or a customer read a note that had been typed for internal eyes at six on a bad Friday, and now nobody in the office wants to share anything at all.
The instinct is understandable and the fix is backwards. Sharing less does not make the file safer. It makes people phone you more, and it loads the one thing you do eventually send with all the weight of everything you did not.
What should a homeowner be able to see on their own claim?
Anything that is a fact about them. The current stage and what happens next, photographs taken of their property, documents they have signed or need to sign, scheduled appointments and who is arriving, and the money — the approved amount, their deductible, what has been invoiced, and what has been paid. None of that is a favour you are doing them.
There is a single test underneath that list, and it settles most of these arguments before they start: whose fact is this? A fact about the property, the policy, the paperwork or the payment belongs to the homeowner, because all four are theirs. A fact about how your company runs — what you paid the crew, what you make on the job, who is short-staffed this week — belongs to your company. Confidentiality is not really the dividing line. Ownership is.
It is also worth knowing that the homeowner has already been told to collect all of this. The Insurance Information Institute’s consumer guidance on settling a claim after a disaster tells policyholders to keep copies of everything they submit to the insurer, copies of everything the insurer sends back, and the name and number of everyone they speak to. So the request is coming. A company that can answer it in ten seconds looks entirely different from one that needs an afternoon and three people’s inboxes.
What should stay internal on a claim, and why?
Four things, mostly: your cost and margin, other people’s commercial information, anything half-finished, and anything about another customer. Each has a decent reason behind it, and for three of the four there is a better sentence you can say instead — which matters, because “I cannot tell you that” is the answer that makes people suspicious.
| Stays internal | Why | What to say instead |
|---|---|---|
| Job margin and your cost breakdown | A fact about your business, not about their loss. It also reopens a negotiation the carrier already settled. | “The approved scope is $X. Here it is line by line.” |
| Subcontractor pricing and crew pay | Same reason, plus it is somebody else’s commercial information to give away. | “The crew is booked for Tuesday morning.” |
| Internal notes about the adjuster or carrier | Written fast, often blunt, and it quietly becomes the homeowner’s opinion of their own adjuster. | “The supplement went in on the 12th. We are waiting on their response.” |
| Drafts — estimates, supplements, raw photo sets | An unreviewed number becomes a promise the second somebody reads it. | “The estimate goes out Thursday, once it has been checked.” |
| Staffing, performance, who is being managed | Their claim does not need to know who is on a warning. | “Your file is with Dana now. Her direct number is…” |
| Anything at all about another customer | Never theirs, under any circumstance, including as an example. | Nothing. Do not use other jobs as illustrations. |
The last row is the only absolute on the list. The others are judgement calls with a default; that one is a rule. It is also the one most likely to be broken by accident, by a screenshot of a list view or a photo folder that happens to include the job before theirs.
Where is the gray zone, and how do you decide?
Most of the gray zone is not a question of whether — it is a question of when. Nearly everything in the middle becomes the homeowner’s eventually. The real disagreement in the office is about the gap between a document existing and a document being finished, and the honest answer is that the gap should be short and stated out loud.
| Item | Share it | The mistake to avoid |
|---|---|---|
| Inspection photo set | After one review pass, as a set | Dumping 180 unsorted photos, thirty of them blurry, with no caption on the shot of the pre-existing leak |
| Your estimate | Once the numbers have stopped moving | Letting them see a working figure. A number seen once is the number they remember |
| A supplement request | When it is submitted to the carrier | Sharing it while it is being written, which reads as a promise of an approval you do not control |
| The carrier’s letter, including a denial | Immediately — it is addressed to them | Sitting on it for two days to work out what to say first |
| A delay and its reason | The day you know | Letting them discover it. A delay they are told about is an update; one they find is a warning sign |
Should you write internal notes as if the homeowner will read them?
Yes, always, and not because of some abstract principle. Internal notes reach homeowners routinely through three completely mundane routes: a forwarded email thread with the history still attached below, a quick screenshot sent to answer a question, and a records request if the claim ever turns into a dispute. None of those require anyone to do anything wrong.
There is a fourth route people forget: turnover. The person who typed something sarcastic in March is not there in September to explain the tone, and whoever reads it next inherits it as fact — including the new coordinator who might read it aloud on the phone. A note is only useful if it still means the same thing to a stranger.
The practical version is a habit, not a policy document. Write what happened, with a date. Label an opinion as an opinion. Keep adjectives off people.
- “Adjuster is useless” — becomes “Called adjuster Aug 12 and Aug 15, left voicemail both times, no return call.” One is a complaint; the other is evidence, and it is the one that helps you when you escalate.
- “Customer is being difficult about access” — becomes “Two scheduled visits cancelled by homeowner, Aug 9 and Aug 14. Rebooked for Aug 21.”
- “Think we can push this through” — becomes “Opinion: the ridge line is arguably covered under the same event. Photo set 3 supports it.”
The rewrite is not corporate politeness. The version with the dates in it is the one that wins a reconsideration; the version with the insult in it is the one you have to explain.
Does giving a homeowner a login create a privacy problem?
For most contractors, not a regulatory one. Broad US privacy law is aimed at larger businesses — California’s CCPA, for instance, applies to for-profit companies with over $25 million in gross annual revenue, or that handle the personal information of 100,000 or more residents or households, or that make half their revenue selling personal data. Most roofing and restoration firms clear none of those.
The real exposure is operational, and it does not care about your revenue. It is the attachment sent to the wrong address, the share link that never expires, the file that was correct in June and is now three revisions out of date, and the household where two people are on the deed and only one is speaking to you. That last one is worth designing for: access should be granted to a person, not to an address. Claims involve co-owners, tenants, landlords and property managers, and they do not always want the same things.
Weighed against the alternative, a login you control is usually the safer option, not the riskier one. The alternative is email attachments, which live forever in inboxes you cannot reach, cannot revoke, and cannot update. I made the wider case for and against portals in customer portals for restoration jobs; the short version is that a portal is worth it when it replaces repeat contact, and a liability when it is a login screen showing a status word.
How should visibility be enforced in the software?
On the record itself, decided once, at the moment the record is created. A document is marked shared or internal when it is uploaded. A note defaults to internal. A photo set becomes visible when it is reviewed. What you are avoiding is the alternative that every office invents on its own: two versions of the same file.
The parallel-file problem is the one that actually bites. Keep a “customer copy” of the estimate and an internal one and two things happen, both guaranteed. Somebody eventually sends the wrong one. And the customer copy goes stale, because the update gets made in the file the office actually uses. A visibility flag has neither failure mode, because there is only ever one document.
- One file, one flag. Shared or internal is a property of the document, not a separate export.
- Sensible defaults by type. Contracts, signed forms and invoices default to shared. Notes, cost breakdowns and internal messages default to private.
- Photos move as sets. Sharing one photo at a time is how a blurry frame becomes a conversation.
- Money is field-level, not document-level. Approved amount, deductible and payment status are theirs; cost lines on the same record are not. That is a distinction a spreadsheet cannot express, which is why the spreadsheet version ends up as two spreadsheets.
- Internal access is a separate question. Who on your team sees the money side is its own decision — see roles and permissions on a claims CRM.
- The portal is a view, not a copy. If it renders the live claim record, it cannot be out of date. If it is a copy, it will be.
This is one of the concrete differences between claims-first software and a general tool bent into shape. In a generic CRM, “customer-visible” is usually something you approximate with a folder naming convention and a promise. You can see how we handle documents, stages and the customer view on the CRM For Claims features page, and how that compares with the general-purpose route on our comparison page.
When is none of this worth building?
If you run a handful of jobs a year and speak to every customer yourself, you do not need any of it. A phone call and an emailed PDF is a complete and honest system, and the boundary lives in your head where it works fine. I would rather say that plainly than pretend otherwise.
It stops working the day a second person answers the phone. From then on, “what can I tell them?” is a question somebody has to ask you, and the answer has to be the same on Tuesday as it was on Monday. That is the point where the boundary has to live in the record instead of in a person — and where getting it wrong stops being a bit of awkwardness and starts being a claim that stalls while a homeowner decides whether to trust you. Our plans and per-user pricing are published for exactly that stage of a business.
If you want to see what a homeowner would actually see on one of your claims, the fastest way is to look at a real one. Book a live walkthrough and bring a job you are running now — we will set the visibility up the way your process already works, rather than the way a demo script would like it to.


