When you email a client a PDF, three things are true from that moment on: you cannot take it back, you cannot see whether they opened it, and you do not know who they forwarded it to. That is the attachment model. It is how most professional correspondence has worked for thirty years, and it is the origin of most of the "sent to the wrong person" incidents that reach a regulator.
The portal model
Share the case, not the file. The client receives an invitation; they verify with a one-time code sent to their email — or a password you gave them another way — and they see exactly the tabs, fields and files you chose for their audience. Nothing is copied to their machine unless they download it, and downloads are recorded.
Change your mind, and you close the window: revoke the share, and the link stops working. Add a document to the case, and it appears in their view without another email. Ask them a question, and the conversation stays attached to the case.
What the client sees
A share audience is defined on the template: which fields, which tables, which files, whether they can comment or upload. A tenant sees their rent statement and the inspection photos, not the landlord's notes. A claimant sees the correspondence with them, not the internal assessment. The same case, different windows.
Sending updates
From the case, post an update to the shared audience — a short note, optionally with files — and they are notified by email with a link back into the portal. Replies come back as messages on the case. There is no thread to lose and no version to reconcile.
File requests
The reverse direction matters as much. A file request asks the client to upload something — the signed form, the ID, the bank statement — through a link that lands directly in the case's Files tab. No attachment in your inbox, no "did you get it?", and the upload is encrypted at rest the moment it arrives.
When attachments are still right
Sometimes the recipient needs a file they can keep: a final report, a signed agreement. Send it — from the case, so the sending is recorded — and treat it as what it is: a copy you have released. The rule of thumb is simple. Working documents go in the portal. Finished documents go as attachments, once, deliberately.