Skip to content
yetkil.

Journal / Technical guide

What an internal company portal is, why you need one and how to build it

What an internal portal actually does, which processes belong in it, how to compare it with off-the-shelf systems and which decisions to make on day one.

  • internal portal
  • back-office systems
  • digitalisation
  • custom software

An internal company portal is the one internal address employees open every day. Leave requests are submitted there, absences are visible there, announcements are published there, and that is where you find out who currently has which laptop.

A portal is not an accounting package or an ERP, and it does not try to replace one. Its job is to gather the processes that are specific to your company — the ones no ready-made product quite covers — in a single place, and to connect to the systems you already run.

This article answers three questions: what a portal is, why you would need one, and how it should be built.

1. A portal is an address, not a list of modules

Thinking of a portal as “a leave module plus an asset module plus an announcement module” is misleading. Modules are the outcome. The portal itself is your company’s internal way of working, gathered in one place.

The difference shows up in a concrete test. Where does an employee submit a leave request, where does their manager approve it, where does HR see it, and where does a colleague find out who is away that day? If all four answers are the same address, you have a portal. If there are four different answers, you are running four systems and four habits.

2. The need usually comes from one of three places

Scattered information. A system for leave, a spreadsheet for assigned equipment, a person to ask about meeting rooms, a chat group for announcements. Each looks small. The sum is the time spent looking for things.

Per-user licensing. Most off-the-shelf systems are billed per person. That ties your software costs to how many people you hire rather than to the work you do. As the company grows, the bill grows on its own, while you carry on doing exactly the same thing.

A product that does not fit. Ready-made systems are designed for an average company. If your approval chain has three steps and the product supports two, you either bend the process to fit the product or run it outside the system. Both choices have a price.

There is also a quieter threshold: the spreadsheet. Spreadsheets are genuinely good tools and they are enough for many processes. They stop being enough when three things happen — more than one person needs to edit the same file at the same time, someone needs to know who changed what, and the process grows an approval step.

3. Do not move everything into the portal

The most expensive way to build a portal is to rewrite what off-the-shelf systems already do well. This split works for most companies:

Keep it off the shelfMove it into the portal
Accounting and bookkeepingLeave requests and approval flows
Payroll and employment recordsAssigned assets: phones, laptops, vehicles
E-invoicingMeeting rooms and resource booking
Email, files, calendars (Microsoft 365, Google Workspace)Announcements, news, internal communication
The ERP itselfInternal requests and fault tickets

What the right column has in common: every company does it differently, and your decisions set the rules. What the left column has in common: you do not set the rules, legislation does, and keeping up with changes is not your job.

4. The defining quality of a good portal is what it can connect to

A portal’s modules change over time. What does not change is the room to move that comes from owning the panel.

In an off-the-shelf product the question is always “does the vendor support this integration?” If the answer is no, there is nothing to do but add it to a wish list and wait. In your own panel the same question becomes “when shall we schedule this work?” That is not a technical detail; it is about who holds the decision.

In practice it looks like this. When someone books a meeting room, the room’s calendar can be read live from Microsoft 365, and the meeting created in the portal can be pushed to Teams. The same panel can show who reports to whom, along with phone numbers and email addresses. None of these is a large piece of work on its own; having them in one place is.

A good portal has these properties:

  • Parts of it can be public. There is no reason to make people sign in to read the news, the announcements or this week’s lunch menu.
  • Sign-in is a choice. It can be connected to Microsoft 365 accounts, or the portal can keep its own. This should be a decision, not a constraint.
  • Permissions follow how the company works. It may make sense for everyone to see approved leave, while in the asset register each person sees only their own items, HR sees every record without being able to edit it, and IT can edit. Those calls belong to the company, not to a product.
  • Access is logged. Who looked at what, and when, should be on record.
  • Data sits on the company’s server. On an in-house server if there is one, otherwise on a server bought in the company’s name.

5. Where to start: a small core

Trying to finish a portal in one go is the slowest and most expensive route. A better one is to start with a small core that everyone opens every day.

A good core is usually this: users and permissions, news and announcements, special days such as birthdays, and the weekly lunch menu. With a tight scope that core is roughly ten hours of development, and it brings the whole company into the portal in the first week.

The main benefit is not technical. People cannot say precisely what they want from a system until they start using one. The requests that arrive after the core goes live are always sharper than the list produced in meetings held before anything was built.

When choosing the first real module, ask two questions: which process touches the most people, and which one wastes the most time in its current form? In most companies the answer is leave tracking.

6. Personal data: whose responsibility, and whose job?

A portal holds employee data, so the legal side needs to be understood correctly before deciding anything.

A company that processes its employees’ data for its own purposes is the data controller under GDPR and Turkish data protection law. That role cannot be handed over: not to the developer who builds the portal, and not to the company providing the server. Whoever builds and runs the software acts on the company’s instructions as a data processor, and that relationship has to be defined in the contract.

So there is no arrangement where outsourcing the work also outsources the responsibility. What can be done technically is clear, and a portal makes it easier:

  1. Role-based permissions: who can see which data, and who can edit it.
  2. Access logging: who looked at what, and when.
  3. Data minimisation: not collecting data you have no use for.
  4. A hosting decision: knowing which server, in which country, holds the data.
  5. Retention: deciding up front when old records get deleted.

In an off-the-shelf system most of these five are limited to whatever you are offered. In your own panel you make the call.

7. A real example: a packaging manufacturer with more than 300 employees

KRCPACK used a separate system for leave tracking and had nothing at all for meeting rooms. Their leave system had no calendar, so there was no single view of who was off and when. The quotes they received for a broader internal panel came with a per-user annual licence.

We built the portal from scratch, around the way they actually work. Today it runs manager-approved leave tracking, HR and vehicle asset assignments, news and announcements, the weekly lunch menu, birthday and anniversary greetings, meeting-room management, IT ticketing and reporting. Meeting-room calendars are read live from Microsoft 365.

The outcome fits in two sentences. The company now has a single panel it can grow as it likes, with no per-user licence. The portal has been in use since June 2026 and is still growing; today the whole monthly hour package goes into it, because using it keeps producing new requests.

That last sentence is not a shortcoming. It is the expected behaviour: companies change, and portals have to change with them.

8. How to do the maths

Whether to build a portal or buy a system does not reduce to one sentence, but the arithmetic is simple.

On one side write: number of users × annual per-user licence × number of systems you use, totalled over three years. On the other side put the portal’s setup hours, its monthly development hours and the server cost.

When comparing the two, remember this: the first figure grows as your headcount grows, even if you do nothing at all. The second does not; it only rises when you ask for new work.

The decision is not only about money, though. An off-the-shelf system is the right answer when the process is bound by legislation, works the same way in every company, and you have no particular way of doing it. A custom panel pays off where the way you work is specific to you, where the ready-made product is either missing something or full of things you do not need, and where the process will keep changing.

Three questions are worth answering before any conversation about a portal: is this process specific to your company, what makes your bill grow, and whose server will the data sit on?

Arriving with those answers makes the first call much shorter. You can read what I do on the internal portals and back-office systems service page, see the details of the working model in how I work, or simply request a free introductory call.

Let us start

One hour on a call clears up most of it.

Tell me what you are trying to do, and we will work out what can be done, how long it takes and whether it is genuinely needed. A free analysis, planning and introductory call.

Phone
Show number
Email
e-posta
Based in
Guimarães, PortugalSamsun, Türkiye Based in Portugal, in Türkiye every couple of months.

Legal

Privacy notice

Last updated: 24 September 2026

This site carries no advertising trackers, behavioural profiling or third-party marketing cookies. Personal data is processed only when you fill in the contact form, and only so that I can reply to you. Google Analytics, used for visit statistics, runs only if you accept it.

Who is responsible

Uğur Yetkil is the controller for the personal data processed on this site. The business operates from Türkiye; you can reach the controller through any of the contact channels on this site.

What is collected

Only what you type into the contact form: your name, company, email address, phone number if you give one, the tier you are interested in, and your message.

There is no sign-in, membership or payment on this site, so nothing else is collected.

Why it is processed

The sole purpose is to reply to your enquiry and run the conversation that follows. This data is not added to a marketing list, not used for newsletters and never sold to third parties.

Legal basis

Processing rests on Article 6(1)(b) GDPR, as steps taken at your request before entering into a contract, and on Article 6(1)(f) as a legitimate interest. For enquiries from Turkey, Article 5/2-f of the KVKK applies.

Who it is shared with

Form submissions are delivered through an email service and a messaging service used for notification. These providers are used solely to deliver the message; your data is not shared for advertising.

Cloudflare Turnstile is used for bot protection. Turnstile does not build a profile that identifies you.

If you accept measurement, visit data is passed to Google through Google Analytics. If you decline, that transfer never happens.

How long it is kept

If your enquiry does not lead anywhere, the record is kept for at most twelve months and then deleted. If we begin working together, the data is kept for the duration of the contract and any statutory retention period that applies.

Cookies and visit measurement

Visit counts are measured with Cloudflare Web Analytics. That counter uses no cookies, writes nothing to your browser and does not identify you, so it runs without asking for consent.

Google Analytics 4 is also used. Because Google Analytics sets cookies, it loads only if you accept it. Until you do, the script is never added to the page; declining takes no action on your part, as that is already the default state.

If you accept, the pages you visit, the link that brought you here, your approximate location and your device and browser details are sent to Google. Your name, your email address and anything you type into the form never enter this measurement. Google may also process this data on servers outside the European Union.

You can change your choice at any time: the “Measurement preference” link at the foot of the page reopens the consent strip. When you decline, measurement stops and the cookies Google Analytics left behind are deleted from your browser.

Apart from that, your browser may store a functional value such as your language preference; it does not identify you.

Your rights

Under the GDPR and the KVKK you may ask what data is held about you, request correction or erasure, object to processing, and ask for your data to be transferred.

To exercise any of these, write to the email address on this site; your request is answered within thirty days at the latest.

Data inside client projects

Delivering the service may require technical access to data held in a client’s systems. The confidentiality clause in my standard service agreement applies, and I will also sign the GDPR or KVKK data-processing agreement your company uses.