You built a client portal. Your CRM tracks every deal. Clients can upload docs, approve invoices, and check project status. It's all there. But 60% of your clients never use it. They email you instead. When you ask why, they say 'I forgot my password' or 'it's too much friction to log in every time.' The portal exists. Adoption caps at 40%. Password resets are a silent killer—not because they're broken, but because they're one extra step a busy client won't take. This isn't a technical complaint. It's a behavioral wall. Every time a client needs to reset their password, you lose them to the path of least resistance: a direct email to your team. That friction—forgetting credentials, hunting for the reset link in spam, entering a new password—compounds across your user base. Studies of enterprise portals show that organizations that switch from password-gated access to passwordless login (magic links, single sign-on, or passkey authentication) see adoption climb from 35–45% to 70–85% within 90 days. The portal itself didn't change. The entry mechanism did. Why the password reset becomes a dropout point A client logs in once. Uses the portal. Leaves. Three weeks later, they need it again, but they've forgotten their password. The reset email goes to their spam folder. Or they reset it, then immediately forget the new one because they use it only once a month. Each reset event is a micro-friction point where clients choose the easier path: email your team instead. Here's what happens in real workflows: Day 1: Client creates account, sets password, uploads document. Friction is high (new system) but motivation is high (they need something done). Adoption: 100% on first use. Week 3: Client returns to check status. Can't remember password. Clicks 'Forgot password.' Email goes to spam or wrong folder. They give up and email your team instead. Adoption drops to 0% for that session. Week 6: You've sent them three reminders to use the portal. But they've already developed a habit of emailing you. The password reset friction, repeated twice, now feels harder than the alternative. They stop trying. By month 2, that client has asked for a password reset twice and used the portal once. They're now counted in the 40% adoption ceiling because they technically can access it—but they don't. The passwordless alternative: magic links and SSO Passwordless login removes the reset step entirely. Instead, a client clicks 'Log in,' enters their email, and receives a one-time magic link. No password to remember. No reset email hunting. Click the link, you're in. Alternatively, if they're already logged into Google or Microsoft, single sign-on (SSO) skips the email step altogether. The adoption jump is not subtle. Organizations that implement magic links see login attempts increase 50–70% because the friction of 'forgot password' is gone. The link expires in 15 minutes, so clients don't have to manage credentials. They just click. Real example: A home services company using Orin's embedded client portal and document management switched from password-based login to magic-link authentication. Before: 42% of invited clients ever logged in. After (8 weeks): 74% of invited clients logged in at least once, and 60% returned within 30 days. No product feature changed. No design change. Only the authentication method. Measuring the friction per user role Not all clients experience the same friction. Some roles reset their passwords more often than others. Measure where resets cluster to understand where passwordless login wins fastest. Project managers (high frequency, 2–4 logins per week): Even for high-frequency users, forgetting a password once per month kills momentum. A 4-week cycle of password resets can tank their adoption from 80% to 40% if they have to reset twice. Magic links remove this completely. Finance stakeholders (low frequency, 1 login per week): Forget the password after the first month. Reset friction is highest here because their motivation to log in is lower. Magic links drop the barrier so low that they log in without thinking. C-suite (very low frequency, 1–2 logins per month): Almost always forget. They're busy. Password resets feel like a chore for something they 'kind of' need to see. Magic links change this from a chore to a click. To measure this in your portal, log password resets per user role for 30 days: Export your portal access logs. Filter by 'password reset' events. Tag each reset by client role (project manager, accountant, owner, etc.). Calculate reset-to-login ratio: number of resets / number of subsequent logins. If a finance stakeholder resets their password three times but only logs in twice, resets are > logins. That's a sign of high friction. Calculate days between last login and reset. If the gap is always > 21 days, the client simply forgets. Passwordless login will dramatically lower reset requests from this group. The metric that matters: Track 'portal return rate' (clients who log in at least t