Your client portal sits at the heart of your service business. It holds invoices, contracts, project status, and payment links. And every forgotten password costs you twice: once when the client calls for a reset, again when they stop using it altogether. Service firms bleed ₹80,000 a year on password-reset support tickets. Each reset takes 8–15 minutes of your team's time. Your client waits hours. They miss invoice deadlines. They stop checking the portal. By month three, you're issuing invoices over email again. SMS one-time passwords (OTP) fix this. Firms that switched from password fields to SMS OTP saw portal adoption jump from 18% to 40% in a single month. No forgotten passwords. No support tickets. No client friction. Here's the cost math, why SMS works, and how to implement it in Orin without breaking compliance. The true cost of password-reset hell Most teams undercount password-reset friction because the cost spreads across payroll, support time, and lost revenue. Take a 12-person service firm with 150 active clients: Support tickets per month: 8–12 password resets. Each takes 10 minutes to handle (finding the client, resetting, confirming). That's 80–120 minutes monthly, or roughly 16 hours yearly. Your support person's loaded cost: ₹500/hour average (salary + overhead). 16 hours = ₹8,000/year in direct salary. Clients who abandon the portal: About 30% of your user base gets frustrated after one or two resets and stops logging in. They request invoices by email, ask for status updates over WhatsApp, ask you to resend contracts. That's an extra 15 minutes per client per month across your ops team. 45 clients × 15 minutes × 12 months = 180 hours/year = ₹36,000/year in indirect labor. Invoice delays: Portal users pay in 4.2 days on average. Email-sent invoices? 7–9 days. The difference costs you cash-flow time. On a ₹50L annual invoice volume, a 3-day delay is roughly ₹40,000 in working capital drag yearly. Lost clients: 2–3% churn per year stems from friction during onboarding. If your average client lifetime value is ₹80,000, three clients = ₹240,000 in lost revenue. Total annual cost: ₹80,000 to ₹330,000 —and most firms only see the 8-hour support ticket line item. Why SMS OTP works better than passwords SMS one-time passwords bypass password management entirely. The client logs in, enters their email or phone, and receives a 6-digit code via SMS. The code expires in 10 minutes. No account recovery page. No "forgot password" email link. No password to remember or reset. Why does this nearly double adoption? Zero cognitive load: Clients don't create or remember a password. They use a code that vanishes after one login. On subsequent visits, they're asked again—same process, same simplicity. No support friction: Can't forget a password you don't have. Support tickets for resets drop to near zero. Mobile-first: SMS lands on any phone instantly. No email spam folder risk. No "did you get my password reset link?" back-and-forth. Faster login: OTP login takes 60 seconds. Password recovery takes 5 minutes and a device switchover. Speed cuts abandonment. Compliance edge: OTP is considered a second factor of authentication in most frameworks (GDPR, PDPA, SOC 2). It's more secure than a single password and costs less to defend. Industry data from consumer apps (ride-sharing, fintech, logistics) shows SMS OTP adoption lifts from 2–10 percentage points per week after launch. Service firms report 18% → 40% (portal login attempts per active client) within 30 days. Implementation: 48 hours in Orin Orin's unified messaging layer integrates SMS delivery natively. Here's the step-by-step setup: Step 1: Enable SMS provider (2 hours) Link Twilio or Telnyx via Orin's SMS gateway (Settings → Integrations → SMS). Test with a code to your own phone (arrives in <3 seconds). Confirm sender ID registration (required in India, Malaysia, Singapore for compliance; usually auto-approved within 4 hours). Set OTP expiry to 10 minutes and max retries to 3 per login attempt. Step 2: Update portal login flow (4 hours) Replace the password field with an "Enter your email" field on the login page. On submission, trigger an SMS with a 6-digit code to the registered phone number. The client enters the code into a second field. Match it against the server-side token; grant session on match. Test with internal team and 3–5 pilot clients. Measure time-to-login and error rates. Step 3: Phased rollout (12 hours) Week 1: Enable for new signups only. Let existing password-login clients keep their accounts. No friction. Week 2–3: Email existing clients: "Faster login, no password to remember." Link to a "Switch to SMS login" button in their account settings. Roughly 60–70% will convert within 7 days. Week 4: Phase out password login. Existing users still see a "Can't receive SMS?" fallback (password reset link), but 85%+ won't need it. Step 4: Monitor and optimize (24 hours) Track: login attempts, SMS delivery rate, code failures, session d