The awkward thing about being a virtual assistant is that the better you do the job, the less there is to show for it. A designer ends the week with a file they can open. You end the week with an empty inbox, a calendar with no collisions in it, a supplier chased before anyone noticed they were late, and a founder who did not have to think about any of it. All of it lives inside somebody else's Gmail, CRM and bank feed — none of it yours to publish, and a screenshot of a tidy inbox proves nothing to anyone. Most virtual assistant portfolio advice avoids that. It tells you to include a bio, a services list and some testimonials, then stops before the hard part: what goes in the middle of the page when the work itself is invisible, confidential, or both. And then there is the second question, behind most of the searching on this subject — what to do when you have not had a client yet. Both have real answers. A VA portfolio is an evidence document rather than a gallery, and the craft sits in three places: turning process work into legible before-and-after, redacting client material so publishing it is genuinely safe, and being honest about the difference between work you were paid to do and work you built to demonstrate a method. Redaction gets the most space below, because that is where the risk is and where nearly every published example is careless. What the person reading it is actually deciding Someone hiring a VA is not assessing taste. They are settling four things. Will this person reduce my workload or add to it — every assistant hire is a bet that the handover cost is smaller than the ongoing saving. Can they use my tools without me teaching them — a client with a Notion workspace, a HubSpot pipeline and a Xero login fears three weeks of explaining their setup. Will they still be here in six months — reliability is the hardest thing to evidence early, which is why testimonials matter disproportionately here. And will they be discreet. You are asking for access to an inbox, a calendar, sometimes a payment system. You cannot claim discretion persuasively in a sentence, but a portfolio that visibly handles client information carefully is itself the argument — and a page showing an unredacted client inbox is a warning some buyers will read exactly that way. None of those is "does it look nice". Design is a hygiene factor here: clean, fast and readable is enough. Turning invisible work into evidence Here is the reframe that makes the rest possible. You are not trying to show the client's inbox. You are trying to show a change of state you caused, and that can be described in words, drawn as a diagram, or demonstrated on a rebuilt version with fake data — the original artefact is one route of three, and usually the worst. Every entry answers five short questions, as five lines rather than five paragraphs. What the task was. "Inbox and calendar management for the founder of a six-person recruitment agency." What state it was in before, specifically. "About 400 unread, no folders, meeting requests answered whenever they were spotted, three double-bookings the previous month." What you changed — decisions, not chores. "Built a four-label triage system, wrote nine canned replies for the weekly recurring questions, moved scheduling to a booking link with buffers either side." How long it took, setup and ongoing separately. "Six hours to set up, then about forty minutes a day." What the client stopped having to do. "He stopped opening the shared inbox at all, and no longer handled scheduling." That fifth line is the one people leave out and the one that sells. Write the outcome as a subtraction from the client's week. The middle column is where the work is: in almost every row, the safest artefact is something you rebuilt rather than something you exported. Organise by service area, not by client Most VAs work for two or three clients and do six different things for each. Organising by client reads like an employment history and forces you to over-identify people. Organising by service area matches how buyers think, because a buyer arrives with one problem, not six. Pick three or four areas you want more of — inbox and email management, calendar and scheduling, customer support, bookkeeping and invoicing support, social media management, research and reporting, travel and events, CRM and data entry — and give each a block: one worked example in the five-line format, the tools you use for it, and a line on how you would take it over from someone. Three areas done convincingly beats eight listed. A page claiming everything reads as someone who has done none of it deeply, and makes you compete on price with every other generalist; whether to niche down works through the trade-off. Redaction: the part everybody gets wrong This section decides whether your portfolio is an asset or a liability. VA artefacts are unusually dangerous to publish, because unlike a design file they routinely contain other people's personal information — not just your client's, but their customers', suppliers' and staff's. One inbox screenshot can leak a dozen email addresses; one CRM row can leak a name, a phone number and a deal value. The general principle, without pretending to give legal advice: information that identifies a living person, directly or in combination with other information, is personal data, and publishing it on a public page is a disclosure — the definition in Article 4 of the GDPR is the clearest short statement of what counts. Practically: if a stranger could read your portfolio and learn something about a named third party who never agreed to be there, do not publish it. Blur, crop or rebuild — and why rebuild wins Blurring and pixelation are the weakest, and you should stop using them. Pixelated or blurred text can be reversed algorithmically, because the blur preserves enough information about the underlying characters to reconstruct them by testing candidate strings against the result. Bishop Fox published a tool that does exactly this, and their conclusion is blunt: the only secure way to redact text is a solid black bar over all of it. Treat every blurred name in every VA portfolio you have seen as legible, because in principle it is. Cropping is better, with one trap. Removing the pixels beats obscuring them. The trap is that some editors save a crop back over the original file without truncating it, leaving the original data at the end of the file where it can be recovered — the flaw known as aCropalypse, found in the screenshot editors on Pixel phones and Windows. So never save a crop over the original: export a new file, or re-screenshot the cropped result. Then open the file you are about to publish, on a different device, and look at it. Rebuilding a clean version with dummy data is safest, and it is the default we recommend. Create a free account on the same tool, populate it with invented names and figures, set up the exact structure you built for the client, and screenshot that. It removes the risk rather than mitigating it, it produces a better image — no half-finished threads, no clutter, no black bars — and it shows the system you designed rather than one day's contents. Label it plainly: "Rebuilt with sample data to show the structure." The right-hand column is not more work than the left. Rebuilding a clean example takes twenty minutes; worrying about a blur takes for ever. The absolute rule about third parties Your client can give you permission to publish material about their business. They cannot meaningfully give you permission to publish their customers' personal data on your marketing site, and you should not ask them to. So: no screenshot containing a third party's name, email address, phone number, address or order details goes on your portfolio, redacted or not. If an example only works by showing a real customer record, it is not usable — describe it, or rebuild it with invented people. A visible URL can expose a client's subdomain or a shared document, so crop the browser chrome out of every screenshot as routine. Asking permission properly Permission is a short, specific conversation, and vagueness is what makes it awkward. Do not ask "is it OK if I use you in my portfolio". Ask for the exact thing: I'm putting together a portfolio page. I'd like to describe the inbox and scheduling work I did for you — the setup, roughly how long it took, and the outcome — without naming the company, and with a rebuilt screenshot using made-up names rather than anything from your account. Would that be all right, and would you rather I describe you as "a recruitment agency" or not mention the sector at all? Three things make that work: you say exactly what will appear, you have already picked the cautious option, and you give them a way to narrow it rather than a yes-or-no. Ask while the work is current — a client who has just been delighted says yes; one you last spoke to a year ago may not reply. If you signed an NDA, read it first; showing confidential work in a portfolio covers what those restrict. Stating your tools honestly Tool claims get checked — not always at the proposal stage, but reliably in week one, when the client asks you to do something in the tool you said you knew. Overclaiming is the fastest way to lose a contract you have won. Use three honest levels and mean them. Familiar with: you have used it, can find your way around, and would need a few days to be useful — perfectly respectable to list. Proficient in: you use it regularly without help and can name the specific things you do in it. Advanced: you set it up from scratch, built the automations, trained someone else, and know where it breaks. Then make each claim specific, because a bare logo says almost nothing. Compare "Proficient in HubSpot" with "HubSpot — proficient. I manage contacts and deal stages, build list-based workflows, and produce the weekly pipeline report. I have not touched custom objects or the reporting dashboards." The second is longer, less impressive and far more persuasive, because it tells a buyer exactly where you fit. Add the plan you have worked on, since features differ sharply between free and paid tiers. A list with an honest gap reads as complete; one with no gaps reads as a wish list. Building a VA portfolio with no experience This is the most common version of the question, and the honest answer does not involve waiting for a first client. You build sample work: invent a client, define a realistic brief, do the work properly, and publish it labelled as a demonstration. Every field with an entry route does this — designers call it spec work, developers a side project — and it is entirely legitimate provided the label is unambiguous and sits next to the work rather than in a footnote. The exact label to use Put a line directly above or beneath the item, in the same size as the surrounding text, not in grey italics at the bottom of the page: Sample project. Built for a fictional client (Northgate Bakery, a two-site bakery I invented for this exercise) to demonstrate my method. This was not a paid engagement. If a whole section is sample work, head it Sample work and open with: "Everything in this section was built to demonstrate process. None of it was delivered to a client." The labelling then survives someone skim-reading. What you must never do is describe invented work in the language of a delivered engagement — no fabricated testimonial, no "increased their bookings by 30%" for a company that does not exist. That is not spec work but a fake credential, and it comes apart in the first interview when someone asks about a client who cannot be found. What to actually build Five artefacts, all achievable in a weekend, each demonstrating a different competence. An inbox triage system. Create a fresh mailbox, send yourself thirty messages of the kind a small business gets — enquiries, invoices, newsletters, a complaint, a supplier chasing — then build the labels, filters and canned replies, screenshot before and after, and add 200 words on why the structure is shaped that way. An SOP document. One repeatable process written as a procedure someone could follow cold: purpose, trigger, numbered steps, screenshots, what to do when it goes wrong, who to escalate to. The most underrated VA portfolio piece, because clients want SOPs and rarely have them. A calendar and scheduling policy. A week view with focus blocks, travel buffers and meeting windows, plus a written policy for how requests get handled and what gets declined. A research deliverable. Set yourself a genuine brief — "shortlist five UK suppliers of compostable packaging, with lead times and minimum orders" — and produce the comparison and a recommendation. Only the client is fictional. A short walkthrough recording. Three or four minutes of your screen with your voice over it, explaining one of the above. For remote work this often does more than the artefact. Check the sharing setting by opening the link in a signed-out private window. Alongside that, take any real administrative thing you have done — for an employer, a community group, a family business — and write it up in the five-line format. Real and small beats invented and impressive. Building a portfolio with no experience and getting your first freelance clients cover the sequencing. Testimonials carry more weight here than anywhere When the work cannot be shown, someone else's account of it becomes your strongest available proof — and a VA testimonial is unusually easy to get, because the person writing it thinks about you in a way most clients do not. A weak one says "Sam was great to work with, highly recommended". A strong one says what changed: "Sam took over our shared inbox in January. Before that I was spending about an hour a day in it and things were getting missed. I have not opened it since February." The difference is in the asking — request a comment on a specific change rather than a general impression, and offer to draft something they can edit; asking clients for testimonials has the wording that gets replies. Use full name, role and company where the client agrees, initials and sector where they do not, and nothing rather than an anonymous quote that could have been written by you. Rates, packages and the availability line You do not have to publish rates, but the section replacing them still has work to do. It should answer: the unit (hourly, monthly retainer, fixed package), what a typical engagement looks like, what is not included, the minimum commitment, your working hours and time zone, and how quickly you respond. Those questions otherwise cost two emails before anyone knows whether to keep talking. Publishing a starting figure filters out buyers who were never going to pay it — a benefit if you have enough enquiries, a cost if you do not. Named packages work well for standardised work like inbox and calendar management and badly for open-ended operations support; if you are still setting the number, how much to charge as a freelancer beats copying a competitor's pricing page. Then add one line about availability, with a date on it: "Taking on one new retainer client from October" does more for enquiry quality than any other sentence on the page. Where the portfolio should live A PDF or slide deck is fine attached to a proposal and poor as your main portfolio: it cannot be found by someone searching your name, cannot be updated after you send it, and gets forwarded in versions you have lost track of. A Notion page is popular among VAs and works better than its reputation, not least because it demonstrates a tool you are probably claiming to know. Two things to check. Publishing a page to the web makes it viewable by anyone and brings all its subpages with it, so audit what is nested underneath first. And Notion's documentation notes that a published page's metadata includes the names, profile photos and email addresses of the users who contributed to it. A simple website on your own address is the better default: findable, yours, and able to carry a proper page title and description so it surfaces when someone searches your name. Bunfolio exists for this case — sign in with Google, fill a short wizard or import a LinkedIn profile, and get a live one-page site on a subdomain, free, with one template and no builder to learn; turning LinkedIn into a portfolio website is close to the shortest route. If you would rather keep the Notion page you already have, keep it — a live imperfect portfolio beats a better one you are still planning. Keep it to one page while you have three or four examples. And what belongs on an about page matters more here than in most fields, because clients are hiring a person for access to their inbox. Frequently asked questions What should a virtual assistant portfolio include? A positioning line saying who you help and with what; three or four service areas, each with one worked example in the five-line format; an honest tool list with proficiency levels; two or three attributed testimonials; a rates or packages section with your working hours and time zone; an availability line with a date; and an obvious way to contact you. How do I make one with no experience? Build five sample artefacts — an inbox triage system, an SOP, a calendar policy, a research deliverable and a short screen recording — for an invented client, and label the section clearly as sample work. Then add any real administrative work you have done, however small. Is mock or sample work dishonest? Not if it is labelled. Sample work presented as sample work is a demonstration of method; presented as a delivered engagement it is a fabricated credential. The line is entirely in the labelling. Can I show a screenshot of a client's inbox or CRM? Not the real one, in practice. Even with your client's permission, those screens usually contain third parties' personal data, and blurring is not a reliable defence. Rebuild the structure with invented names and label it as such. How many examples do I need? Three good ones, four at most, each covering a different service area. Depth persuades; a long list reads as someone who has skimmed everything. Should I put my rates on it? Optional. If you get more enquiries than you can handle, a published starting rate saves you time. Otherwise leave the number off but publish everything around it — unit, minimum, inclusions, working hours, response time. How we put this guide together Several frameworks here are Bunfolio's own recommendations rather than industry standards. The five-line entry format — task, state before, what you changed, time taken, what the client stopped having to do — is ours, as are organising by service area rather than by client, the three-level tool-proficiency wording, and the label wording for sample work. They come from working with freelancers building portfolios on Bunfolio: outcomes phrased as a subtraction from the client's week persuade, and claims narrow enough to be checkable survive an interview. The security points are sourced rather than asserted. The advice never to rely on blurring or pixelation comes from Bishop Fox's write-up of their Unredacter tool, which demonstrates recovering pixelated text and concludes that solid black bars are the only secure method. The warning about saving a crop over the original comes from David Buchanan's write-up of aCropalypse (CVE-2023-21036), in which cropped screenshots retained the original image data at the end of the file. The definition of personal data is Article 4 of the GDPR, quoted as a definition only — nothing here is legal advice, and if you handle sensitive material at scale, take proper advice rather than ours. The link-sharing roles come from Google's documentation on sharing files from Drive, and the metadata note from Notion's help page on public pages and web publishing, which states that a published page's metadata includes the names, profile photos and email addresses of contributing users. We have deliberately not quoted any figure for average VA rates, how many clients a typical VA has, or what share of businesses hire one. Numbers of that kind circulate widely in this niche and we could not trace them to a primary source we were willing to stand behind; inventing one inside a guide about honest claims would be self-defeating. Every client, company and figure used as illustration above is invented — the recruitment agency, the bakery, the invoice ageing numbers, the testimonial about Sam. They show the shape of a good entry, not anything that happened. Related reading: building a portfolio with no experience for the wider version of the sample-work question, showing confidential work in a portfolio for the permission conversation in more depth, asking clients for testimonials for the wording that gets a reply, and how much to charge as a freelancer before you write the rates section.