Short answer: a property-management software permissions matrix should define who may view, create, edit, approve, pay, export, delete, configure, impersonate, or administer each record type, and for which properties or entities. Every important permission needs an allowed test, a denied test, an owner, approval evidence, and a recurring review date.
Buildium describes access based on role, region, responsibility, and selected properties. Its bookkeeping guidance separates view, entry, approval, and full-access duties. AppFolio publicly describes custom user roles, two-factor authentication, auditing, and tracked changes. These vendor capabilities are useful reference points, but this independent template does not verify a particular plan, configuration, certification, or regulatory outcome.
Inventory roles before assigning screens
List employees, temporary staff, owners, residents, vendors, cleaners, accountants, auditors, integration identities, service accounts, and administrators. Define duties and portfolio scope before copying an existing user. A title such as property manager is not precise enough when two people have different approval limits or property assignments.
Model actions rather than menu visibility
A user who can open a financial page may still need separate rights to enter, edit, approve, void, export, or pay. Record actions for properties, leases, residents, applications, maintenance, inspections, documents, reports, bank data, payments, users, integrations, and configuration. Use the broader security and access-control checklist for authentication, devices, backups, and incident readiness.
Apply portfolio and entity scope
Test whether access follows the assigned organization, legal entity, owner, portfolio, property, building, or unit. Search, dashboard totals, notifications, exports, API responses, saved reports, shared links, and mobile views must honor the same scope. A hidden menu is not evidence that the underlying record is protected.
Separate preparation from approval
Identify workflows where one person should not control the complete chain. Examples include entering and approving a bill, changing payout details and releasing funds, preparing and issuing a refund, creating and approving a user, or editing and approving a report. Separation requirements vary, so have qualified accounting, legal, security, and operational reviewers approve the matrix.
Protect sensitive fields and bulk actions
Personal information, bank details, identity documents, screening records, access codes, legal files, payroll, exports, bulk communication, and deletion deserve explicit rows. Masking, download, print, copy, sharing, API, and support access may need different treatment from ordinary viewing.
Download the permissions matrix
Download the editable property-management software permissions matrix (CSV). It includes role, resource, action, portfolio scope, field sensitivity, approval limit, segregation rule, allowed test, denied test, evidence, owner, review date, and removal trigger.
Test both allowed and denied behavior
Create fictional test records and verify that each role can complete required work. Then attempt the same action outside the role's property, amount, record type, and workflow stage. Include direct URLs, search, export, API, mobile, notifications, and shared links. Record screenshots or logs without exposing real personal or financial data.
Control integrations and service accounts
Document each API key, OAuth connection, webhook, email integration, payment connection, storage identity, and automation user. Record owner, scope, secret location, rotation, last use, failure behavior, and revocation test. Connect this review to the software exit checklist so access can be removed during migration or vendor termination.
Review access at lifecycle events
Trigger review at hiring, role change, leave, termination, portfolio reassignment, vendor completion, owner exit, incident, integration change, and periodic certification. Removal should cover sessions, remembered devices, shared links, API credentials, exports, local files, and downstream applications.
Frequently asked questions
Should administrators use their admin account for daily work?
Prefer a standard account for routine work and a controlled administrative path for privileged changes where the product supports it. Protect elevated access with strong authentication, limited membership, alerts, and review.
Can a vendor see resident contact information?
Only when the approved workflow, authorization, privacy review, and minimum necessary scope support it. A work order should not automatically expose unrelated resident or financial records.
Official references
- Buildium: custom roles, permissions, fields, and reports
- Buildium: permissions, approval thresholds, and separation of duties
- AppFolio: custom roles, two-factor authentication, and audit logs