Property Manager logoProperty ManagerEvidence-first rental operations
Security and governance

Governance foundations for evidence-heavy rental operations.

Security follows the same boundaries as the operating record: verified identity, organization and role scope, protected evidence, attributable decisions, recoverable services, and human control over sensitive automation.

Operating principle

Security foundations

  • Role-based access controls with organisation, portfolio, and property scope
  • Organization isolation across staff, landlord, tenant, supplier, contractor, and platform roles
  • Session expiry, revocation, password policy, MFA requirements, SSO readiness, and optional IP controls
  • Immutable audit events for approvals, exports, and service proofs
  • Object storage controls, version references, and access-authorized document delivery
  • Upload size, filename, MIME, signature, authorization, and quarantine protections
  • Configurable retention policies and legal hold support
  • White-label domains and portals governed through verified organisation settings
  • Supplier portal access and client-facing links should remain scoped, revocable, and auditable
Operating principle

Evidence and compliance positioning

  • Designed to support consistent process and stronger operational records
  • Evidence retention built into repairs, documents, resident updates, landlord approvals, and supplier delivery
  • Supports Renters' Rights and Building Safety readiness but does not replace legal advice
  • Complaints, disrepair, notice context, and safety evidence should be reviewed by qualified specialists when needed
  • Case exports should show chronology, owners, timestamps, files, and decisions without implying legal conclusions
Operating principle

AI and governance controls

  • AI assistance should be logged, explainable, and clearly separated from final human decisions
  • Export, approval, and evidence-pack activity should remain auditable
  • Security pack available on request for procurement and risk teams
  • Clear explanation of auditability, retention, integration, and governance controls
  • AI triage, summary, and routing suggestions should be positioned as operator support rather than automated determinations
  • Roadmap controls should include AI decision logs, overrides, human review, and policy-level configuration
  • Provider credentials remain referenced through deployment secrets rather than exposed in ordinary application records
  • Backups, restore procedures, health checks, queue visibility, and feature-flag rollback support operational resilience
Operational safeguards

Controls mapped to the way property work actually moves.

Security is applied across identity, evidence, external delivery, and continuity. The aim is to keep sensitive tenant and property information appropriately scoped while preserving a trustworthy record of actions and decisions.

Next step

Need the security pack or a procurement conversation?

Use the contact route when the discussion is about controls, governance, risk, or rollout policy rather than a general demo.