Security foundations
- Role-based access controls with organisation, portfolio, and property scope
- Organization isolation across staff, landlord, tenant, supplier, contractor, and platform roles
- Session expiry, revocation, password policy, MFA requirements, SSO readiness, and optional IP controls
- Immutable audit events for approvals, exports, and service proofs
- Object storage controls, version references, and access-authorized document delivery
- Upload size, filename, MIME, signature, authorization, and quarantine protections
- Configurable retention policies and legal hold support
- White-label domains and portals governed through verified organisation settings
- Supplier portal access and client-facing links should remain scoped, revocable, and auditable