Tentunit Business — User Roles & Permissions Policy

Version 1.0 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business

This page is informational. It explains, but does not override, the Business Account Terms, which controls.


1. Overview

Tentunit Business uses role-based access control so each member of your team sees and does only what their job requires. This page explains the available roles, what each can do, and how to manage them responsibly.

1.1 What This Page Covers

This page describes the six standard roles available in every Tentunit Business account, a summary permission matrix, and Tentunit’s recommendations for assigning and reviewing access. It is informational: your binding obligations for staff access — including attribution of all Authorized User actions to your business, credential hygiene, and prompt deprovisioning — are set out in the Business Account Terms, and restrictions on credential sharing appear in the Acceptable Use Policy.

1.2 How Roles Fit Into Your Account

Every person who accesses your account must be an Authorized User with an individual, named login and exactly one assigned role per workspace. Roles determine feature access; they do not change who is legally responsible. Under the Business Account Terms, all actions taken by your staff are attributed to your business, regardless of role.

2. Role Definitions

Six standard roles cover the typical property management team. Assign each person the narrowest role that lets them do their job.

2.1 Account Owner

The Account Owner holds ultimate administrative control of the account. There is exactly one Account Owner per account. The Owner can do everything an Administrator can, plus actions reserved to the Owner alone: transferring ownership, closing the account, accepting updated legal terms, and changing the payout destination bank account. The Owner should be a principal of the business — ownership belongs to the legal entity, and control disputes are resolved as described in the Business Account Terms.

2.2 Administrator

Administrators run the account day to day at full breadth: managing billing and the subscription plan, inviting and removing staff, assigning roles, configuring properties and rent schedules, initiating refunds, and exporting data. Use this role sparingly — typically for an operations lead or office manager who genuinely needs account-wide control.

2.3 Property Manager

Property Managers handle tenancy operations for the properties assigned to them: listings, applications, leases, rent schedules, tenant messaging, and maintenance coordination. They can initiate tenant refunds for their properties but cannot touch subscription billing, staff management, or payout settings.

2.4 Accounting / Finance

The Accounting/Finance role is for bookkeepers and controllers. It provides visibility into payments, payouts, invoices, and reconciliation reports, plus the ability to manage subscription billing details, initiate refunds, and export financial data. It does not include staff management or tenant-facing operations such as messaging.

2.5 Maintenance

The Maintenance role is for maintenance staff and coordinators. It provides access to maintenance requests, work orders, unit access notes, and tenant messaging limited to maintenance threads. It provides no access to financial data, billing, or personal data beyond what a work order requires.

2.6 Read-Only

Read-Only users can view dashboards, properties, and reports (including payout visibility) but cannot create, modify, export, or send anything. This role suits owners’ advisors, auditors during a review, and staff in training.

3. Access by Role

The matrix below summarizes standard permissions. It is a summary of product behavior, which may evolve; the in-app role settings are the operative reference.

3.1 Permission Matrix

Capability Account Owner Administrator Property Manager Accounting/Finance Maintenance Read-Only
Manage billing (plan, payment method, invoices) Yes Yes No Yes No No
Manage staff (invite, remove, assign roles) Yes Yes No No No No
Configure rent schedules Yes Yes Yes (assigned properties) No No No
Initiate refunds Yes Yes Yes (assigned properties) Yes No No
View payouts Yes Yes Yes (assigned properties) Yes No Yes
Export data Yes Yes Yes (assigned properties) Yes (financial data) No No
Message tenants Yes Yes Yes No Yes (maintenance threads) No

3.2 Owner-Only Actions

Certain actions sit above the matrix and are reserved to the Account Owner: transferring account ownership, changing the payout bank account, closing the account, and accepting amended terms on behalf of the business.

3.3 Property Scoping

Property Manager and Maintenance roles can be scoped to specific properties or portfolios, so a manager for one building cannot see another building’s tenants or finances. Enterprise plans support custom roles and API-scoped credentials; see your Order Form.

3.4 Choosing the Right Role

A quick rule of thumb: if a person only needs to see information, use Read-Only; if they work with tenants and units, use Property Manager or Maintenance with property scoping; if they work with money and books, use Accounting/Finance; and reserve Administrator for the small number of people who genuinely manage the account itself. Role changes take effect immediately, and a user’s active sessions are re-evaluated against their new permissions, so it is safe to downgrade first and adjust later if something breaks.

4. Permission Management Responsibility

Tentunit provides the controls; deciding who gets access is your responsibility. These practices keep that responsibility manageable.

4.1 You Assign and Review Roles

Your business — through the Account Owner and Administrators — decides who receives access and at what level, and is responsible for keeping assignments correct as people join, move, and leave. Tentunit does not assign roles within your account.

4.2 Least Privilege

Grant each Authorized User the minimum role, and the narrowest property scope, needed for their duties. Prefer Property Manager over Administrator, Read-Only over Accounting/Finance, and scoped access over account-wide access. Resist “just make them an admin” — most permission incidents trace back to over-broad roles.

4.3 Quarterly Access Review

We recommend reviewing the full Authorized User list at least quarterly: confirm each person still works for you, still needs their role, and still needs their property scope. Downgrade or remove anything unused. The staff list and role-change history in account settings support this review.

4.4 Immediate Offboarding

Deactivate an Authorized User immediately upon departure or role change — do not wait for a scheduled review. Under the Business Account Terms, actions taken under live credentials are attributed to your business even after an employee has left, until you deprovision them.

5. Security Expectations

Good role hygiene only works alongside good credential hygiene. These are the security practices we expect around user access.

5.1 Multi-Factor Authentication

MFA is strongly recommended for every Authorized User and expected for the Account Owner, Administrators, and Accounting/Finance users, whose roles can move money or data. Administrators can encourage adoption by reviewing MFA status in the staff list.

5.2 Sessions and Devices

Authorized Users should sign out on shared or public devices, and Administrators should terminate active sessions for any user whose device is lost or whose account may be compromised. Sessions expire automatically after extended inactivity.

5.3 No Credential Sharing

Every login is individual. Sharing passwords, pooling a login among staff, or using group mailboxes as user accounts is prohibited by the Acceptable Use Policy and the Business Account Terms — and it destroys the audit trail that protects you in a dispute.

5.4 Audit Logs

Tentunit retains audit logs of role changes, staff invitations and removals, and other security-relevant account events. These logs support your quarterly reviews, internal investigations, and dispute resolution, and are available to Administrators in account settings.

5.5 Incident Reporting

Report suspected credential compromise, unauthorized access, or any security concern to [email protected] immediately. Prompt reports let us secure the account quickly; Tentunit’s own breach notification commitments to business customers (within 72 hours of confirming a breach affecting you) are described in the Data Processing Addendum.