Tentunit Business — User Roles & Permissions Policy
Version 1.0 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business
This page is informational. It explains, but does not override, the Business Account Terms, which controls.
1. Overview
Tentunit Business uses role-based access control so each member of your team sees and does only what their job requires. This page explains the available roles, what each can do, and how to manage them responsibly.
1.1 What This Page Covers
This page describes the six standard roles available in every Tentunit Business account, a summary permission matrix, and Tentunit’s recommendations for assigning and reviewing access. It is informational: your binding obligations for staff access — including attribution of all Authorized User actions to your business, credential hygiene, and prompt deprovisioning — are set out in the Business Account Terms, and restrictions on credential sharing appear in the Acceptable Use Policy.
1.2 How Roles Fit Into Your Account
Every person who accesses your account must be an Authorized User with an individual, named login and exactly one assigned role per workspace. Roles determine feature access; they do not change who is legally responsible. Under the Business Account Terms, all actions taken by your staff are attributed to your business, regardless of role.
2. Role Definitions
Six standard roles cover the typical property management team. Assign each person the narrowest role that lets them do their job.
2.1 Account Owner
The Account Owner holds ultimate administrative control of the account. There is exactly one Account Owner per account. The Owner can do everything an Administrator can, plus actions reserved to the Owner alone: transferring ownership, closing the account, accepting updated legal terms, and changing the payout destination bank account. The Owner should be a principal of the business — ownership belongs to the legal entity, and control disputes are resolved as described in the Business Account Terms.
2.2 Administrator
Administrators run the account day to day at full breadth: managing billing and the subscription plan, inviting and removing staff, assigning roles, configuring properties and rent schedules, initiating refunds, and exporting data. Use this role sparingly — typically for an operations lead or office manager who genuinely needs account-wide control.
2.3 Property Manager
Property Managers handle tenancy operations for the properties assigned to them: listings, applications, leases, rent schedules, tenant messaging, and maintenance coordination. They can initiate tenant refunds for their properties but cannot touch subscription billing, staff management, or payout settings.
2.4 Accounting / Finance
The Accounting/Finance role is for bookkeepers and controllers. It provides visibility into payments, payouts, invoices, and reconciliation reports, plus the ability to manage subscription billing details, initiate refunds, and export financial data. It does not include staff management or tenant-facing operations such as messaging.
2.5 Maintenance
The Maintenance role is for maintenance staff and coordinators. It provides access to maintenance requests, work orders, unit access notes, and tenant messaging limited to maintenance threads. It provides no access to financial data, billing, or personal data beyond what a work order requires.
2.6 Read-Only
Read-Only users can view dashboards, properties, and reports (including payout visibility) but cannot create, modify, export, or send anything. This role suits owners’ advisors, auditors during a review, and staff in training.
3. Access by Role
The matrix below summarizes standard permissions. It is a summary of product behavior, which may evolve; the in-app role settings are the operative reference.
3.1 Permission Matrix
| Capability | Account Owner | Administrator | Property Manager | Accounting/Finance | Maintenance | Read-Only |
|---|---|---|---|---|---|---|
| Manage billing (plan, payment method, invoices) | Yes | Yes | No | Yes | No | No |
| Manage staff (invite, remove, assign roles) | Yes | Yes | No | No | No | No |
| Configure rent schedules | Yes | Yes | Yes (assigned properties) | No | No | No |
| Initiate refunds | Yes | Yes | Yes (assigned properties) | Yes | No | No |
| View payouts | Yes | Yes | Yes (assigned properties) | Yes | No | Yes |
| Export data | Yes | Yes | Yes (assigned properties) | Yes (financial data) | No | No |
| Message tenants | Yes | Yes | Yes | No | Yes (maintenance threads) | No |
3.2 Owner-Only Actions
Certain actions sit above the matrix and are reserved to the Account Owner: transferring account ownership, changing the payout bank account, closing the account, and accepting amended terms on behalf of the business.
3.3 Property Scoping
Property Manager and Maintenance roles can be scoped to specific properties or portfolios, so a manager for one building cannot see another building’s tenants or finances. Enterprise plans support custom roles and API-scoped credentials; see your Order Form.
3.4 Choosing the Right Role
A quick rule of thumb: if a person only needs to see information, use Read-Only; if they work with tenants and units, use Property Manager or Maintenance with property scoping; if they work with money and books, use Accounting/Finance; and reserve Administrator for the small number of people who genuinely manage the account itself. Role changes take effect immediately, and a user’s active sessions are re-evaluated against their new permissions, so it is safe to downgrade first and adjust later if something breaks.
4. Permission Management Responsibility
Tentunit provides the controls; deciding who gets access is your responsibility. These practices keep that responsibility manageable.
4.1 You Assign and Review Roles
Your business — through the Account Owner and Administrators — decides who receives access and at what level, and is responsible for keeping assignments correct as people join, move, and leave. Tentunit does not assign roles within your account.
4.2 Least Privilege
Grant each Authorized User the minimum role, and the narrowest property scope, needed for their duties. Prefer Property Manager over Administrator, Read-Only over Accounting/Finance, and scoped access over account-wide access. Resist “just make them an admin” — most permission incidents trace back to over-broad roles.
4.3 Quarterly Access Review
We recommend reviewing the full Authorized User list at least quarterly: confirm each person still works for you, still needs their role, and still needs their property scope. Downgrade or remove anything unused. The staff list and role-change history in account settings support this review.
4.4 Immediate Offboarding
Deactivate an Authorized User immediately upon departure or role change — do not wait for a scheduled review. Under the Business Account Terms, actions taken under live credentials are attributed to your business even after an employee has left, until you deprovision them.
5. Security Expectations
Good role hygiene only works alongside good credential hygiene. These are the security practices we expect around user access.
5.1 Multi-Factor Authentication
MFA is strongly recommended for every Authorized User and expected for the Account Owner, Administrators, and Accounting/Finance users, whose roles can move money or data. Administrators can encourage adoption by reviewing MFA status in the staff list.
5.2 Sessions and Devices
Authorized Users should sign out on shared or public devices, and Administrators should terminate active sessions for any user whose device is lost or whose account may be compromised. Sessions expire automatically after extended inactivity.
5.3 No Credential Sharing
Every login is individual. Sharing passwords, pooling a login among staff, or using group mailboxes as user accounts is prohibited by the Acceptable Use Policy and the Business Account Terms — and it destroys the audit trail that protects you in a dispute.
5.4 Audit Logs
Tentunit retains audit logs of role changes, staff invitations and removals, and other security-relevant account events. These logs support your quarterly reviews, internal investigations, and dispute resolution, and are available to Administrators in account settings.
5.5 Incident Reporting
Report suspected credential compromise, unauthorized access, or any security concern to [email protected] immediately. Prompt reports let us secure the account quickly; Tentunit’s own breach notification commitments to business customers (within 72 hours of confirming a breach affecting you) are described in the Data Processing Addendum.