Security & privacy
Managing residents access credentials
Giving residents online access to documents, expenses and communications is now standard practice, but it carries precise responsibilities for the property manager: who can see what, how to invite a new resident, and what happens when a unit is sold or a password is lost. Orderly credential management reduces phone calls to the management office, respects confidentiality obligations under personal data processing rules, and keeps every access to building documents traceable. This guide walks through the operational steps, from invitation to revocation, with particular attention to what a resident should be able to see and what instead remains confidential to other households or owners.
Inviting a resident to the portal
The invitation starts from the resident registry that the property manager already maintains for routine communications and meeting notices: linking a valid email address to the unit is enough for the resident to receive a personal activation link. With AmministraPro the invitation is sent directly from the resident's record, without needing to share temporary passwords by phone or on paper, a practice that unnecessarily exposes the credential to third parties.
It is good practice to verify the email address at the time it is collected, because an invitation delivered to the wrong address can expose financial information to an unrelated person. For units with multiple owners (joint ownership, inheritance), it is worth deciding in advance who receives the main access and whether secondary accounts should be activated, avoiding ambiguity that later surfaces at the assembly meeting.
What a resident can see, and what they cannot
The guiding principle is relevance: each resident should be able to view the data that concerns them directly, such as their own expense allocation, the payment status of their own unit, meeting minutes, and shared building documents (budgets, regulations, insurance policies). It is not appropriate, however, for a resident to freely view another resident's detailed payment or debt position, beyond what aggregate accounting transparency toward the assembly requires.
This distinction also follows from general personal data processing principles applied to building management: the property manager handles data belonging to multiple individuals for building management purposes and must limit its visibility to what is strictly necessary for each recipient. A well designed portal applies these boundaries automatically based on the connected user's profile, without the manager having to configure permissions manually unit by unit.
Password resets and access issues
A self service password reset, via a link sent to the registered email, is the preferred approach: it avoids the manager or office needing to know or communicate other people's credentials, reducing the risk of human error. When a resident reports not receiving the reset email, the most frequent causes are an outdated email address in the registry or spam filters: before intervening manually it is worth checking and correcting the registry data.
For less digitally experienced residents, typically older age groups, it helps to provide direct support from the office during first access, explaining that the link received has a limited validity period and should be used promptly.
Revoking access: sale, inheritance, management changes
Portal access should be deactivated promptly whenever the reason it was granted ceases: sale of the unit, succession through inheritance, or a change of tenant in cases of leased units with delegated access. Access left active lets a former owner keep viewing documents and financial movements that no longer concern them, which is clearly unfair toward the new owner.
In practice, revocation should be handled as part of the registry update procedure the property manager already carries out for ownership transfers: updating cadastral data and the ownership share, notifying the bank where required, and deactivating the account linked to the previous owner, with a new invitation issued to the incoming owner where appropriate.
Credential security in day-to-day management
A few good practices reduce operational risk for the management office: never share credentials by phone, never reuse the same invitation for different units, and periodically check the list of active accounts against the building's current registry, especially after assembly meetings involving ownership changes.
With AmministraPro the property manager retains visibility over the accounts linked to each building directly from the platform, so a reset or revocation can be handled without manual steps on external systems, keeping credential management consistent with the up to date resident registry.
Frequently asked questions
Can a resident see other residents' payments?
Generally no: a resident accesses their own allocation and payment data, not the detailed debt position of others, aside from the aggregate information needed for accounting transparency toward the assembly, such as budget totals or defaulters listed in collectively approved documents.
What should be done if a resident sold their unit but still accesses the portal?
Access should be revoked as soon as the building registry is updated to reflect the ownership transfer: this is one of the steps the property manager must carry out together with updating cadastral data and notifying the new owner, to prevent the former owner from continuing to view documents and financial movements no longer relevant to them.
Who should receive the invitation when a unit has multiple owners?
It is best to identify a main contact for access in advance, typically agreed among the co-owners, and to consider activating additional accounts when joint ownership requires it, avoiding ambiguity in receiving communications and meeting notices.
How does the password reset work in the AmministraPro portal?
The resident requests the reset independently via the link sent to their email address on file, without the property manager needing to know or communicate the new password: if the link does not arrive, the most common cause is an outdated email or a spam filter, which should be checked before other interventions.
Why is careful management of building access credentials important?
Because the property manager processes data belonging to multiple individuals for building management purposes and must ensure access only to those entitled to it, limiting mutual visibility between residents to what is strictly relevant and promptly revoking access that no longer has a valid reason, consistent with general principles of proper personal data handling.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
