Practical guide
Roles and permissions: manager, staff, owner
In condominium software not every user needs to be able to do everything. The managing controller coordinates the whole activity, the practice's staff follow a subset of condominiums, owners access only their own data through a private area. Distinguishing these roles and assigning coherent permissions is not a technical detail but a way to respect the GDPR minimisation principle, under which personal data should be accessible only to those who genuinely need it. This guide explains how to set roles and permissions clearly, tidily and defensibly, avoiding both indiscriminate access and needless complication.
Why you need distinct roles, not a single access level
In the traditional model, the condominium file on an office PC was often accessible to anyone who opened that folder. Everyone saw everything: budgets, registries, arrears for every building. This clashes with the principle that each staff member should handle only the data needed for their tasks, and it multiplies the risk in case of error, resignation or account compromise.
Defining distinct roles means building the software around the essential question: who needs to view or modify what. A staff member following ten condominiums has no reason to access the other fifty managed by the practice, and an owner should not be able to see the neighbours' accounting position. The role is the tool that turns this logic into concrete permissions.
The managing controller: the role with the most responsibility
The managing controller has the complete view: they manage the entire portfolio of condominiums, configure the settings, assign and revoke staff access, and approve the most sensitive operations. From a GDPR standpoint they are the data controller, responsible to owners for the accuracy and security of the data, regardless of the tool used.
Precisely because their account has the broadest privileges, it must be protected with particular care: a strong password, two-factor authentication and attention to never sharing credentials. Compromising the controller's account potentially exposes every condominium managed, so its security is the practice's priority.
Staff: access limited to their assigned condominiums
The staff role should allow work only on the condominiums that person actually follows, and with permissions consistent with their tasks. Whoever handles accounting needs to record transactions and prepare statements, whoever manages communications must be able to send notices to owners, but it does not follow that both should be able to modify everything.
Good software lets you calibrate permissions by role and by condominium, so the assignment reflects the practice's real organisation. This makes work tidier, reduces errors and simplifies checks: if something changes in a condominium, you know which profiles could act on it.
The owner: a private area for their own data only
The owner is a user outside the practice who, through the private area, consults exclusively what concerns them: their own instalments, their accounting position, the meeting documents and the minutes of their building. They must not be able to see the personal or financial data of other owners, in line with the minimisation principle.
Article 1130 bis of the Italian Civil Code grants owners the right to review accounting documents. A well-profiled private area makes this right exercisable independently, showing each person their own data without exposing others', and relieving the manager from the constant request for copies.
Setting roles and permissions without overcomplicating things
A software like AmministraPro is built with role-based access profiling and a dedicated private area for owners, so each figure sees only what they need without convoluted configuration. Anyone who wants to understand how roles and permissions are organised can review the capabilities on the features page and compare the plans on the pricing page.
- Start from the question: who must view or modify what, and why.
- Assign each staff member only the condominiums in their remit.
- Distinguish read-only permissions from editing ones where it makes sense.
- Protect the managing controller's account with particular care.
- Periodically review roles and revoke access no longer needed.
- Offer owners a private area limited to their own data only.
Frequently asked questions
Why not give all staff access to all condominiums?
Because it clashes with the GDPR minimisation principle, under which each staff member should handle only the data needed for their tasks. Indiscriminate access multiplies the risk in case of error or account compromise and makes it harder to know who could act on a given piece of data. Limiting access to the assigned condominiums is safer and tidier.
Can an owner see other owners' data in the private area?
In software with properly profiled access, no. Each owner sees only their accounting position, their instalments and the documents that concern them, not those of other owners in the same building. This is consistent both with the GDPR minimisation principle and with the right of access to documents under Article 1130 bis of the Italian Civil Code, which concerns one's own data.
Who assigns and revokes staff permissions?
As a rule the managing controller, whose role has the broadest privileges, configures access and updates it when the practice's organisation changes. It is good practice for this activity to follow a clear procedure, so that assigning and revoking permissions stays traceable and does not depend on informal steps that are hard to reconstruct.
Is it worth distinguishing read permissions from editing ones?
Where it makes sense, yes. Some staff only need to consult information, others need to record or modify it. Distinguishing read-only from editing reduces the risk of unintended changes and better reflects each person's actual tasks. There is no need to overcomplicate the scheme: a few clear categories consistent with the practice's organisation are enough.
How often should assigned roles be reviewed?
It helps to do it periodically and whenever something changes: a staff member leaving the practice, a condominium moving to another manager, a new task. Reviewing roles lets you revoke access no longer needed, reducing the risk surface and keeping the permissions map aligned with the organisational reality.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
