Building operations depend on many people working together: administrators, committee members, residents, and service providers. They need access to the information and tools relevant to their responsibilities, but not every user should be able to perform every action. With PropOrdo V2, user permissions are more clearly structured, giving organisations a more precise way to manage access across their building operations.
Why user permissions matter in strata management
Property and strata management platforms bring together sensitive information and important operational workflows. Teams may coordinate maintenance, review financial information, manage documents, communicate with residents, and make decisions about shared assets. When access rules are unclear, users can be blocked from work they are responsible for, or receive access beyond what they need.
A well-defined permission model helps organisations answer two practical questions: who is this user within the organisation? and what actions are they allowed to take on this type of information? PropOrdo V2 brings these questions together through roles and more specific permissions.
Roles establish the user's access context
A role describes a user's position in an organisation, such as administrator, contributor, or member. Roles remain an important first check: they determine which users can enter a particular workflow or resource area. This makes role-based access useful for broad eligibility and organisation-level context.
However, a role on its own may be too broad for a growing organisation. Two people with the same role may need different access to finance, documents, workflows, or communication. That is where permission scopes provide additional control.
Permissions add action-level control
PropOrdo's permission model assigns access by business module, submodule, and action. The action permissions include Create, Read, Update, and Delete. This structure lets an organisation distinguish between viewing information and changing it, and between one resource area and another.
- Create: permission to add a supported record or item.
- Read: permission to view supported information.
- Update: permission to change supported records.
- Delete: permission to remove supported records.
For example, a user may be allowed to read a workflow-related record without automatically receiving permission to update or delete it. The exact access depends on the user's role, the relevant module and submodule, and the action being requested.
How PropOrdo checks access
When a protected endpoint is requested, PropOrdo first uses the guard to resolve the organisation context associated with the resource. It then checks whether the user's role is eligible for that endpoint. Where the endpoint declares a module and action permission, PropOrdo also checks that the user's organisation role has the matching permission for the applicable submodule.
This distinction is important: the guard used to find the organisation is not always the same as the permission submodule. For an organisation-level request that acts on a workflow, for example, the organisation may be resolved from the route while the permission check targets the workflow submodule. Keeping those purposes explicit helps access rules match the resource and action the endpoint actually handles.
What this means for administrators
Administrators can manage access with a clearer view of what each permission represents. Instead of treating access as a single all-or-nothing setting, they can reason about the business area, the resource type, and the action required. This supports more deliberate access reviews as committee membership, responsibilities, or service arrangements change.
Permission management is also useful when responsibilities are shared. A team member who needs to review information may not need the ability to edit it. Separating read access from create, update, and delete access gives organisations a more useful foundation for assigning access according to actual work.
What contributors and members should expect
Users may see different access depending on their role and the permissions configured for their organisation. A visible feature or familiar role name does not necessarily mean every action is available. If an action is restricted, the user should contact their organisation's administrator to confirm the intended access and responsibilities.
Organisations should review access when someone joins or leaves a committee, takes on a new responsibility, or no longer needs access to a particular area. Regular reviews help keep permissions aligned with current responsibilities rather than relying on outdated assumptions.
A stronger foundation for accountable operations
PropOrdo V2's structured role and permission model is designed to make access decisions more specific and easier to reason about. Roles establish who may enter a workflow; module, submodule, and action permissions determine what that user may do within the applicable area. Together, these checks support clearer boundaries around building information and operational actions.
For strata committees, owners corporations, and property teams, clarity over access is part of good governance. It helps users understand their responsibilities, supports more consistent administration, and provides a practical framework for managing access as an organisation changes.
Explore PropOrdo V2
PropOrdo brings building information and operational workflows into a shared platform for property teams and communities. To learn how PropOrdo can support your organisation's processes, request a demonstration.