What a role actually does in PropFlow today, how the list grew to ten, what AppFolio, Yardi, RealPage, EliseAI and our own customers call these jobs, and the six roles we should start with before Western Slope, Situs Group and ConAm sign in next week.
2026-09-10, rewritten late evening after Fede's rulings · decision 1 decided (the six) (roles are the job a person holds in their company; no accounting role now; minimum set, add later) · all three decisions decided (Sep 10–11) · podcast episode (6 min)
Six roles, named the way the industry names the jobs. Organization Admin, Regional Manager, Property Manager, Leasing Agent, Maintenance Technician, Owner. Every one of those words appears in AppFolio's own standard role list or in our customers' own org charts. Ten names today collapse to these six; one shared list feeds every screen; a guard test stops anyone from writing their own copy again. The catalog, the guard test and the six-role flip are merged.
A role is one word stored on a person's membership in a company. That one word is read in eight different places. Only the first is "just UI".
Two things a role does not control, and should not: what a company has paid for (their modules; ruled Aug 25 and Sep 7: entitlement is the outer gate, a role only narrows inside it) and whose AppFolio login is on file for a building (a technical field that happens to be named "owner" in the code; Gera's design says it must never appear in a roles list).
| Where a role is picked | What it offers | Why it differs |
|---|---|---|
| Onboarding wizard, "Add your team" | 5: Property Manager, Leasing Agent, Maintenance, Accounting, Viewer | Hand-written short list; admin and regional were pushed to Settings "for later" |
| Settings → Team (customer's own admin) | 7 to 10 depending on who is inviting | Computed live from the invite ladder; the only screen that never drifts |
| Back office → Customer → "+ Invite person" | 3: Organization Admin, Property Manager, Leasing Agent | Hand-written, deliberately narrow |
| A second invite screen in the code | all 10 | dead nothing links to it; a second copy of invite logic waiting to be re-wired by accident |
Read from the production user table on Sep 10 (counts only, no names).
| Role | People |
|---|---|
| Platform Admin (PropFlow staff) | 5 |
| Property Manager | 3 |
| Viewer | 1 |
| No role stored at all (retired column; see correction below) | 12 |
| Organization Admin, Leasing Agent, Maintenance, and the four title-only roles (retired column; Kenya in fact holds Regional Manager) | 0 |
| When | What changed | Roles |
|---|---|---|
| Mar 17 | First roles system for the pilot: admin, property manager, assistant manager, leasing agent, maintenance supervisor, maintenance tech, viewer | 7 |
| May 10 | The company model (the old design Fede remembers): "admin" split into PropFlow staff vs. a customer's own admin; the maintenance pair and the assistant collapsed | 6 |
| Aug 19 | Four "team title" labels added so a teammate's job title could be shown, with a ruling that relabelling must never take a feature away, so all four were wired to equal Property Manager | 10 |
| Sep 10 | Fede pauses roles; inventory, handoff, this audit | 10 |
Fede's rule: a PropFlow role is the job a person holds in their company, in the words the industry uses. So the question is not what abstraction is cleanest, it is what the people at Western Slope, ConAm and Situs already call each other. Four sources, from most to least binding for us.
AppFolio ships 13 standard user roles, customisable per company; Plus-tier customers can also copy a role under a new name. Owners are not users at all: they get a separate Owner Portal with its own per-owner permissions (dashboard, reports, documents), which is the same shape in Buildium, RealPage and Yardi.
| AppFolio role | In one line | Ours |
|---|---|---|
| President | Everything, including managing users and sensitive personal data | Organization Admin |
| Regional Manager | Starts as Property Manager, meant to be widened for people with more authority | Regional Manager |
| Property Manager | Full edit on properties, tenants, vendors, owners; limited accounting | Property Manager |
| Assistant Property Manager | Property Manager minus deleting things | not yet (most likely first addition) |
| On-Site Manager | Property Manager without owner info, view-only reports | folds into Property Manager |
| Leasing Agent · Assistant Leasing Agent | Leasing, receipts and charges; assistant cannot delete | Leasing Agent |
| Maintenance Coordinator · Maintenance Technician | Coordinator: all maintenance and vendors. Technician: only their own work orders, mobile view | Maintenance Technician (one role for now) |
| Accountant · Accounts Payable · Accounts Receivable | Accounting roles | none (Fede, Sep 10: not now) |
| View Only | Sees properties, tenants, vendors, maintenance; no accounting | Owner (view only) |
| Owner Portal (not a role) | Per-owner permissions: dashboard, reports, documents | Owner, for now; Gera's ownership record later |
| Job | Institutional multifamily (RealPage, Entrata, NAA) | Third-party / small operators (AppFolio, Buildium, Yardi Breeze) | AI leasing tools (EliseAI, Funnel) |
|---|---|---|---|
| Top of a customer's account | Global / Organization Admin | President, Administrator, Admin | Organization Admin (EliseAI), Admin (Funnel) |
| Oversees several buildings | Regional Manager, Regional Property Manager, Portfolio Manager (NAA credential: CAPS) | Regional Manager | Owner tier (EliseAI, above Community Admin) |
| Runs one building | Community Manager (NAA credential: CAM) | Property Manager | Community Admin (EliseAI) |
| Leases | Leasing Consultant, Leasing Professional (NAA credential: CALP) | Leasing Agent | User (Funnel), Agent |
| Fixes things | Maintenance Supervisor, Maintenance Technician (NAA credential: CAMT) | Maintenance Coordinator, Maintenance Technician, Maintenance User | n/a |
| Owns the building | Owner Portal, Asset Manager | Owner Portal, Rental Owner | Owner (EliseAI) |
Yardi Voyager, Entrata and Rent Manager ship configurable security groups rather than fixed names; the job names above are what their customers configure. EliseAI's documented roles: Organization Admin, Community Admin, Owner, Delinquency Agent, Analyst.
| Company | Person | Their title | Our role |
|---|---|---|---|
| Western Slope | Jason Fish | Managing broker / partner | Organization Admin |
| Western Slope | Jay Taylor | Partner (asked today: "can you designate two admins?") | Organization Admin |
| Western Slope | Kat Barker | Leasing manager | Property Manager, or Leasing Agent if she should not see maintenance |
| Western Slope | Beverly | "Assistant PM", Kat's virtual assistant | Leasing Agent |
| ConAm / Yale 25 Station | Dara Johnson | Regional portfolio manager (Sean: "global admin… might be Dara") | Organization Admin, or Regional Manager (decision 2) |
| ConAm / Yale 25 Station | Jaise Sylva | Community manager | Property Manager |
| JP&Co | Kenya | Regional manager | Regional Manager |
| Ownership side | Sean's father; Sean for JP&Co | Owner who wants to watch | Owner |
Every word below is either an AppFolio standard role or a title one of our customers uses today. "Property Manager" rather than "Community Manager" because AppFolio, Buildium and two of our three customers say Property Manager; the hint text can say "community manager" for ConAm-style shops. "Leasing Agent" rather than "Leasing Consultant" for the same reason. Which buildings a person covers stays a separate setting on their membership, because Kat covers every Western Slope building and Jaise covers one.
| Role | Today | Proposed |
|---|---|---|
| Organization Admin | exists, wired | unchanged |
| Regional Manager | a label equal to Property Manager, plus it may invite Property Managers | becomes real: Property Manager permissions across every building in the company, plus inviting and managing on-site staff. No billing, no company settings. AppFolio describes it the same way: "starts as Property Manager, widened for people with more authority" |
| Property Manager | exists, wired | unchanged; hint mentions "community manager" |
| Leasing Agent | exists, wired | unchanged |
| Maintenance Technician | exists as "Maintenance", wired | label only; one role covers coordinators and technicians until a customer needs AppFolio's split |
| Owner | exists as "Viewer", wired (read-only everywhere, read-only Clara tools, never paged) | label only, plus reach limited to the buildings they own. Gera's ownership record replaces the manual scoping later; nothing to undo |
| Accounting, Assistant Property Manager, Leasing Assistant | labels equal to Property Manager, nobody uses them | no longer offered; values stay valid in the database, nobody renamed |
Fede asked how to consolidate roles into one place and make sure nobody adds their own list again. The answer has two halves, and the first is being built tonight as a dark change with no visible difference.
Answers save for everyone who opens this page. Already ruled today and not re-asked: roles are named for the job a person holds in their company; no accounting role now; start minimal and add later.
Live code at the main branch on 2026-09-10: the role list and permission tables (src/lib/platform/auth/permissions.ts, permissions-source.ts), the three pickers, the staff-recognition list Clara uses, the tool authorisation matrix, the invite and accept endpoints. The company-model design record from May 10. The Sep 10 roles inventory and handoff on the onboarding hub; production user counts read on Sep 10 by that inventory. Today's standup, raw per-speaker transcript (Fede, Gera, Sean). AppFolio help center: "User Roles in AppFolio", "Manage User Roles and Permissions", "Adding Maintenance Technician Users", "Owner Portal Permissions" (local knowledge-base copies). Yardi Breeze custom-roles post; Buildium "User Roles and staff member access"; RealPage OneSite and Entrata product docs; EliseAI SSO role-mapping article; NAA credentials pages (CALP, CAM, CAPS, CAMT); IREM ARM/CPM. Design-partner contacts on the onboarding hub. Gera's portfolio architecture design, people section. A direct read of JP&Co's AppFolio role settings was attempted and stopped: the login breaker was tripped from two earlier failures today, so the help-center article stands in for it. This page is a second page next to the hub on purpose: Fede asked for one short, standalone read with diagrams to decide on, and the hub is a running log.