← All articles

Who Should See What? Setting Up User Roles and Permissions for Compliance Records

admin workflow

Who Should See What? Setting Up User Roles and Permissions for Compliance Records

Most letting agencies start with one login. One person — often the office manager, sometimes the owner — holds the password, checks the reminders, and books the contractors. It works fine when the portfolio is forty properties and one office.

It stops working somewhere around eighty. That's roughly where a second property manager joins, a branch opens, or a landlord asks "can I just log in and see my own certificates?" — and the single-login model turns from a shortcut into a liability. This post is about what to do before that happens, not after.

Why "everyone shares one login" quietly becomes a risk

A shared login isn't just inconvenient, it's an audit trail problem. If a certificate gets marked as booked, uploaded, or dismissed, and three people had access to that account, nobody can say with confidence who actually did it. That matters more than it sounds — if a council or a tenant's solicitor asks "who reviewed this EICR and when," "someone on the team, at some point" isn't a good enough answer.

It's also a training and mistake problem. New starters get the same access as a ten-year property manager, which means the same ability to permanently delete a record or mark a Gas Safety check as complete without ever seeing the actual certificate. And it's a departure problem: when someone leaves, changing a shared password means messaging everyone who uses it. Most agencies just... don't, and the account sits open long after someone's left the building. If that describes your setup, it's worth pausing here before moving on — a shared login with a departed staff member still active is the single most common gap we see when reviewing an office's access.

What separating roles actually buys you

CertMinder UK supports multiple named users per account, each with their own login and a role that determines what they can see and do. The point isn't bureaucracy for its own sake — it's matching access to responsibility, so the system reflects how the office actually works rather than how convenient it was to set up on day one.

A sensible starting structure for most letting agencies looks like this:

Admin / office manager — full access: can add and remove users, edit certificate records, approve work orders, and see every property across every branch. This should be a small list of people, not the whole office.

Property manager — full access to the properties they're assigned to, including uploading certificates, booking contractors through the work-order flow, and dismissing reminders once genuinely resolved. No access to properties outside their patch, and typically no ability to add or remove other users.

Read-only / landlord view — can see the current status and certificate history for their own properties, but can't edit, upload, or dismiss anything. This is the role that answers the "can my landlord just log in?" question without handing over editing rights to someone who isn't managing the compliance day-to-day.

Contractor-facing access, where it's used, should be narrower still — visibility into the specific work order they've been assigned, not the wider property file.

The exact labels matter less than the principle: access should follow the property assignment and the job, not the org chart from three reshuffles ago.

Getting the transition right

If you're moving off a shared login, do it in one sitting rather than gradually — a half-migrated system, where some people still use the old shared credentials and others have new named logins, is worse than either extreme on its own, because nobody's sure which account did what during the overlap.

Start by listing who actually needs access and to which properties, not who's always had it. It's a reasonable moment to notice that a former employee, a departed contractor, or someone who moved to a different branch still has a live login. Set roles deliberately rather than defaulting everyone to admin because it's the fastest option — it's the fastest option today and the thing you have to unwind in six months.

Once roles are set, the audit trail does the rest of the work. Every certificate upload, dismissal, and work-order approval is tied to the person who did it, which is exactly the record you want to be able to produce if a compliance question ever gets formal.

A word on why this matters beyond neatness

CertMinder UK doesn't take referral fees from the contractors you book, and we're not going to pretend permissions are exciting. But access control is one of the few genuinely structural things a compliance system can get right or wrong for you. Visibility isn't a feature you bolt on later — it's the baseline the rest of the system depends on, and that includes visibility into who on your own team did what.

None of this is legal advice — for questions about your specific regulatory or contractual obligations around record-keeping and data access, check current government guidance or speak to a qualified adviser. But from a workflow standpoint, the fix here is genuinely simple: give each person the access their job needs, nothing more, and let the system remember who did what so you don't have to.

Never miss a compliance deadline

CertMinder UK tracks every certificate and tenancy document across your properties and reminds you before anything expires.

Start free trial