Security & privacy

Access modes: owner-operator, property-managed, and HOA

← All guides

Security & privacy · 2 min read · from the Veni help library

Where to find it

Open Settings, then the Access control tab. A banner at the top names your organization's management mode and states its default ceiling. There are two sub-views underneath: Reach (view / manage), which controls what each user type can open in the portal, and Visibility (identity), which controls how identified the data they see actually is.

The three modes

Your organization is set to one of three modes, and it sets a ceiling that admins can only tighten, never loosen, when editing individual cells in the visibility matrix:

  • Owner-operator: staff resolve fully identified data by default. You can restrict individual roles or sections further, but the starting point is full identity.
  • Property-managed: resident activity is de-identified by default, meaning staff see events happening, not who they happened to. You can tighten specific cells beyond this, but never loosen past the mode's default.
  • HOA governance: activity is aggregate and the resident roster is pseudonymous by default. Per-unit identity is only available through a logged Access Investigation, and cells can be tightened further but never loosened past this ceiling.

Access control mode banner showing the organization's management mode and ceiling noteAccess control mode banner showing the organization's management mode and ceiling note

How HOA mode gates identity

In HOA governance mode, the board cannot simply look up who lives where. A board member with manage access to Investigations opens a new investigation by picking a building and unit, choosing a basis (suspected short-term rental, unauthorized occupant, security incident, or bylaw/rule violation), and entering a reason. While the investigation is open, it unlocks that unit's activity for the requester. Every open and close is logged, and the affected resident is disclosed to per your organization's policy.

Opening an investigation requires manage access on the Investigations section specifically. A view-only grant lets you see existing investigations but not open new ones.

Reach versus Visibility

The Reach view answers "can this role open this section at all," while the Visibility view answers "how identified is the data they see once they're in it." A role can have manage-level reach into Activity while still seeing a de-identified feed, because visibility is capped by the organization's mode regardless of what reach level is granted. In Reach, Management Admin is always locked to Manage; that column can't be edited down. In Visibility, Management Admin is capped by the mode like every other role: in owner-operator mode Admin resolves full identity by default, but in property-managed mode Admin sits at the same pseudonymous ceiling as staff on front desk, guest passes, packages, activity, and alerts, and in HOA governance mode Admin's ceiling is aggregate on most sections and pseudonymous on the resident roster and activity, with per-unit identity still gated behind a logged Access Investigation.