Secrets Management for a Property Manager's Tenant Systems
Most property management companies don't have a real Doppler-versus-Vault decision to make, because their technology footprint doesn't need either tool's full weight. The actual risk sitting underneath that question is simpler and more common: a shared login that's outlived three site managers, still active, still working, and nobody's sure who currently knows it.
The Pitfall: A Shared Login That Outlives Three Site Managers
Site-level staff turnover is normal in property management, and the easiest habit to fall into is reusing one login across every new hire at a property rather than creating individual accounts. Years later, that login has been known by people who no longer work there, and nobody can say with confidence who still remembers it.
What's Actually at Risk: Tenant Payment and Personal Data
The systems behind that shared login usually include a resident portal with payment information and a database of tenant personal details, both of which carry real consequences if exposed. The property management software itself may be reasonably secure; the risk is almost always in how loosely access to it has been controlled at the site level.
Where Doppler Fits a Property Manager's Small Tech Footprint
If your team maintains even a light integration layer, a script pulling maintenance requests into a dashboard, or a connection between your property management software and a rent payment processor, Doppler gives you a simple place to store those few credentials without building infrastructure you don't need.
Where Vault Is Probably More Than You Need
Vault's dynamic secrets and self-hosted operational model solve problems that come with running your own infrastructure at scale, and most property management companies simply aren't running that kind of infrastructure. Unless you're building substantial custom software around your portfolio, the setup and maintenance burden of Vault outweighs anything it would add over a simpler tool.
A Rotation Checklist Tied to Staff Turnover, Not the Calendar
Change any credential a departing site manager had access to on their last day, not at the next scheduled review. Keep a short list, by property, of who currently has access to what, and check it every time staff turn over at a site. This single habit closes the gap that causes the most real risk in property management technology.
When a site manager leaves, work through these steps:
- Change every credential the departing manager had access to on their last day, not at the next scheduled review.
- Keep a short list by property of who currently has access to what, and check it each time staff turn over.
- Move to individual logins per staff member where the software supports it, instead of introducing another shared one.
- Separate credentials by system rather than keeping them all in one shared note or spreadsheet tab.
- Find out who holds the building access system credentials and whether the installing vendor's default account is still active.
A Common Mistake: Storing a Vendor Password Next to the Wifi Password
A common habit at the property level is keeping every password a site needs, the building's wifi, the alarm system, a vendor portal login, in one shared note or spreadsheet tab that any staff member can open. It's convenient, and it's exactly why a single departing employee can walk away with access to far more systems than their role actually required.
Separate credentials by sensitivity, not just by convenience: the wifi password isn't the same risk as a login that can view tenant payment history, and storing them identically treats them as though they were. Even a simple step, like a distinct, access-controlled note for anything touching tenant financial or personal data, meaningfully reduces what a single leak exposes.
A Worked Example: Rebuilding a Site's Access List From Scratch
Pick one property and, without looking at any existing documentation, list every system a current site manager can access: the property management software, the maintenance request app, the payment processor's dashboard, the building's alarm panel. Then compare that list against what the current staffing actually requires, and you'll usually find at least one system a departed employee's credentials could still reach.
Doing this exercise once, property by property, surfaces gaps a calendar-based review misses, because it starts from what access actually exists rather than from what you assume was already cleaned up. Repeat it whenever a site changes management, not on a fixed annual schedule, since staffing changes are what actually drive the risk.
Who Holds the Building Access System Credentials Today
Beyond the tenant portal and accounting software, a property manager usually has a smart lock system, a building access panel, or a video system with its own admin login, often set up years ago by whichever vendor installed the hardware and rarely touched since.
Find out who currently holds that credential and whether it's still the installing vendor's default account. If a maintenance vendor's technician still has standing access to a building's lock system from a job that ended a while back, that's a bigger exposure than most of the software credentials this decision is usually about.
Fold these physical-system logins into the same rotation and offboarding habit you apply to the tenant portal and property management software. They're easy to forget precisely because they're touched so rarely, which is exactly why they're worth checking first.
When you take over management of a new property, make a physical-system credential audit part of the transition checklist, right alongside setting up the tenant portal and the accounting software login.
What Good Looks Like
A property manager retires a shared login the same day a site manager leaves, keeps tenant payment integrations on their own credentials separate from the property management software's login, and can name who has access to each system at any time.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Frequently Asked Questions
Does a property management company need a dedicated secrets vault at all?
Most don't need a full platform like Vault. Even a small company benefits from an organized place to store the handful of credentials tied to integrations such as a rent payment processor, rather than a shared document or a login written down at the front desk.
What should happen to shared logins when a site manager leaves?
Change the password immediately and, where the software supports it, move to individual logins per staff member instead of reintroducing another shared one. Waiting until the next scheduled review leaves a known, working credential active in the hands of someone no longer employed there.
Are integrations with a rent payment processor a bigger risk than the property management software itself?
Often yes, because the property management software vendor typically maintains its own security, while the credentials connecting it to a payment processor are usually managed internally, with far less oversight and a higher chance of being shared informally between staff.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
HashiCorp Vault vs AWS Secrets Manager vs Doppler: Secrets Platforms
Compare Vault, AWS Secrets Manager, and Doppler for secret sprawl prevention, dynamic credential rotation, Kubernetes injection, and SOC 2 audits.
SOC 2 for Commercial and Multifamily Property Managers
Why institutional owners are asking property management companies for SOC 2, and how Vanta, Drata and Secureframe fit tenant and leasing systems.
Database Infrastructure for Commercial Property Managers
Commercial and multifamily property managers integrating with PM software have specific database needs. Here's how Supabase and AWS RDS compare.
Building a Rollout Worksheet for a Tenant Portal Update
Commercial and multifamily property managers can roll out a tenant portal change property by property. A worksheet for deciding between LaunchDarkly and Split.
AppSec Choices for Property Managers Running Tenant Software
A criteria-based look at Snyk versus GitHub Advanced Security for property managers running tenant portals, vendor systems, and smart building tech.
CrowdStrike vs SentinelOne for Property Management Firms
A property manager's endpoints are scattered across dozens of leasing offices with no local IT staff. How CrowdStrike and SentinelOne fit that reality.