Founder & Lead Engineer, RAITHub
A tenant portal needs five features tenants return to: paying rent with a visible status, submitting maintenance requests by priority, reading the lease and documents, seeing payment history with receipts, and reviewing move-in and move-out inspections. Everything else is secondary. Each feature must show the tenant only their own lease, which is an authorization problem before it is a design one.
This guide is for PropTech founders and product teams building the tenant side of a property management product. It draws on PropDesk, the property management platform RAITHub built for landlords with 1 to 50 units, which has 4 user roles (landlord, tenant, contractor and admin), collects rent through Stripe and runs 1,024 automated tests. RAITHub does not publish PropDesk usage analytics, so where this post talks about how often tenants use a feature, it is engineering reasoning from the product's design, not measured data.
What features does a tenant portal app need?
The features that answer the questions a tenant actually has: what do I owe, has my payment gone through, when will my repair be done, and where is my lease. PropDesk's tenant portal covers exactly these (PropDesk case study).
| Feature | The tenant's question | In PropDesk's tenant portal | First release? |
|---|---|---|---|
| Rent payment | What do I owe, and has it gone through? | Yes, via Stripe | Yes |
| Maintenance requests | Has anyone seen my repair, and when will it be done? | Yes, submitted by priority: Emergency, Urgent or Routine | Yes |
| Lease and documents | What did I sign, and when does it end? | Yes | Yes |
| Payment history and receipts | Can I prove I paid? | Yes | Yes |
| Move-in and move-out inspections | What condition was the unit in when I arrived? | Yes, inspection reviews | Second release, unless deposits are disputed often in your market |
| Rent reminders | When is rent due? | Yes, sent automatically before the due date | Second release |
| Lease e-signature | Can I sign without printing? | No, it is on PropDesk's roadmap | Later, through a signature provider |
| SMS notifications | Can I get alerts by text? | No, it is on PropDesk's roadmap | Later |
The last two rows matter as much as the first five. A tenant portal is judged on whether the core works every month, not on how many features it lists. PropDesk's own roadmap holds e-signatures, SMS through Twilio and tenant screening for later releases, because each one depends on a partner integration.
Which tenant portal features get used most often?
Rent payment, by design: it is the one task every tenant has every month. Maintenance comes next, driven by events rather than the calendar, and documents are opened rarely but matter a great deal when they are.
| Feature | How often a tenant needs it | What that means for the build |
|---|---|---|
| Pay rent, check status | Every month, on or near the due date | Must be fast on a phone, and its status must never be wrong |
| Maintenance request | When something breaks | Photo upload, a priority choice and a status the tenant can see |
| Payment history | A few times a year: tax time, a dispute, a new application | Downloadable receipts; every entry traceable to a payment |
| Lease and documents | At move-in, renewal and move-out | Reliable storage and access control; search is optional |
| Inspections | At move-in and move-out | Photos with timestamps, kept for the life of the tenancy and beyond |
This ordering is why the rent screen deserves the most engineering care. A tenant who pays and then sees "unpaid" loses trust in the whole product, and phones the landlord, which defeats the point of the portal.
How should tenants pay rent in the portal?
Offer card and bank debit, show the payment's real status at every step, and never show "paid" until the money has actually arrived. On Stripe's published US pricing, a domestic card costs 2.9% + 30¢ and ACH Direct Debit costs 0.8% capped at $5.00 (Stripe pricing), so on $1,500 rent the tenant or landlord pays $43.80 by card or $5.00 by bank debit.
Bank debit is cheaper but slower. Stripe describes ACH Direct Debit as a payment method that "can take up to 4 business days to receive acknowledgement of success or failure" (Stripe: ACH Direct Debit). The tenant portal therefore needs three visible states, not two:
- Processing. "Your payment of $1,500 is on its way. Banks take up to 4 business days." No late fee applies while it is processing.
- Paid. Receipt available, balance cleared.
- Failed. A plain reason, the balance reopened, and a button to pay another way.
One detail from the same Stripe page affects the portal directly: its product support list marks Stripe's hosted Customer Portal as not supported for ACH Direct Debit. If tenants should be able to change their bank account themselves, plan to build that screen, using Stripe's own payment components so the mandate, the tenant's authorisation to be debited, is shown and recorded for you. The full money flow, including late fees and reminders, is in building online rent collection.
How does the tenant portal fit with the other roles?
It is one of four views onto the same records. PropDesk has a landlord portal, a tenant portal, a contractor portal and an admin portal, from one codebase. The tenant portal is the narrowest of them, and that narrowness is enforced on the server, not by hiding buttons.
| Role | Sees in PropDesk | Must never see |
|---|---|---|
| Tenant | Own rent payments, maintenance requests, lease and documents, inspection reviews, payment history and receipts | Another tenant's lease, payments or requests |
| Landlord | Properties and units, leases, rent and financial tracking, maintenance assignment and contractors, vacancies and onboarding | Another landlord's portfolio |
| Contractor | Assigned work orders, job status, property and unit access details, completion confirmation | Rent, leases, tenant payments |
| Admin | Users, platform settings, audit trails, reporting | Nothing hidden, but every action logged |
The classic tenant-portal bug is changing a number in the URL, from /leases/1042 to /leases/1043, and seeing a neighbour's lease. OWASP calls this an insecure direct object reference and names the fix plainly: "implement access control checks for each object that users try to access" (OWASP IDOR Prevention Cheat Sheet). Random IDs help, but only as a second layer. A minimal version of the check, in TypeScript:
type Role = 'landlord' | 'tenant' | 'contractor' | 'admin'
interface Session { userId: string; role: Role }
interface Lease { id: string; landlordId: string; tenantIds: string[] }
export function canReadLease(session: Session, lease: Lease): boolean {
switch (session.role) {
case 'admin':
return true
case 'landlord':
return lease.landlordId === session.userId
case 'tenant':
return lease.tenantIds.includes(session.userId)
case 'contractor':
return false // contractors see work orders, never leases
}
}
// In the route handler: load, check, then return. A failed check returns 404,
// so the response does not confirm that the lease exists.
export async function getLease(session: Session, id: string, load: (id: string) => Promise<Lease | null>) {
const lease = await load(id)
if (!lease || !canReadLease(session, lease)) return { status: 404 as const }
return { status: 200 as const, lease }
}
A switch over a union type means the TypeScript compiler complains if a fifth role is added and nobody decides what it may see. The wider permission design is in SaaS authorization and RBAC design, and what to do when one customer can already see another's data is in users can see other tenants' data.
How should tenants sign in to a tenant portal?
With as little to remember as possible: an email link or a one-time code, invited by the landlord, tied to the lease. Tenants sign in rarely, often once a month, so a forgotten password is the most common support request a portal can create.
- Invite, don't self-register. The landlord adds the tenant to a lease and the invite creates the account. A stranger cannot sign up and claim a unit.
- Accessible authentication. WCAG 2.2, the W3C accessibility standard, includes success criterion 3.3.8, Accessible Authentication (Minimum), at level AA, which asks that sign-in not depend only on a cognitive function test such as recalling a password without an alternative (WCAG 2.2). An emailed link meets that easily.
- Thumb-sized controls. The same standard's criterion 2.5.8, Target Size (Minimum), sets a 24 by 24 CSS pixel minimum for most targets. Most tenants will pay rent from a phone.
- Former tenants keep read access. After move-out, a tenant still needs receipts and the move-out inspection, especially while a deposit is being settled. Make it read-only, not deleted.
Should a tenant portal be a mobile app or a web app?
For a first release, a responsive web app. Tenants open it a few times a month, many will never install an app for one landlord, and a link in an email or text reaches them at once. A progressive web app can be added to the home screen later without a store review. RAITHub builds web products, not native mobile apps, so if your plan depends on an app store listing, that part needs a different vendor.
What should a tenant portal leave out of the first release?
Anything that does not answer the tenant's four questions, and anything that needs a partner contract before it can work.
- Chat between tenant and landlord. A comment thread on the maintenance request does the job with a record attached. General chat becomes an unmoderated inbox.
- Community boards and amenity booking. Useful for large buildings, rarely for landlords with 1 to 50 units, PropDesk's market.
- Tenant screening, e-signatures and credit reporting. All on PropDesk's roadmap, all dependent on third-party providers and their terms.
- Native apps. See above.
The release plan for the whole product, not just the tenant side, is in property management software for small landlords.
How do you test a tenant portal?
Sign in as each role and try to reach what that role must not see, then test every payment state. PropDesk's 1,024 automated tests are 932 unit and 92 end to end. For a tenant portal, these are the cases worth writing first:
| Test case | What must hold |
|---|---|
| Tenant A requests tenant B's lease, payment or request by ID | 404, and nothing in the response reveals it exists |
| Contractor requests a lease or payment | 404 |
| Bank payment submitted, still processing | Shown as processing; no late fee; no "unpaid" banner |
| Bank payment fails after four days | Balance reopens; tenant told why and offered another method |
| Two tenants on one lease | Both see the lease and the shared balance; neither sees the other's card details |
| Tenant moves out | Read-only access to receipts, documents and inspections; no new payments or requests |
| Invite link used twice, or after expiry | Second use rejected; expired link asks the landlord to resend |
The method behind this is in how RAITHub tests software.
Why RAITHub for this, and when you don't need us
RAITHub built PropDesk's tenant portal as one of four role-scoped portals on one codebase, with Stripe rent collection, maintenance by priority, inspections and 1,024 tests, and published those numbers so you can judge the work first. First releases are built under MVP development as fixed-scope projects, quoted in writing after a free 15-minute technical audit. You own the code, and an NDA is standard.
You don't need RAITHub if:
- You are a landlord who wants a portal for your own tenants. Every mainstream property management tool includes one. Buy it.
- You need native iOS and Android apps. RAITHub builds web applications, not native mobile apps.
- You need tenant screening or credit reporting live on day one. PropDesk has neither yet, and both depend on provider agreements and local rules. That is general information; confirm the rules with your adviser.
- You want developers placed in your team, or a certified vendor. RAITHub does not offer staff augmentation and is not SOC 2 or ISO 27001 certified.
If a tenant portal is part of the product you are building, book the free 15-minute technical audit with your roles and your rent flow. The PropTech page and the PropTech software development guide set out the wider build.
Stripe, OWASP and W3C sources checked on 29 September 2026.
Frequently asked questions
What features should a tenant portal have?
Rent payment with a visible status, maintenance requests by priority, lease and document access, payment history with receipts, and move-in and move-out inspection reviews. PropDesk's tenant portal covers all five.
What is the most used feature of a tenant portal?
By design, rent payment, because every tenant has it every month. RAITHub does not publish PropDesk usage data; the ordering comes from how often each task occurs, not from measured analytics.
Should tenants pay rent by card or bank debit in the portal?
Offer both. On Stripe's published US pricing, a card costs 2.9% + 30 cents and ACH Direct Debit 0.8% capped at $5.00, but a bank debit can take up to 4 business days to confirm, so show it as processing.
How do you stop one tenant seeing another tenant's data?
Check on the server, for every record, that the signed-in user is on that lease, and return 404 otherwise. OWASP's guidance on insecure direct object references says the same: access control checks for each object.
Does a tenant portal need a mobile app?
Not for a first release. A responsive web app reaches tenants through a link, and a progressive web app can be added to the home screen later. RAITHub builds web applications, not native apps.
How many roles does PropDesk have?
Four: landlord, tenant, contractor and admin, each with its own portal from one codebase. The tenant portal covers rent payments via Stripe, maintenance requests, lease and documents, inspections and payment history.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.