Skip to content
Keeping control of your dataLesson 19 of 22

Academy/Technology

Admin credentials

The login that can add, remove, or reconfigure everything, not just view it.

Admin credentials are the login and permission level that lets someone add, remove, or reconfigure users and data in an association's software, not just view it. The board, not a manager or a vendor, should control who holds that level of access, and losing track of it creates a data problem and a compliance problem.

01

What "admin" actually controls

Most HOA software has two tiers of access. An ordinary user, an owner checking their balance, a director reading a posted document, can look at what is theirs and maybe submit a request. An admin account can add or delete other users, change payment settings, export the entire membership list, or reset everyone else's password. That second tier is what this lesson means by admin credentials: the login that lets someone reconfigure the system itself, not just use it.

Every tool the association runs, the owner portal, the accounting platform, the website, the online payment system, has its own admin account somewhere. If nobody on the board can say who holds each one, or how to get back in without the person who originally set it up, the association does not actually control its own systems, no matter how good the software is.

02

Who should hold the keys, especially at a transition

The safer default is that the board holds, or can immediately reclaim, admin rights to every system that touches owner data or association funds, even when a management company operates the account day to day. That matters most at a transition, when a management contract ends or the person who built the portal moves on. One management-industry transition guide puts the underlying principle plainly:

"Your homeowners association's funds and documents belong to the board, not to whoever happens to be managing them at the moment."

Source: HOA Management Company Transition Checklist for Boards, RowCal

Treat that as sound practice to negotiate into every management contract, not as confirmed law in your state. Before signing or renewing a contract, get in writing who holds admin rights during the relationship, and how credentials and data get handed over if the relationship ends. See Switching software and Avoiding vendor lock-in for what else belongs in that clause.

03

Why this is compliance, not just IT hygiene

Admin access is not only a convenience question. It is a data-security question with legal deadlines attached in some states. California requires that once a business discovers a breach exposing unencrypted personal information, it act inside a fixed window:

"The disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach."

Source: California Civil Code section 1798.82, California Legislature

Whether a breach notification law like this applies to your association, and how many days it gives you to act, depends on your state. Check your state's statute. Either way, an old admin account nobody remembers to close is one more door into that data, and closing it is cheaper before a breach than after one.

The same logic reaches payment admin access. The Payment Card Industry Data Security Standard applies to:

"Entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD) or could impact the security of the cardholder data environment (CDE)."

Source: PCI Data Security Standard, PCI Security Standards Council

A payment portal built by a web developer, not a dedicated processor, can put the association's own admin access in scope even though no board member ever sees a raw card number.

Check yourself

Answer before you read the explanation, recalling it is what makes it stick.

Your management company changes hands mid-contract and won't share the admin login for the resident portal. What should the board do first?

A former board member still has admin access to the accounting software four months after leaving. What should concern the board most?

The association takes dues through an online portal a local web developer built, not through a dedicated payment processor. Who is in scope for PCI DSS on that system?

Sources

Technology

Next, learn what to put in your contract so your data and credentials actually come back when you switch software.

Whether a breach notification law applies to your association, and how many days it gives you to act, varies by state. What your management or software contract says about returning admin credentials and data on termination varies by contract and should be checked directly.