Before we build, we need to understand exactly where we're starting. Here is your current technology landscape as confirmed during our March 18 discovery session.
- Email (team-core.com domain)
- Calendar (shared team calendars)
- Google Drive (organized by client/property)
- Google Chat (team communication)
- Google Docs & Sheets
- 60+ properties (GL and P&L)
- Tenant lease administration
- Rent collection & bill payment
- Work order management
- Financial tracking & reporting
- Database API available
- Investor contributions & distributions
- Tax documents & positions
- Investor portal (monthly reports)
- Contains PII: Tax IDs, SSNs, bank accounts
- Data automatically pushed to Property Manager — no AI connection needed
- Additional financial tracking
- Company accounting
- Property/market research
- Comparable transactions
- Third-party platform — future phase
- Excel (financial models, budgets)
- Word (lease documents, letters)
- Used alongside Google tools
Matt, Kevin
Phil, Sam
Managers
Amanda, Zach
Team
- Gmail (team-core.com)
- Google Drive
- Calendar
- Docs & Sheets
- Google Chat
- Lease administration
- Tenant data
- GL & P&L
- Work orders
- Rent collection
- Comps & research
- Market analytics
- Third-party platform
- Investor PII (SSNs, Tax IDs)
- Bank accounts
- Contributions/distributions
- AppFolio PM: leases, tenants, financials, work orders
- Google Drive: executed lease PDFs, property files
- QuickBooks: financial summaries (read-only)
- Authentication (2FA required)
- Data sanitization (PII redaction if needed)
- Role-based access control (who sees what)
- Claude API (Zero Data Retention)
- Your data never touches a public model
- No training on your data — ever
- Draft outputs held for team review
- AI gets you 90%, you do the last 10%
- Approval required before any external communication
- Generated documents stored in Google Drive
- Audit trail logged
- All encrypted at rest (AES-256)
- TLS 1.2+ in transit
- Investor PII (Tax IDs, SSNs, bank accounts)
- Contribution/distribution records
- Investor portal & tax documents
Data that benefits the AI agent is automatically pushed to Property Manager. The sensitive investor data stays in its own secure environment.
"The risks associated with tying AI to this would be too great. At least not now." — Matt Farrell, CEO/Partner
- QuickBooks access = read-only financial data only
- No connection to actual bank accounts
- No payment processing through AI
The AI agent can read financial summaries to generate budgets and reports, but it has zero access to transact, move money, or view bank credentials.
All AI access requires 2FA. Every team member authenticates through Google Authenticator or SMS verification before any system interaction.
- Primary method: Google Authenticator app
- Backup method: SMS verification code
- Session timeout after inactivity
Different team roles see different data. Access is scoped to what each role needs — nothing more.
| Role | Team Members | Access Scope |
|---|---|---|
| Leadership | Matt, Kevin | Full portfolio access |
| Property Managers | Amanda, Zach | Building-specific access |
| Brokers | Phil, Sam | Transaction/lease data |
| Maintenance | Maintenance team | Work orders only |
All data is protected at every stage, whether sitting in storage or moving between systems.
- At rest: AES-256 encryption (military-grade standard)
- In transit: TLS 1.2+ for all data transfers
- API keys: Stored in encrypted vault, rotated regularly
- Zero retention: Claude API does not store processed data
Every AI action is logged. Full accountability with a complete paper trail for compliance.
- Timestamp: When the action occurred
- User: Who initiated it
- Action type: What was requested
- Data accessed: Which records were involved
- Output: What was generated