How to Verify PM Data Isolation
-
Navigate to the sign-in page.

-
In the Email address field, enter PM-A’s email address.
-
In the Password field, enter PM-A’s password.
-
Select Sign in.

-
On the PM dashboard, verify that only PM-A’s properties, leases, and tenants are visible.
-
Navigate directly to a PM-B property URL (for example,
/dashboard/properties/[PM-B-property-id]). -
Verify that access is denied. No data, titles, or partial snippets from PM-B are visible. [SCREENSHOT NEEDED HERE]
What to expect
Only PM-A’s own properties, leases, and tenants are displayed. Attempting to access PM-B’s data via direct URL returns an access-denied or not-found response with no data leakage. Cross-role dashboard access is blocked.
Need help?
| Symptom | Cause | Fix |
|---|---|---|
| PM-B’s data appears on PM-A’s dashboard | Backend permission filter misconfiguration | Verify can_access_property enforces property_manager_id == user.id |
| Direct URL to PM-B property shows data | Permission check bypassed | Verify Django permission class is applied to the endpoint |
