Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Do We Stop Negotiators Who Have Left an Agency Keeping Access to Our Product?
Problems We Solve

How Do We Stop Negotiators Who Have Left an Agency Keeping Access to Our Product?

Proptech products leak access when agency staff leave and nobody tells you. We build leaver detection, SSO and admin tools so agencies control their own users.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Former negotiators keep access because agencies rarely tell their software suppliers when someone leaves, and your product only removes users when asked. We build agency-controlled user management, sign-in through Microsoft or Google where the agency uses them, signals that flag likely leavers, and a regular access review the agency admin can finish in minutes.

A negotiator moves to the agency down the road

A senior negotiator leaves one agency on Friday and starts at a competitor on Monday. Their email account at the old agency is closed, but their login to your product used a personal email address and a password they saved on their phone. On Tuesday they can still see the old agency's applicant list, vendor phone numbers and the valuation pipeline.

Nobody at the old agency thought to tell you. The branch manager assumed closing the email account was enough. You only learn about it when the agency's director notices the login in an activity report weeks later, or worse, when a vendor mentions a call from the rival agency.

Why leavers slip through

Estate and letting agencies have high staff movement, particularly among negotiators and lettings staff, and people often move between agencies in the same town. Your product sits outside the agency's own IT, so it is easy to forget in the leaving checklist.

  • Users sign in with passwords you manage, not with the agency's Microsoft 365 or Google Workspace accounts, so closing their work account does nothing.
  • Some users registered with personal email addresses because it was quicker on the day.
  • Only your support team can remove users, so agencies email you and wait, or forget.
  • Branch managers do not know which of their staff have access to your product.
  • Accounts are shared between two people at busy branches, so disabling one breaks another.

What an open door costs

Agency data is commercially sensitive: vendors thinking of selling, applicants with their budgets, landlords and their portfolios. A leaver with access can take that to a competitor, and it is personal data too, which the agency is responsible for protecting and which you process for them. The damage to your relationship with the agency lands on you even when the agency forgot to tell you.

There is also a billing side. If you charge per user, departed staff may still be counted, and agencies notice.

Then there is the question an agency's director eventually asks: who had access to our data last year? If your product cannot answer that from its own records, the agency has to take your word for it, and a group with a data protection officer will not be comfortable doing that for long.

How we build access that follows the agency

What we build puts the agency in charge of its own users and makes leavers visible even when nobody reports them.

  1. Sign-in through the agency's Microsoft 365 (Entra ID) or Google Workspace where they use one, so closing a work account closes access to your product too.
  2. For agencies without that, work email verification and a rule that personal addresses need an admin's approval.
  3. An agency admin screen where the branch manager or office manager can add, suspend and remove users, and move them between branches, without contacting you.
  4. Leaver signals: a user whose work email starts bouncing, who has not signed in for a set period, or whose sessions suddenly come from a different network, is flagged to the agency admin.
  5. A quarterly access review sent to each agency admin, listing every user and when they last signed in, with a one-click suspend.
  6. An audit log of sign-ins and exports per user, so the agency can see what a departed user did and when.
SignalWhat happens
Work account closed (SSO agency)Access ends at next sign-in attempt
Work email bouncesUser flagged to agency admin
No sign-in for a long periodListed in access review
Sign-in from an unusual networkFlagged, optional extra check
Admin marks user as leaverSessions ended, user removed from billing

The next time someone leaves

The same negotiator leaves on Friday. The agency uses Microsoft 365, so when IT closes their account, their next attempt to open your product fails. At a smaller branch without SSO, the office manager gets a notice on Monday that a user's work email has started bouncing and suspends them with one click. The monthly invoice counts one fewer user without anyone emailing your finance team.

Is access control relying on agencies remembering?

  • Agencies have to email your support team to remove a user.
  • Some users sign in with personal email addresses.
  • You do not offer sign-in with Microsoft or Google.
  • Agency admins cannot see a list of their users and last sign-in dates.
  • You have billed agencies for users who left months ago.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do all agencies need Microsoft 365 or Google Workspace for this?

No. SSO covers those that have it; the admin tools, leaver signals and access reviews cover everyone else.

Can we force SSO for some agencies and not others?

Yes. It is a setting per agency, so a corporate group can require it while a small independent keeps passwords.

What about shared logins at busy branches?

We move them to individual users with the right branch permissions, because shared accounts cannot be audited or removed cleanly.

What do you need from us?

Access to your authentication code and user model, and a view of how agencies currently ask you to add or remove users.

Keep reading

More on Problems We Solve

Start here

Tell us where your proptech product gets stuck with agencies

Describe what your product does for estate or letting agents, which agency systems it has to talk to, and where the friction shows up: onboarding, integrations, support or billing. We will tell you what we would build and what we would leave alone, and if the fix is a process change rather than code, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →