← All features
Property Management

Tenant Request QR Codes One Per Door

Pro. The code, the page behind it and the alerts are all part of Pro.

A card inside the door of a unit, with a QR code on it. A resident scans it with the camera they already have, describes the problem, and it arrives with you knowing which unit it came from. Nobody installs anything, nobody makes an account, and nobody types a unit number.

What the resident does

Points a phone camera at the card. A web page opens — no app, no login, no account. They describe the problem, optionally attach up to three photos, and send it.

They are never asked for a name, a phone number or an email address. The code identifies the unit, and the callback contact is read from that unit’s own record at the moment the request arrives. That is not a convenience feature: the tenant’s name and number are deliberately never published to the page, so the only place they can come from is the private record, which means the page a stranger can open carries the building and the unit label and nothing about who lives there.

The card also carries a four-character verify code, printed in ink, that the page shows back. It is not a password. It is the cheapest thing that makes a swapped sticker noticeable — and the characters it can use exclude O and 0, I and 1, S and 5, Z and 2, because somebody is going to read it aloud.

Four questions that come before the form

Some of what a resident calls an emergency is not one, and sorting those out is the easy half. The reverse is the fatal one. Every gas utility gives the same instruction: if you smell gas, leave, and do not use a light switch, an appliance or a phone indoors. For that situation a form is not merely slow — filling one in is the dangerous act.

So four questions sit above the form: I can smell gas. There is fire, smoke or sparking. Water is actively running or flooding. The unit will not lock, or a door or window is broken open. Tripping any of them replaces the form with a phone number and an instruction — leave now and call from outside, or call 911 — rather than annotating a form that is still there to be filled in. The page must never take a report of a gas leak and answer "we have received it".

The page behind the tag

The same scan opens the information a resident normally has to phone the office to get: office contact and hours, an after-hours number, what actually counts as an emergency, shutoff locations, fire safety, utilities, rubbish and parking, notices, and links to documents. Write it once for the building, then change only the parts where a specific unit differs — the unit’s panel holds the difference and is merged over the building’s.

It reads in the visitor’s language rather than in yours, which matters most on exactly the page where somebody is trying to report that they have no heat.

What a stranger who found the card cannot do is enumerate anything. The public tag document can be fetched by its own opaque id and the collection cannot be listed at all, so one code found on a wall implies nothing about any other door.

What reaches you

A push notification to the account owner, always. That one needs no configuration and is the reason a building nobody has set up still reaches a person.

Then a separate email and text list for tenant reports, configured per building alongside the vendor check-in contacts and kept apart from them, so resident reports can go somewhere other than the vendor desk. If you leave the tenant list empty, the building’s vendor check-in list is used instead rather than nothing being sent — a request is never dropped because a second list was never filled in. If you want resident reports kept off the vendor contacts, fill the tenant list in; whatever is in it always wins.

A text is only sent to a number that has confirmed consent to receive one, which only the recipient can give — adding a number in the app does not, on its own, make a message arrive.

The photos are never attached to the mail. A link generated server-side would bypass the storage rules completely and hand pictures of the inside of somebody’s home to whoever the email gets forwarded to, so the notification links to your dispatch queue, where being signed in as the owner or an active team member is the thing that opens them.

Requests land in their own review tab and never become work orders by themselves. Turning one into work — and choosing who on the crew it goes to — is a decision somebody makes.

Turnover, lost cards and noisy neighbours

Card gone missing, or the unit turned over? Re-mint the tag. The old public page is deleted the moment the change lands, so a sticker in somebody’s bin resolves to nothing. The same happens if the tag is cleared or the unit is deleted — all three are the same fact and all three retire the old code.

Because every door carries its own code, the one-request-per-hour limit is per unit. One resident reporting something never blocks their neighbour from reporting anything, which is the failure mode a single building-wide code has.

The older building-wide code keeps working for ever. A card already on somebody’s wall does not stop resolving because a better one now exists.

Why this one is Pro, in full

Unlike work orders and PM scheduling, there is no free half here worth having, and it is better to say so than to have somebody find out at the door. Two gates, and they are not the same kind. The tag is a live URL code, and live URL codes are Pro because they only resolve while a hosted page is being published and kept current — that one is enforced in the app, which shows a padlock on PRINT TENANT REQUEST TAG and PRINT DOOR TAG (LETTER) instead of printing. The second is a security rule on the server: creating a tenant request document requires the owner of that building to be Pro, so even a tag that somehow got printed cannot collect a request for a free account.

Reading a page that already exists is free, and always will be — the resident scanning the card never pays for anything and never signs in.

Frequently asked questions

Does the tenant need to install an app?

No. The QR code opens an ordinary web page in the phone’s browser. There is no app to install, no account to create and nothing to sign in to.

Do residents have to give a phone number or email?

No. The code identifies the unit, and the callback contact is read from that unit’s record when the request arrives. Tenant names and numbers are never published to the page a resident opens.

What happens if somebody reports a gas leak?

They do not get a form. Four safety questions sit above it — gas, fire, flooding, and a door that will not lock — and tripping any of them replaces the form with a phone number and the instruction to leave first and call from outside.

Is the tenant request QR code free?

No. It is Pro twice over: printing the tag needs Pro, because it is a live URL code, and the security rules on the server refuse to create a tenant request unless the building’s owner is a Pro subscriber. Reading a page that already exists is free for the resident, who never signs in.

What if a card is lost or the unit turns over?

Re-mint the tag. The old public page is deleted as soon as the change lands, so the old card stops resolving. Clearing the tag or deleting the unit has the same effect.

Can one resident spam the queue?

Each code accepts one request an hour, and the clock is stamped by the server when a request is genuinely created. Because every door has its own code, the limit applies to that unit alone and never blocks a neighbour.

Read next

Owners, units and tenants → Turning a request into a work order → How per-unit tenant tags were built → Vendor check-in codes, the other door sign →

Free to download. Nothing to set up.

Core tracking is free forever and works with no signal. Pro adds cloud sync, the web dashboard, AI scanning and the hosted QR codes.

Create Free Account App Store Google Play