Building a Technology Roadmap for a Property Business

Most property businesses do not have a technology problem so much as a sequencing problem. Everything seems urgent, so work starts everywhere and finishes nowhere. The cyber security gap, the Microsoft 365 configuration, the automation opportunity and the AI question all arrive at once, each with someone pushing for it.
A technology roadmap is not a shopping list. It is a decision about what to do first, what to do next, and what to leave alone until the things in front of it are finished. For a property business, that order matters more than which products you choose, because doing the right things in the wrong order produces more cost and more risk than doing nothing at all.
The question is not what to buy. The question is what order to do things in.
The short answer
Secure and understand what you have before you standardise it. Standardise before you automate. Automate before you introduce AI. Each stage depends on the one before it — automating disorganised information multiplies the mess, and AI layered on top of loose permissions exposes information faster than anyone intended. The LOOKUP Business Modernisation Framework™ is the method behind that sequence: eight stages, worked in order, so that each one is built on something solid rather than on hope.
Why sequence matters more than selection
The common failure in property businesses is not choosing the wrong product. It is doing the right things in the wrong order. Automating a process that runs on disorganised information does not make the process better — it makes the disorganisation faster. Adopting AI before permissions are under control does not deliver productivity — it delivers exposure. Standardising offices before they are secured means you are standardising a vulnerability across every branch at once.
Sequence is the difference between technology that compounds and technology that collides. When you secure first, every later investment sits on a foundation that is already protected. When you standardise second, automation has a consistent environment to run against. When you automate third, the workflows you build are repeatable because the information underneath them is in a known place. When AI comes last, it reaches only what it should reach, because the permissions and governance were settled before it arrived.
Reversing that order is expensive. A property business that automates before it standardises ends up with two versions of every workflow — the old manual one nobody trusts and the new automated one nobody understands. A business that adopts AI before securing its identity ends up with a tool that can see every tenant application, every landlord financial detail and every trust account record, because nobody closed the access before opening the tool. The cost of doing things in the wrong order is not just the wasted project — it is the cleanup that follows, which is always larger than the project was.
A roadmap forces the question of order. It does not eliminate urgency, but it replaces the instinct to start everything with the discipline to finish things in sequence. For a property business, where the technology environment spans offices, devices, property platforms, trust accounting and Microsoft 365, that discipline is what separates a business that grows cleanly from one that accumulates complexity until it stalls.
The LOOKUP Business Modernisation Framework™
The eight stages are a sequence, not a menu — each one is the foundation for the next, and skipping ahead is the most common reason technology investment fails to deliver.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Discover
Map every system the property business actually runs — the property platform, the CRM, trust accounting, Microsoft 365, email, shared drives and the devices staff use across offices and properties — so the roadmap starts from reality, not assumption.
Secure
Enforce multi-factor authentication, conditional access and prompt offboarding across Microsoft 365 and every connected device, so that tenant identity documents and trust account information are protected before anything is rebuilt.
Modernise
Move from fragmented email and shared drive storage into governed SharePoint, Teams and OneDrive structures, so that property information sits in a consistent, searchable environment rather than scattered across inboxes.
Standardise
Apply the same identity, device, security and Microsoft 365 configuration across every office, so that a new branch or acquisition inherits the standard instead of building its own from scratch.
Optimise
Identify the repetitive workflows — enquiry routing, maintenance request intake, inspection follow-up, landlord reporting — and streamline or automate them now that the information underneath is consistent and accessible.
Prepare
Review permissions, write the approved-tools policy, define what information is never pasted into public AI tools, and brief staff on verification expectations before any AI is deployed in the property business.
Implement
Deploy one AI-assisted workflow — listing drafts, enquiry classification or inspection summaries — with a named owner and human review of every output, building real evidence before scaling.
Improve
Review which workflows are trusted and used, revisit the approved-tools list as technology changes, and confirm that human oversight of AI output remains the standard across every office and property team.
What comes first for most property businesses
The honest answer is that it varies, but identity, access and email protection almost always precede everything else. The reason is simple: every later stage depends on knowing who can reach what. If a departed agent still has mailbox access, if a contractor can open every tenant application, if a new starter gets broad permissions by default because nobody has time to scope them properly, then nothing built on top of that environment is trustworthy.
For most property businesses, the first practical step is not a project — it is an audit of who has access to what right now. That means reviewing Microsoft 365 sign-ins, checking which accounts are still active for people who left, confirming whether multi-factor authentication is enforced on every mailbox, and looking at whether the sharing settings on SharePoint and OneDrive let the whole team open everything by default. That work is unglamorous, but it is the foundation everything else stands on.
After identity and access, the next priority is usually email protection. Property businesses live in email — rental applications, settlement instructions, maintenance requests, landlord communications, trust account correspondence. Email is also the primary attack surface, because business email compromise and payment redirection target exactly the kind of time-sensitive, high-value transactions property businesses handle every day. Securing email is not a separate workstream from securing identity; it is the same workstream applied to the system that carries the most risk.
Only after those foundations are in place does it make sense to standardise the Microsoft 365 environment across offices, automate the workflows that are actually repeatable, and begin preparing for AI. A property business that tries to skip straight to automation or AI without securing identity and email first is building on sand — and the first compromise will undo whatever productivity the later stages delivered.
The roadmap does not mean waiting. It means doing the first thing properly so the second thing works. For a property business that has never had a coordinated technology plan, the relief of knowing what comes first — and why — is often the most valuable outcome of the entire process.
Where AML/CTF obligations sit in the sequence
AML/CTF obligations are already in force for Australian real estate businesses providing designated services. That changes the sequence for many property businesses, because the technology that supports customer due diligence, recordkeeping and access control is no longer a future consideration — it is a current requirement. In practical terms, that often moves identity management, information governance and retention controls forward in the roadmap, ahead of automation or AI work that might otherwise have seemed more urgent.
The roadmap still follows the same sequence — secure, standardise, then automate — but the obligations give the early stages a concrete driver. Enrolling with AUSTRAC, maintaining an AML/CTF program, conducting customer due diligence, reporting suspicious matters and keeping records all depend on systems that control who can access identity information, where that information is stored, and whether it can be retrieved on request. Those are the same foundations the roadmap is building anyway; the obligations simply make the case for doing them first rather than later.
LOOKUP does not provide legal or compliance advice and does not determine whether a business provides a designated service. Meeting AML/CTF obligations in a property business is about the technology that supports what compliance advisers require — identity and access control, information governance, recordkeeping systems and retrieval capability — not about interpreting the legislation itself.
How to tell which stage you are actually at
Most property businesses overestimate how far along they are. The questions below are ones a principal can answer without a consultant. If the answers are mostly no, you are earlier in the sequence than you think — and that is useful information, because it tells you where to start.
Are you secured?
- Is multi-factor authentication enforced on every mailbox, including shared and admin accounts?
- Have all departed staff and contractors been removed from Microsoft 365 and every property platform?
- Can you say, right now, who has access to tenant identity documents across your systems?
- Is email protected against phishing and business email compromise, and do staff know how to verify payment changes?
Are you modernised?
- Does property information sit in governed SharePoint sites and Teams channels, or is it still in personal inboxes and shared drives?
- Can a staff member in one office find a document created in another without emailing someone for it?
- Are devices managed, encrypted and remotely wipeable, or are staff using personal devices with no controls?
Are you standardised?
- Do all offices use the same Microsoft 365 configuration, or does each branch have its own setup?
- Is there a documented onboarding and offboarding process that is actually followed, or does it vary by office?
- Could you open a new office tomorrow and have it match the standard, or would it start from scratch?
Are you ready for automation or AI?
- Are the workflows you want to automate documented and consistent, or do they vary by person?
- Is there a written policy on which AI tools staff may use and what information must never be pasted into them?
- Do staff understand that AI output must be verified, and is there a named person responsible for reviewing it?
What a roadmap should contain
A roadmap is not a document. It is a decision tool. If it does not help you decide what to do next and what to leave alone, it is not working. The elements below are the minimum a roadmap needs to function as a plan rather than a wish list.
A current position
An honest assessment of where the business is right now — what is secured, what is not, what is consistent across offices and what is not. Without this, every later decision is a guess.
A sequence with reasons
Not just a list of projects, but the order they go in and why. The reason for each stage is that the next one depends on it. If you cannot explain why something comes first, the sequence is not settled.
A first step small enough to start
The roadmap fails if the first action is too large to begin. The first step should be concrete, scoped and achievable within a reasonable timeframe so that momentum builds rather than stalls.
Named owners
Every stage needs someone responsible for it — not a department, a person. A roadmap nobody owns is a document, not a plan. Owners track progress, make decisions and escalate when something blocks them.
A review point
A scheduled date to assess what is done, what is in progress and what has changed. Priorities shift as the business grows, as obligations change and as technology moves. A roadmap that is never reviewed is abandoned by default.
A roadmap that contains those five elements is a working tool. A roadmap that is missing any of them — especially named owners and a review point — tends to sit in a folder until someone asks why nothing happened.
How LOOKUP helps
LOOKUP works on the Microsoft 365 environment, identity, devices, security and workflows that surround the specialist systems a property business runs on. That means discovery and assessment to establish where you actually are, roadmap development to set the sequence and the reasons behind it, and staged delivery that proves each stage before moving to the next.
LOOKUP coordinates with property management platforms, CRMs and trust accounting vendors rather than replacing them. The roadmap is about the environment those systems sit in — who can access them, how information moves between them, whether devices are managed, and whether the Microsoft 365 baseline is consistent across every office. For growing networks, a Virtual CIO can provide the ongoing technology leadership that keeps the roadmap on track without a full-time executive hire. For a broader view of how LOOKUP approaches property businesses, see our Real Estate & Property Services industry page.
Discovery & Assessment
Establish your current position — systems, security, identity, information and devices — so the roadmap starts from reality.
Roadmap Development
Set the sequence, the reasons for it, named owners and a first step small enough to begin immediately.
Staged Delivery
Deliver each stage in order, proving it before moving to the next, with a review point built in.
The other outcomes in this series
This roadmap is one of seven business outcomes for property businesses. Each addresses a specific question a property principal asks. They connect to each other, and they all sit within the same sequenced approach.
Meeting AML/CTF Obligations
Does our technology actually support what we are required to do under the AML/CTF regime?
Protecting Personal Information
How do we hold only what we need, and control who can see it?
Preventing Payment Redirection
How do we stop an impersonated email redirecting deposits and settlement funds?
Standardising Technology Across Offices
How do we get one standard that also applies to the next office we open or acquire?
Reducing Administrative Overhead
Where does the repeated handling sit, and what can safely come out?
Preparing for AI
Where does AI genuinely help, what has to be true first, and what must stay with a person?
Frequently asked questions
A technology roadmap for a property business is a sequenced plan that determines the order in which security, standardisation, automation and AI work should be done, rather than a list of products to buy. It starts from your current position and names what comes first, what depends on it, and what should wait.
The order matters because each stage depends on the one before it — automating disorganised information makes the mess faster, and AI layered on loose permissions exposes sensitive data rather than improving productivity. Doing the right things in the wrong order costs more than doing nothing, because the cleanup always exceeds the project.
Most property businesses should start with identity, access and email protection, because every later stage depends on knowing who can reach what and whether mailbox access is controlled. If departed staff retain access or sharing is wide open, nothing built on top of that environment can be trusted.
No — a roadmap works around your existing property platform, CRM and trust accounting system rather than replacing them, because the sequence is about the Microsoft 365 environment, identity, devices and workflows that surround those specialist systems. LOOKUP coordinates with property platform vendors rather than substituting for them.
Implementation timing depends on the scope of governance, existing policies, security controls, permissions, information structure, staff readiness and the number of offices involved, so there is no universal timeframe that applies. The roadmap is worked in stages, with each one proven before the next begins.
The LOOKUP Business Modernisation Framework is an eight-stage sequence — Discover, Secure, Modernise, Standardise, Optimise, Prepare, Implement and Improve — that guides technology investment from understanding the current environment through to AI adoption and continuous review. Each stage is the foundation for the next.
Skipping to AI without securing identity, organising information and setting permissions first means the tool reaches everything each user can see, which in a property business includes tenant identity documents, landlord financial details and trust account records. The preparation stages exist so AI reaches only what it should.
You can estimate your stage by answering diagnostic questions about whether multi-factor authentication is enforced, whether departed staff have been removed, whether information sits in governed locations, and whether workflows are documented — if the answers are mostly no, you are earlier in the sequence than you think.
Standardising before securing means you are replicating a vulnerability across every branch at once, which increases exposure rather than reducing it. Security comes first so that the standard you roll out to each office is already protected.
Automating before standardising produces two versions of every workflow — the old manual one nobody trusts and the new automated one nobody understands — because the information underneath is inconsistent. Standardising first means automation runs against a known, consistent environment.
The roadmap should have a named owner — typically a principal, director or general manager — supported by either an internal IT lead or an external partner, because a roadmap nobody owns is a document rather than a plan. Ownership includes tracking progress, deciding priorities and scheduling reviews.
New obligations like AML/CTF may move recordkeeping, identity verification and access control forward in the sequence, because the technology that supports those obligations depends on the same foundations the roadmap is already building. LOOKUP does not provide AML/CTF advice but ensures the technology environment supports what compliance advisers require.
A roadmap should contain a current position, a sequence with reasons for that order, a first step small enough to start immediately, named owners for each stage, and a review point where progress is assessed and priorities adjusted. Without those elements it is a wish list, not a plan.
A roadmap should be reviewed at a scheduled point — typically quarterly or after any major change such as an acquisition, a new obligation or a security incident — so that priorities shift deliberately rather than reactively. The review confirms what is done, what is in progress and what comes next.
LOOKUP runs a discovery and assessment process to establish your current position, develops a staged roadmap with named owners and dependencies, and then delivers each stage in sequence — coordinating with property platform vendors throughout. LOOKUP works on the Microsoft 365 environment, identity, devices, security and workflows rather than replacing specialist property systems.
Sources & Further Reading
The following primary and authoritative sources support the research, guidance and industry context discussed on this page:
Australian Signals Directorate — Essential Eight Mitigation Strategies
2024 — The ASD publishes the Essential Eight as a baseline set of mitigation strategies that can serve as a common security standard across offices and property teams.
View SourceEvidence Standard
LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
Build a roadmap that tells you what to do first
A technology roadmap is not about buying more — it is about doing things in the right order so each investment builds on the last. If your property business is starting everything and finishing nothing, a sequenced roadmap is what changes that.
Peter Kantarelis
Founder, LOOKUP — Business Technology Strategist
Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.
View More Insights