
Search commercial real estate analytics and the first page is filled with data and advisory firms, an industry association and a university short course. We read one of them in full, and it sells exactly what the domain names suggest: a validated view of transactions, listings and valuations, bought by the people who make decisions with it.
That is a real product category and it solves a real problem. It is also the opposite of the problem a CRE software company has.
The Search Results Answer the Buyer's Question, Not the Builder's
We measured the first ten organic results on 26 August 2026, and the measurement covers domains and titles rather than what each page sells. Only one of the ten was read in full, so what follows is one verified example and nine unopened doors.
One of them states the position in its own words. Altus Data Studio describes itself as "the most comprehensive database of validated Canadian CRE data, built for professionals who can't afford to work from incomplete information", sold direct to brokers, researchers, developers, investors and lenders. (Altus Data & Analytics, read 26 August 2026.)
Three other pages we tried returned 403 or 404 to us, so no claim about what the other nine sell appears here. What the measurement does support is narrower and still useful: none of the ten titles addresses a software company shipping dashboards to its own customers.
For a Builder the Data Is Already Yours to Hold, Which Moves the Difficulty
A data vendor answers one question for many buyers, and every buyer may see the same answer. That is the product.
A software vendor answers many questions for one customer at a time, and the boundary between customers is the product. Nothing about that boundary is a reporting concern; it is an access decision that happens to render as a chart.
So the CRE question stops being "where do we get the data" and becomes "who is allowed to see which rows of the data we already have".
A Portfolio Is Not a Tenant ID, and That Is the Whole Difficulty
Most multi-tenant analytics assumes one identifier separates customers. In CRE that assumption breaks on the first real org chart.
An owner holds a portfolio. A property manager operates buildings that may span several owners, and an asset manager holds a few assets inside a portfolio that somebody else reports on.
Those are three different paths through the same tree, and only one of them looks like a tenant identifier.
The figure draws that as paths rather than boxes because the shape is the point. A scope in CRE is a route from a root to a set of leaves, and two routes can legitimately cross at the same building while carrying different columns.
The Same Asset Under Two Customers Is Normal, Not a Data Problem
This is where a scoping design usually gets discovered rather than planned.
Ownership and operation are different relationships, so one building can appear in an owner's portfolio and in a manager's operating set at once. Both customers are entitled to a view, and the views are not the same: a rent roll may belong to one and a work-order backlog to the other.
Treating that as a duplicate to clean up produces the wrong fix. The right question is which columns each path may reach, which is a question about the policy rather than about the record.
Where the Path Has to Be Set, and Where It Must Not Be
A path with several levels still has to arrive at the data layer as something a policy can evaluate.
Our own documentation describes one mechanism for that without saying where it must run. External filters are described as ones that "integrate Sumboard's filtering capabilities with external systems or applications" and are "managed outside of Sumboard", carrying a filter key that is "used in the query to apply the filter to specific charts". (Sumboard docs, Filtering, External filters, both read 26 August 2026.)
Note what that does and does not settle. "Outside Sumboard" names where the filter is managed, not that it is covered by a signature, and our documented signing example covers the dashboard token alone.
The reasoning underneath is ours rather than the documentation's, and it is the same reasoning as anywhere else: a viewer who can edit the path is not evidence about that viewer. What JWT authentication puts inside the signature and what a row-level security policy evaluates are the two halves that have to agree on the path, and whether your own stack covers the path with the signature is the thing to check rather than assume.
Purchased Benchmarks and Customer Data Meet in the Same Dashboard, and They Are Not the Same Secret
The two categories this page opened by separating tend to end up on one screen.
A market benchmark bought from a data vendor becomes a column beside a customer's own numbers, which is exactly what makes the dashboard useful. It also means one panel now carries two kinds of confidentiality: a licensed dataset with its own redistribution terms, and a rent roll that belongs to one customer.
A scope that only knows about customers will happily show the licensed column to everybody, and a licence that forbids redistribution does not care that the panel looked like one chart.
Four Questions Before the First CRE Dashboard Ships
Count the levels in the hierarchy. Write it out for your worst customer rather than your first one, because the answer decides whether a single identifier can carry a scope at all.
Ask whether two customers can hold the same asset. If the answer is yes, the policy needs to reach columns and not only rows, and finding that out after launch is expensive.
Settle where the path is decided. A path that arrives from the browser is only as trustworthy as whatever re-checks it server-side, so the question is which component decides and not which component transmits.
Read the licence terms on any purchased data. A benchmark column is subject to the agreement it came with, and that agreement rarely anticipated your customers seeing it.
What This Page Does Not Cover
Market forecasting, cap-rate methodology and the valuation debate belong to the vendors this page opened with, and they are better placed to write about them.
We also did not survey CRE platforms to count how many express scoping as a hierarchy rather than a flat identifier. That would be a useful measurement and it is not one we made. The frequency words on this page are this author's experience rather than counts, and that applies to all of them rather than to a listed few.
Where to Go Next
- Row-level security: what a row policy decides, and what it does not.
- JWT authentication: what a signature covers, and where the scope travels.
- Multi-tenant analytics architecture: the isolation choices underneath a customer boundary.
- Embedded Analytics articles: the rest of this cluster.
Ready to launch customer-facing analytics?
Stop losing customers to competitors with better analytics. Sumboard's customer-facing analytics platform lets you launch self-service dashboards in days, not months.


