Security and integrations

Built with hotel operations, access, and accountability in mind.

GSM separates guest access, team permissions, assistant behavior, settings, credentials, and operational state across a multi-tenant platform.

Access by context

Public access does not become operational access.

Guest, staff, management, property, and provisioned group contexts stay deliberately separated as a request moves into hotel operations.

Avelora Bay Hotel · Demo · Access model

  1. 01Public guest portal
  2. 02Verified stay context
  3. 03Guest confirmation boundary
  4. 04Server-controlled request operations
  5. 05Property-authorized staff
  6. 06Property-authorized management
  7. 07Provisioned group view
GuestStaff roleManagement rolePropertyOrganization / group

Verified guest context does not expose staff or management data. Property and role authorization remain required for operational views.

Controlled AI boundary

Conversation can prepare work. It cannot silently create it.

GSM keeps assistant behavior separate from server-controlled request operations and the authorized staff workflow.

01

AI conversation

Answer, translate, clarify, and prepare.

02

Guest confirmation

The explicit operational boundary.

03

GSM operational control

Persist, route, authorize, and record.

Integration architecture

Describe implementation state before provider breadth.

GSM includes integration foundations and hotel data workflows. Availability depends on the specific provider and implementation; universal PMS or live OPERA API integration is not claimed.

  1. 01

    Available

    A capability available in the relevant product context.

  2. 02

    Configured per project

    Availability depends on the provider, scope, and agreed implementation.

  3. 03

    Foundation

    Technical foundations exist; a complete provider connection is not being claimed.

  4. 04

    Planned

    Directional work only, with no current availability claim.

These are implementation-status categories, not certifications, provider endorsements, or a promise that a specific system is integrated.

Operational accountability

Settings and credentials stay behind controlled operations.

Public product language focuses on observable boundaries: role and property scoping, secret redaction, audit-oriented request history, and separation of public and authorized views.

  • Stay verification modelWhere configured, guest access can use verified stay context.
  • Request confirmation modelNo staff request exists before the guest confirms.
  • Settings auditConfiguration changes remain part of accountable hotel operations.
  • Secret redactionCredentials are not exposed in public or operational product views.