Public product-security overview

A practical security overview for hotel guest-service workflows.

See how GSM separates public guest access, verified context, guest confirmation, server-controlled operations, authorized hotel views, and transparent integration status.

Public and authorized contexts

Access is connected by context, not collapsed into one public view.

Each stage is a semantic public-product explanation. It does not expose implementation, database, or customer-specific architecture details.

  1. 01Public guest portal
  2. 02Verified stay context where required
  3. 03Guest confirmation
  4. 04Server-controlled request operations
  5. 05Property-authorized staff
  6. 06Property-authorized management
  7. 07Provisioned group visibility

Controlled operation

Conversation alone does not create staff work.

  • Stay verification where required

    Eligible guest access can use verified stay context.

  • Guest confirmation boundary

    Conversation alone does not create staff work.

  • Server-controlled operations

    Requests move into hotel operations through controlled server-side workflow rules.

  • Property and role context

    Authorized hotel views remain scoped to the relevant property and role.

  • Request history and accountability

    Operational history supports clear ownership and accountable follow-up.

  • Secrets and public output

    Provider credentials and operational secrets stay in server-side configuration and are not intentionally exposed in public product-page output.

Integration-status transparency

Describe the implementation state before the provider promise.

A status describes implementation state and does not imply universal PMS or provider support.

  1. 01

    Available

    Available where GSM confirms the implemented capability.

  2. 02

    Configured per project

    Configured according to the relevant property or project context.

  3. 03

    Foundation

    A foundation exists but is not presented as a completed provider connection.

  4. 04

    Planned

    Planned work is not presented as available.

Current limits

Honest public product boundaries.

This overview does not claim SOC 2, ISO 27001, SSO, data residency, a guaranteed uptime level, completed penetration testing, or universal PMS integration.