Hotel development data is commercially sensitive. Hospitality Planner is built so that each organisation, hotel and stakeholder group sees only its own scope, and so that decisions remain traceable.
Every record belongs to one organisation. Access is evaluated per request against the caller's memberships; there is no cross-organisation read path for ordinary users.
Within an organisation, access is scoped further to the portfolios, hotels and projects a user is a member of.
Organisation admin, portfolio lead, project manager, team member, read-only and external stakeholder roles, assigned per scope.
Platform super-administration is a distinct, separately governed role. It is not granted through ordinary organisation administration.
Documents and drawings are held in private storage, partitioned per project and served only through short-lived authorised links.
Delivery intelligence only retrieves evidence from the projects the requesting user can already access.
Membership changes, approvals, gate decisions, data imports, exports and acted-on recommendations are recorded as an auditable history.
Change history and archived records are retained rather than overwritten, so prior states remain traceable.
This page describes architecture and engineering practice. It does not assert any independent security certification, third-party audit or penetration test. Where a licence requires formal assurance, that scope is agreed during contracting.