Adoption boundary: these procedures are defined in the product governance pack. The legal operating company must approve owners, train users, retain evidence and test the procedures before representing them as fully operational.
| ID | Controlled procedure | Accountable role | Minimum evidence |
|---|---|---|---|
| OPS-01 | Reservation, hold, confirmation, cancellation, no-show and checkout lifecycle | Operations | Status history, guest notice, inventory movement |
| OPS-02 | Dated inventory and rate-change control | Operations | Versioned update and no-oversell check |
| OPS-03 | Property onboarding, evidence review and publication | Operations | Authority, hotel evidence and image rights |
| FIN-01 | Payment-provider onboarding and production activation | Finance | Merchant approval, sandbox, webhook and rollback test |
| FIN-02 | Payment-event verification and reservation confirmation | Finance | Signature, provider lookup, amount/currency match |
| FIN-03 | Settlement reconciliation, commissions and partner payouts | Finance | Matched settlement, variance review, dual approval |
| FIN-04 | Refund, chargeback and late-payment remediation | Finance | Approval, provider reference and guest outcome |
| PRV-01 | Data-subject rights and identity verification | Privacy | Reference, verification, decision and response record |
| PRV-02 | Personal-data breach assessment and notification | Privacy / Security | Timeline, risk assessment, decision and notifications |
| SEC-01 | Access provisioning, role review and termination | Security | Approval, least-privilege role and revocation |
| SEC-02 | Security incident response and evidence preservation | Security | Incident log, containment, communications and lessons |
| TEC-01 | Encrypted backup, restore testing and disaster recovery | Engineering | Encrypted artifact, off-server copy and restore result |
| TEC-02 | Change, release, migration and rollback management | Engineering | Approval, test evidence, backup and rollback decision |
| VEN-01 | Supplier due diligence, data agreement and offboarding | Governance | Risk review, contract, transfer basis and exit record |
| EDT-01 | Human and AI-assisted editorial publishing | Editor | Source record, quality gate, disclosure and correction |
Document control
Each detailed playbook must name its approver, effective date, scope, inputs, steps, segregation of duties, exception route, records, retention rule, training owner, test cadence and next review date. Emergency deviations are recorded and retrospectively approved.
Segregation of duties
Operations cannot activate providers or view secret configuration. Finance cannot browse guest or property-application correspondence beyond the references needed for financial control. Editors cannot access operational personal data. Settings, backups and role administration are restricted to the super-administrator function.