2.2 KiB
Gate B automation, identity and privacy acceptance
Run these reviews against the exact 0.2.0 candidate on the accepted HTTPS sandbox. Keep guest data, staff addresses, provider agreements, screenshots and raw reports in the restricted evidence store. Repository records contain opaque references only.
Knowledge, AI and FAQ automation
Curate representative hotel-specific positive and negative FAQ cases. Use the bounded no-send evaluation and require zero false positives and zero false negatives. Review AI suggestions separately; escalations are valid outcomes, but no unsafe or unsupported draft may be approved. Exercise the FAQ stop control, train every pilot staff member, and name monitoring and rollback owners. Finish with FAQ mode off and PMS/payment writes disabled.
Copy deploy/automation-acceptance.example.json, complete the record, independently review its evidence, and run:
python3 deploy/automation_acceptance.py /secure/acceptance/automation-acceptance.json
Identity, preferences and privacy
The hotel and privacy owners must approve explicit retention periods for conversations, audit history, backups and accounts. Name privacy, deletion and legal-hold owners and retain the deletion and hold procedures. Review Google processing for the mailbox pilot; either accept OpenAI processing or keep AI drafts disabled.
Exercise owner/staff boundaries, invitation and recovery lifecycle, trusted-proxy throttling, session invalidation, every owner-controlled preference, data inventory, deletion/retention handling, backup retention and audit evidence. Explicitly review the known absence of MFA, granular roles and self-service recovery; any accepted containment belongs in the final pilot decision.
Copy deploy/identity-privacy-acceptance.example.json, complete the record, independently review its evidence, and run:
python3 deploy/identity_privacy_acceptance.py /secure/acceptance/identity-privacy-acceptance.json
These validators check completeness and release binding. They do not make legal decisions, inspect provider agreements or implement deletion on behalf of the operator. Reference the retained records and validator output from automation and identity-privacy in the final pilot approval.