Card data exposure sweep
We search case comments, email messages, task descriptions and custom text fields for patterns resembling payment card numbers, and review whether attachments such as authorization forms are stored in Salesforce. Where exposure exists, we note how it got there and which process needs to change. The goal is to keep card data out of the org entirely, rather than trying to protect it once it arrives.
Property-level access review
Sales managers, front office leads and franchise partners should normally see their own locations and shared regional accounts. We test that with sample users, review role hierarchies and territory rules, and check whether a departed employee at one property still has access. Reports and dashboards shared across the portfolio are examined to confirm they do not reveal guest details beyond what regional leaders need.
Group and event pipeline audit
Group blocks, meetings, weddings and charter bookings move through tentative, definite and cancelled states, with dates and room counts changing along the way. We check whether stages, required fields and lost reasons are used consistently across properties, whether forecasted revenue reflects current blocks and whether duplicate accounts for the same planner or third-party intermediary are distorting production reports. Cutoff and attrition dates are sampled as well.
Guest identity and loyalty matching
One guest can appear through reservations, loyalty enrollment, complaints and marketing lists under different emails or spellings. We measure duplication, review matching and merge rules and look at how loyalty status and preferences are stored. That tells you how reliable a single guest view is today and what would need to change before building personalization or AI-driven service on top of it.