Industry Insights / Management Companies, Brands & Ownership Groups
Permissions Are Part of the Customer Experience
The invitation reached the right person and opened the right property—then stopped at an action the recipient had every reason to believe was allowed.
Permission design protects the relationship when an authorized person can reach the intended work, understand the boundary, and recover when access fails.
Article contents5 sections
Article navigation
Contents
The invitation opened into a dead end
The invitation named the property and reached the correct recipient. One click later, the review stopped at a blocked action with no explanation worth acting on.
By October 2021, more property decisions were moving through shared digital workflows. Permission was no longer an invisible administrative choice. Customers met it in the invitation, the sign-in, the unavailable button, and the attempt to recover.
Protection needed a purpose
NIST's voluntary Privacy Framework, released in January 2020, gave organizations a disciplined way to examine privacy risk. Its digital-identity guidance also considered the burden authentication and recovery placed on users. Neither resource was a law or a product endorsement.
The practical tension was enough. Too much access exposed material unrelated to the recipient. Too little interrupted legitimate work. Privacy before inquiry began the relationship; permission design carried that respect into collaboration.
A production partner might need a restricted layout without internal commercial commentary. The boundary followed the task, not the easiest role an administrator could configure.
Access had a beginning—and an end
A legitimate invitation could resemble phishing when the sender and purpose were vague. Authentication stronger than the risk demanded could make low-risk viewing needlessly difficult. An error message that exposed system detail would create a different problem.
The relationship changed again after proposal review. A handoff, departure, or completed engagement should trigger reconsideration. Permanent access could not outlive the purpose that justified it, and permission to view approved content did not repair an expired right or obsolete property condition.
Recovery was part of the protected route
An authorized participant might use assistive technology, share a weak connection, or lose access to the channel receiving a recovery code. Repeating the barrier was not recovery.
The alternative route had to remain understandable without becoming a weak back door. Human assistance stayed visible and verified identity in proportion to the protected work. Information was functionally unavailable when the intended person could not complete the process required to reach it.
The boundary became part of the work
The cited tourism research addressed presence and intention, not identity assurance or access control. SiteSee could keep property understanding connected to the permission governing its use. The benefit was not restriction for its own sake. It was collaboration with a boundary people inside it could understand.
That discipline grew more important when acquisitions joined unfamiliar systems and customer paths.
The opening invitation succeeded only after the recipient reached the intended work, knew why other material remained closed, and could see what would happen when the relationship ended.
Sources and evidence
- National Institute of Standards and Technology, “Privacy Framework Version 1.0” (opens in a new tab), January 2020.
- National Institute of Standards and Technology, “SP 800-63-3 Digital Identity Guidelines” (opens in a new tab), 2017.
- Tussyadiah and colleagues, “Virtual reality, presence, and attitude change” (opens in a new tab), Tourism Management, 2018.
- Bogicevic and colleagues, “Virtual reality presence as a preamble of tourism experience” (opens in a new tab), Tourism Management, 2019.
Last updated: 2026 08 22