background

NATO School Oberammergau Project

NATO School Oberammergau needed more than a normal accommodation booking system. The new environment had to replace an internal legacy process, work with partner hotels, fit inside Salesforce, and meet unusually strict security and governance requirements.

Booking Ninjas built much of that accommodation environment and prepared it for deployment.

The system did not go live.

But what happened before that decision became an important part of how Booking Ninjas approaches security today.

Customer NATO School Oberammergau
Project Accommodation operations
Final status Did not go live

The challenge: replace a legacy booking system inside a high-security environment

NATO School needed a new way to manage internal accommodation while also working with outside hotel partners.

The intended environment needed to bring several pieces together:

  • Internal accommodation bookings
  • Room and lodging data
  • External hotel partners
  • Reservation workflows
  • Existing Salesforce data
  • User permissions
  • Administrative access
  • Security and accreditation rules

Booking Ninjas was already built on Salesforce and had worked inside the Salesforce ecosystem for years.

That gave the project a mature platform foundation, but the NATO environment required much more than normal application setup.

What Booking Ninjas built

The project moved well beyond an early demo.

Booking Ninjas developed the main booking and accommodation environment, configured the required workflows, and completed substantial property-data migration work.

The goal was not to put another booking tool beside NATO School's existing systems.

The goal was to create a Salesforce-native environment that could become the working replacement for the legacy accommodation process while also supporting coordination with partner hotels.

01 Legacy process

Understand the existing accommodation and booking workflow that needed to be replaced.

02 Salesforce setup

Build the booking and accommodation records inside the Salesforce environment.

03 Data + workflows

Move property data and prepare the operational rules needed for day-to-day use.

04 Security review

Test the application and surrounding configuration before production deployment.

A Salesforce org is the environment where records, workflows, permissions, integrations, reporting, and other parts of a Booking Ninjas setup can live together.

Then came a much deeper security review

Before production deployment, the Booking Ninjas implementation went through a multi-week grey-box penetration test by the Penetration Testing Section of the NATO Cyber Security Centre.

The review raised two main technical areas that needed more attention:

Area What the review challenged
Access control How Salesforce configuration and application-level permissions controlled which users could reach which records and functions.
Business logic How booking, payment, and transaction behavior was validated inside the application rather than relying only on the interface.

The review also went beyond the application itself.

NATO raised governance questions around where administrative access could come from and how a third-party managed package could affect accreditation of the wider NATO information environment.

Those requirements were much stricter than the conditions Booking Ninjas normally met in a commercial Salesforce deployment.

The decision: the system did not go live

After the assessment, NATO School decided not to proceed with Booking Ninjas in production.

The package was removed from the planned information environment and the project was cancelled before go-live.

That part should not be hidden.

Booking Ninjas does not present NATO School as a live production customer and does not claim that the accommodation platform was approved for NATO production use.

The findings became work for our development team

Booking Ninjas already had a Salesforce-native product and established development practices before the NATO project.

The review still gave the team a reason to examine those practices again under a much tougher standard.

The team revisited several areas:

  • Permission sets
  • Sharing rules
  • Record access
  • External-user access
  • Application business logic
  • Authentication controls
  • Email authentication
  • Deployment practices

Security work around the project included stronger use of permission sets and sharing rules, tighter patterns for external users, less dependence on existing Account and Contact records inside the booking flow, and additional email authentication controls.

The important point is not that Booking Ninjas changed from an unsafe product into a safe one.

It is that a product already built on Salesforce was challenged by a much stricter environment and improved because of that challenge.

Access became an even bigger part of how we think about a setup

A secure system is not only about keeping outsiders out.

It also needs to make sure the people already inside can only reach the records and actions their role requires.

That is why permission sets, sharing rules, authentication, role-based access, and record visibility matter so much in Salesforce.

Booking Ninjas' current Salesforce security work follows that same idea. Our Salesforce Shield capability uses permission sets, role-based visibility, audit controls, and Salesforce security tools to help structure access around the people using the system.

The exact controls still depend on the customer's Salesforce environment and security requirements.

Salesforce provides the foundation. The application still has to use it correctly.

This was another important lesson from the project.

Building on Salesforce gives Booking Ninjas access to strong platform tools for authentication, permissions, sharing, encryption, monitoring, and governance.

But the platform cannot make every application decision for the developer.

Booking Ninjas still has to decide how its own records, code, workflows, permissions, integrations, and business logic use those tools.

Following the period of security hardening around the NATO project, Booking Ninjas continued through Salesforce's own security review process and met the security requirements applied to Salesforce ISV applications.

That process reinforced the same lesson: platform security and application security have to work together.

What the NATO School project changed for Booking Ninjas

The accommodation system never became a production NATO School system.

The work still changed how Booking Ninjas approached later projects.

Access received more scrutiny

Permission sets, sharing, external users, and record access became an even more deliberate part of implementation.

Business logic was reviewed deeper

Important booking and transaction rules needed protection in the application logic, not only in what users could see on screen.

Governance became part of security

Administrative access, deployment, integrations, and the wider environment became part of the security conversation.

Deployment practices became stricter

Security review was treated as part of how a system should be prepared, not something added after the build.

Salesforce controls were used more carefully

Permissions, sharing, authentication, and security features became more closely tied to the real roles using the system.

The lessons stayed with the product

The knowledge from the NATO review continued into the way Booking Ninjas designed and reviewed later environments.

Most customers will never need NATO-level restrictions

A hotel, student residence, coworking space, or membership organization normally does not operate under the same accreditation and administrative rules as a NATO information system.

It would not make sense to force those restrictions onto every Booking Ninjas customer.

But going through the review changed the questions our team asks.

Who should see this record? Who should be able to change it? What happens if a request bypasses the normal screen? Where can administrators connect from? Which integrations touch the data? What does the customer's own security policy require?

Booking Ninjas can bring the technology and lessons from earlier work, but the final security model still has to match the organization using it.

That is another reason the customer's Salesforce org matters: the environment can be shaped around the organization's workflows, data, users, permissions, integrations, and policies.

A stronger security foundation for the work that came after

Today, Booking Ninjas looks at security across more than one layer.

  • Application architecture
  • Business logic
  • User permissions
  • Record sharing
  • Authentication
  • Administrative access
  • Integrations
  • Deployment governance

Current Booking Ninjas Salesforce capabilities also include secure access controls, role-based visibility, Salesforce security features, encryption options, and structured identity management where the customer's setup requires them.

The NATO School project is part of why those areas receive the attention they do.

Learn more about the security foundation

About this story: Booking Ninjas built and security-tested an accommodation environment for NATO School Oberammergau, but the project was cancelled before production deployment. This page does not present NATO School as a live Booking Ninjas customer, imply NATO approval or endorsement of the product, or claim that the system received accreditation for production use.

Have strict security rules around your booking operation?

Tell us how your users, data, access rules, integrations, and booking workflows need to work. We can help shape the Salesforce environment around those requirements.

WhatsApp Us

WhatsApp Us