NATO School Oberammergau needed more than a normal accommodation booking system. The new environment had to replace an internal legacy process, work with partner hotels, fit inside Salesforce, and meet unusually strict security and governance requirements.
Booking Ninjas built much of that accommodation environment and prepared it for deployment.
The system did not go live.
But what happened before that decision became an important part of how Booking Ninjas approaches security today.
The challenge: replace a legacy booking system inside a high-security environment
NATO School needed a new way to manage internal accommodation while also working with outside hotel partners.
The intended environment needed to bring several pieces together:
- Internal accommodation bookings
- Room and lodging data
- External hotel partners
- Reservation workflows
- Existing Salesforce data
- User permissions
- Administrative access
- Security and accreditation rules
Booking Ninjas was already built on Salesforce and had worked inside the Salesforce ecosystem for years.
That gave the project a mature platform foundation, but the NATO environment required much more than normal application setup.
What Booking Ninjas built
The project moved well beyond an early demo.
Booking Ninjas developed the main booking and accommodation environment, configured the required workflows, and completed substantial property-data migration work.
The goal was not to put another booking tool beside NATO School's existing systems.
The goal was to create a Salesforce-native environment that could become the working replacement for the legacy accommodation process while also supporting coordination with partner hotels.
Understand the existing accommodation and booking workflow that needed to be replaced.
Build the booking and accommodation records inside the Salesforce environment.
Move property data and prepare the operational rules needed for day-to-day use.
Test the application and surrounding configuration before production deployment.
A Salesforce org is the environment where records, workflows, permissions, integrations, reporting, and other parts of a Booking Ninjas setup can live together.
Then came a much deeper security review
Before production deployment, the Booking Ninjas implementation went through a multi-week grey-box penetration test by the Penetration Testing Section of the NATO Cyber Security Centre.
The review raised two main technical areas that needed more attention:
| Area | What the review challenged |
|---|---|
| Access control | How Salesforce configuration and application-level permissions controlled which users could reach which records and functions. |
| Business logic | How booking, payment, and transaction behavior was validated inside the application rather than relying only on the interface. |
The review also went beyond the application itself.
NATO raised governance questions around where administrative access could come from and how a third-party managed package could affect accreditation of the wider NATO information environment.
Those requirements were much stricter than the conditions Booking Ninjas normally met in a commercial Salesforce deployment.
The decision: the system did not go live
After the assessment, NATO School decided not to proceed with Booking Ninjas in production.
The package was removed from the planned information environment and the project was cancelled before go-live.
That part should not be hidden.
Booking Ninjas does not present NATO School as a live production customer and does not claim that the accommodation platform was approved for NATO production use.
The findings became work for our development team
Booking Ninjas already had a Salesforce-native product and established development practices before the NATO project.
The review still gave the team a reason to examine those practices again under a much tougher standard.
The team revisited several areas:
- Permission sets
- Sharing rules
- Record access
- External-user access
- Application business logic
- Authentication controls
- Email authentication
- Deployment practices
Security work around the project included stronger use of permission sets and sharing rules, tighter patterns for external users, less dependence on existing Account and Contact records inside the booking flow, and additional email authentication controls.
The important point is not that Booking Ninjas changed from an unsafe product into a safe one.
It is that a product already built on Salesforce was challenged by a much stricter environment and improved because of that challenge.
Access became an even bigger part of how we think about a setup
A secure system is not only about keeping outsiders out.
It also needs to make sure the people already inside can only reach the records and actions their role requires.
That is why permission sets, sharing rules, authentication, role-based access, and record visibility matter so much in Salesforce.
Booking Ninjas' current Salesforce security work follows that same idea. Our Salesforce Shield capability uses permission sets, role-based visibility, audit controls, and Salesforce security tools to help structure access around the people using the system.
The exact controls still depend on the customer's Salesforce environment and security requirements.
Salesforce provides the foundation. The application still has to use it correctly.
This was another important lesson from the project.
Building on Salesforce gives Booking Ninjas access to strong platform tools for authentication, permissions, sharing, encryption, monitoring, and governance.
But the platform cannot make every application decision for the developer.
Booking Ninjas still has to decide how its own records, code, workflows, permissions, integrations, and business logic use those tools.
Following the period of security hardening around the NATO project, Booking Ninjas continued through Salesforce's own security review process and met the security requirements applied to Salesforce ISV applications.
That process reinforced the same lesson: platform security and application security have to work together.
What the NATO School project changed for Booking Ninjas
The accommodation system never became a production NATO School system.
The work still changed how Booking Ninjas approached later projects.
Permission sets, sharing, external users, and record access became an even more deliberate part of implementation.
Important booking and transaction rules needed protection in the application logic, not only in what users could see on screen.
Administrative access, deployment, integrations, and the wider environment became part of the security conversation.
Security review was treated as part of how a system should be prepared, not something added after the build.
Permissions, sharing, authentication, and security features became more closely tied to the real roles using the system.
The knowledge from the NATO review continued into the way Booking Ninjas designed and reviewed later environments.
Most customers will never need NATO-level restrictions
A hotel, student residence, coworking space, or membership organization normally does not operate under the same accreditation and administrative rules as a NATO information system.
It would not make sense to force those restrictions onto every Booking Ninjas customer.
But going through the review changed the questions our team asks.
Who should see this record? Who should be able to change it? What happens if a request bypasses the normal screen? Where can administrators connect from? Which integrations touch the data? What does the customer's own security policy require?
Booking Ninjas can bring the technology and lessons from earlier work, but the final security model still has to match the organization using it.
That is another reason the customer's Salesforce org matters: the environment can be shaped around the organization's workflows, data, users, permissions, integrations, and policies.
A stronger security foundation for the work that came after
Today, Booking Ninjas looks at security across more than one layer.
- Application architecture
- Business logic
- User permissions
- Record sharing
- Authentication
- Administrative access
- Integrations
- Deployment governance
Current Booking Ninjas Salesforce capabilities also include secure access controls, role-based visibility, Salesforce security features, encryption options, and structured identity management where the customer's setup requires them.
The NATO School project is part of why those areas receive the attention they do.
Learn more about the security foundation
See where Booking Ninjas records, workflows, permissions, integrations, and other organization-specific settings can live.
What Is a Salesforce Org? →See how permission sets, role-based access, audit controls, and Salesforce Shield can support sensitive operational data.
Explore Salesforce Shield →See how Booking Ninjas uses Salesforce access, visibility, governance, and data protection tools around operational records.
Explore Data Management →About this story: Booking Ninjas built and security-tested an accommodation environment for NATO School Oberammergau, but the project was cancelled before production deployment. This page does not present NATO School as a live Booking Ninjas customer, imply NATO approval or endorsement of the product, or claim that the system received accreditation for production use.
Have strict security rules around your booking operation?
Tell us how your users, data, access rules, integrations, and booking workflows need to work. We can help shape the Salesforce environment around those requirements.