Skip to main content

Hospitality smart upsell agent

Relevance is not permission to add a charge.

A hospitality upsell agent can suggest optional additions that fit a guest's stated needs, current reservation and available services. It checks eligibility and presents the full price and terms before a guest chooses. Guests must be able to decline easily, and property staff retain responsibility for exceptions and fulfillment. Acceptance, payment and delivered service remain separate records.

Make optional additions easy to understand and decline

Included features, mandatory charges, paid additions, complimentary options, upgrades, substitutes, bundles and service recovery need clear labels. Recommendations must include a no-addition path. Do not sell during emergencies, complaints, payment disputes, bereavement, safeguarding concerns or unresolved access and service failures.

Disclose sponsored, promoted or margin-weighted treatment where applicable. Do not conceal a cheaper suitable option, preselect charges, manufacture urgency or make dismissal difficult. Accept and decline need equal visual weight; suppression and frequency limits persist across channels and sessions. A decline remains final for its defined context unless the guest asks again.

Follow selection through actual service

Keep request-only, waitlisted, sold-out, capacity-constrained and staff-confirmed offers distinct. Recheck inventory, capacity, price and policy before display, selection and commitment. Sensitive inference from names, devices, purchases or messages cannot establish guest needs or eligibility.

Each paid addition requires explicit guest action after the exact price, restrictions, base-reservation effect, cancellation and fulfillment terms are shown. Payment authentication, authorization, capture and settlement are separate from property confirmation and delivered service. Use approved payment paths outside model context and reconcile uncertain effects before retrying.

Recommendation boundary

Recommend an eligible addition without turning service into pressure.

A useful addition must fit the guest's stated context, exist now, disclose its full consequence and remain easy to decline. Four boundaries keep that promise inspectable.

01

Guest, service moment, purpose, and consent

Resolve property, channel, authenticated or anonymous context, reservation or visit, party, current service moment, stated need, accessibility request, communication purpose, consent and suppression before retrieving commercial options.

Required evidence: Tenant, property and channel identifiers, guest or session scope, reservation and party, journey stage, original request, stated need, accessibility request, purpose, consent source and time, marketing boundary, decline, opt-out, suppression and retention class.

02

Eligible catalog, inventory, price, and terms

Read current property catalog and capacity, remove included, duplicate, incompatible, unavailable, unsafe or otherwise ineligible items and preserve exact price, policy, accessibility and fulfillment evidence for every remaining candidate.

Required evidence: Item, property and owner, catalog and inventory versions, service window, quantity and capacity, eligibility and exclusion trace, currency and unit, inclusions and charges, terms, accessibility and safety sources, fulfillment route and expiry.

03

Transparent ranking and voluntary selection

Rank only eligible options against guest-stated criteria, expose commercial influence and a plain-language reason and present an equally usable decline or no-addition path without preselection, urgency or repeated pressure.

Required evidence: Objective and constraints, candidate set, features, model and policy versions, commercial weight, position, reason, alternative, uncertainty, abstention, exposure, guest correction, accept or decline action, frequency cap and suppression receipt.

04

Purchase, fulfillment, and guest outcome

Revalidate item and price, obtain explicit review, commit once through approved reservation, order and payment tools and follow the addition into property confirmation, physical delivery, cancellation, refund, complaint and recovery.

Required evidence: Review version, selected item and quantity, revalidation, guest confirmation, idempotency, reservation or order mutation, payment states, property acknowledgment, service task, actual fulfillment, correction, cancellation, refund, complaint, recovery and outcome window.

Context-to-outcome path

Filter eligibility before ranking, and prove service after purchase.

Hospitality additions cross recommendation, commerce and physical operations. Each stage prevents a persuasive interface from outrunning source truth or guest choice.

  1. 01

    Frame one permitted recommendation moment

    Name property, channel, journey stage, guest or session scope, reservation, party, stated need, accessibility request, commercial purpose, permitted data, consent, suppression, unacceptable contexts and the no-recommendation outcome.

    Owner
    Guest service, privacy, marketing, accessibility and property owners
    Evidence
    Moment charter, property and channel, context fields and source, purpose, consent and suppression rules, sensitive-data exclusions, emergency and complaint exclusions, accessible alternative, objective, harm limits and stop condition.
  2. 02

    Qualify catalog and inventory

    Map additions, inclusions, duplicates, dependencies, incompatibilities, availability, capacity, price, terms, accessibility and safety sources and deterministically exclude anything that cannot be offered now.

    Owner
    Catalog, revenue, operations, accessibility, safety and finance owners
    Evidence
    Catalog contract, item and property identifiers, source versions, inventory and capacity read, eligibility rules, exclusions, price and policy components, accessibility and safety ownership, fulfillment path and rejected items.
  3. 03

    Build and evaluate bounded ranking

    Compare eligible options with guest-stated criteria, preserve commercial weights and explanations, test sparse and shifted context, sensitive proxies, position effects, popularity loops, segment exposure, abstention and a non-personalized baseline.

    Owner
    Product, data, model-risk, consumer and accessibility owners
    Evidence
    Frozen candidate and context sets, objective and features, model and ranker versions, baseline, offline metrics, position and exposure analysis, proxy review, stress cases, explanations, abstentions, human review and release decision.
  4. 04

    Present free choice and commit once

    Refresh eligibility, inventory, price and terms, show why the addition may fit and its full consequence, preserve equal accept and decline paths and submit only an explicit selection through bounded idempotent tools.

    Owner
    Guest, reservations, ecommerce, payment and property owners
    Evidence
    Display and position, disclosure and commercial influence, source refresh, price and terms, no-addition path, selection or decline, review version, payment reference, command, idempotency key, attempts, receipt and uncertain effect.
  5. 05

    Reconcile service and guest effect

    Join the accepted addition to authoritative order, charge, property acknowledgment and physical delivery; resolve cancellation, refund and complaint and evaluate guest and business effects without equating acceptance with benefit.

    Owner
    Operations, finance, guest service, recovery and analytics owners
    Evidence
    Reservation or order state, charge and settlement, service task, property acknowledgment, actual delivery, correction, cancellation, refund, complaint, recovery, opt-out, staff work, guest effect, business measure and attribution design.

Authority map

Separate exact offer controls, bounded ranking, and guest choice.

A recommendation model can order eligible additions. It cannot define eligibility, consent to a charge or certify that the guest benefited.

01

Deterministic offer and purchase controls

Software owns tenant and guest scope, consent and suppression, catalog contracts, eligibility, inventory, capacity, exact price, terms, frequency limits, purchase states, payment tokens, idempotency, receipts, reconciliation and retention.

  • Property, session, guest, reservation, item, inventory, exposure, selection, order and service identifiers
  • Eligibility, duplication, incompatibility, availability, capacity, frequency, consent and suppression checks
  • Currency, quantity, unit, inclusion, mandatory charge, tax, discount, deposit and refund calculations
  • Exposure, decline, selection, purchase, charge, fulfillment, cancellation, refund and correction states
02

Bounded relevance and explanation

AI can clarify stated needs, compare already eligible additions, rank against approved objectives and draft source-linked explanations while commercial influence, uncertainty, alternatives, abstention and no-addition remain visible.

  • Stated-need and service-moment candidates for correction
  • Eligible-item relevance and comparison candidates
  • Source-linked reasons, differences and alternatives
  • Abstention and staff-handoff drafts when context conflicts
03

Guest and property authority

The guest owns correction, decline, selection and cancellation rights under current terms. Qualified property owners control catalog truth, commercial objective, price and policy exceptions, accessibility and safety claims, service feasibility, fulfillment, refund, recovery and agent retirement.

  • Context correction, no-addition choice, explicit selection and opt-out
  • Catalog, promotion, price, package, inventory and exception decisions
  • Accessibility, allergen, dietary, alcohol, transport, safety and service judgments
  • Fulfillment, complaint, refund, recovery, correction, rollback and retirement

Upsell components

Build a choice ledger, not a persuasion score.

Four components preserve why an addition appeared, what the guest chose and whether the property actually delivered it.

01

Context, purpose, and suppression ledger

Version property, channel, guest or session scope, reservation, journey stage, original words, stated need, accessibility request, purpose, allowed fields, consent, decline, opt-out, frequency and prohibited selling contexts.

Operating contract: Behavior is not stated need, prior purchase is not present intent, operational contact is not marketing consent, view is not interest, silence is not permission, decline is not a prompt to retry and distress is not a sales opportunity.

02

Catalog and eligibility ledger

Version each addition, inclusion, dependency, inventory, capacity, service window, price, unit, terms, accessibility and safety source, fulfillment route, eligibility rules, exclusions and expiry.

Operating contract: Catalog item is not available offer, included feature is not upsell, mandatory charge is not optional, similar is not compatible, popularity is not fit, inventory is not delivery capacity and a model score cannot override an exclusion.

03

Ranking, exposure, and choice ledger

Preserve objectives, features, model and policy versions, eligible candidate set, commercial weights, positions, reasons, alternatives, abstention, every exposure, correction, accept, decline, dismissal and suppression receipt.

Operating contract: High score is not guest need, paid placement is not organic relevance, first position is not best fit, exposure is not comprehension, click is not consent, selection is not settled purchase and acceptance is not guest benefit.

04

Purchase, service, and outcome ledger

Link explicit selection to revalidation, quote or hold, reservation or order mutation, payment states, property acknowledgment, service task, physical delivery, correction, cancellation, refund, complaint, recovery and later analysis.

Operating contract: Command is not effect, authorization is not settlement, order confirmation is not delivery, checked task is not service, cancellation request is not refund, complaint closure is not satisfaction and revenue after exposure is not caused lift.

Delivery path

Prove one addition and service moment before scaling recommendations.

Start where eligibility, guest choice, purchase correctness and physical fulfillment can all be observed without pressuring a vulnerable moment.

  1. 01

    Choose one bounded addition cohort

    Select one property, journey moment, optional item family, guest context, current catalog and inventory, clear price and policy, staff owner, safe no-addition path and observable fulfillment or refund outcome.

  2. 02

    Map choice, offer, and service truth

    Inventory allowed context, consent and suppression, inclusions, catalog items, eligibility, availability, price, terms, commercial influence, accessibility and safety sources, purchase tools, service tasks and recovery.

  3. 03

    Build exact filters before ranking

    Implement deterministic exclusions and calculations, frozen candidate sets, source-linked relevance, commercial disclosure, uncertainty, equal decline, frequency limits, complete review and idempotent purchase with reconciliation.

  4. 04

    Test manipulation and operating failure

    Exercise sparse context, sensitive proxies, complaint state, repeated decline, popularity bias, paid boost, sold-out item, price change, hidden charge, accessibility mismatch, duplicate submit, payment timeout, service failure and refund delay.

  5. 05

    Release narrowly and follow delivery

    Run beside the current guest-service path, compare exposure quality, decline persistence, selection correctness, staff work, complaints, fulfillment and refunds and attribute guest or business change only under a suitable design.

Release controls

Six controls before an addition can reach a guest.

Recommendations can shape attention and spending before a guest realizes a commercial decision is being made. These controls preserve truth and free choice.

Purpose and vulnerable moments are bounded
Bind property, channel, journey stage, guest or session scope, reservation, stated need, accessibility request, consent and permitted data; prohibit sensitive inference and suppress sales during emergencies, complaints, disputes, distress and unresolved recovery.
Eligibility precedes model ranking
Version catalog, inclusions, inventory, capacity, service window, compatibility, accessibility, safety, price and policy and deterministically exclude unavailable, duplicate, incompatible, unsafe or otherwise ineligible additions before scoring.
Ranking influence remains visible
Publish the objective, candidate set, commercial weights and exclusions, disclose promoted treatment, compare with non-personalized and popularity baselines, test position and segment exposure and preserve reasons, alternatives, uncertainty and abstention.
Decline is equal, durable, and respected
Use clear labels and equal controls, offer a no-addition path, prohibit default paid extras, fake urgency, artificial scarcity and confusing wording, cap frequency and persist decline and opt-out across the defined context.
Purchase requires exact review
Refresh item, inventory, quantity, price and terms, show effect on the base service and require explicit guest selection; keep account data outside model context and separate authentication, authorization, capture, settlement and property commit.
Service and outcomes are reconciled
Use idempotent bounded commands, resolve unknown effects before retry and join order, charge and property acknowledgment to physical delivery, cancellation, refund, complaint and recovery; never call acceptance benefit or revenue causation.

Outcome evidence

Measure voluntary choice and delivered value, not acceptance alone.

A high acceptance rate can come from pressure, hidden defaults or misplaced offers. Proof must include who saw what, why, what committed and what was actually served.

Baseline

  • Properties, channels, journey moments, guest or session contexts, purposes, consent and suppression rules, catalog items, inclusion and eligibility rules, inventory sources, price and policy families, purchase tools, service owners and outcome windows
  • Current guest and staff time from need clarification through offer, decline or selection, review, purchase, property acknowledgment, service, cancellation, refund, complaint and recovery
  • Current ineligible, stale, duplicate, inaccessible, unsafe, hidden-charge, over-frequent, complaint-time and unexplained offers; opt-outs, abandoned purchases, duplicate effects, delivery failures, refunds and staff overrides
  • Current exposures, positions, choices, purchases, charges, delivered additions, cancellations, refunds, complaints, recoveries, guest effects, revenue and margin with channel, season, demand and concurrent campaign context

Outcome evidence

  • Correct tenant, property, guest scope, purpose, consent, suppression, item, inclusion, eligibility, inventory, price, policy, position, explanation, selection, purchase, charge and fulfillment handling against authoritative evidence
  • Eligible-offer rate, stale-offer prevention, explanation and price comprehension, decline persistence, frequency, opt-out, exposure concentration, selection correction, purchase correctness, delivery, cancellation, refund and staff work by relevant context
  • Cross-tenant context, sensitive inference, vulnerable-moment selling, hidden commercial boost, ineligible rank, default charge, false scarcity, obstructed decline, raw account data in model context, blind retry, duplicate effect and unsupported delivery prevention
  • Guest-reported fit, accessibility handling, complaint and recovery, actual service, refund settlement and business outcomes against non-personalized, manual and no-offer baselines with experiment, season, channel, inventory and attribution limits visible

Guardrails

  • Wrong tenant, property, guest, reservation, moment, purpose or item; sensitive or protected traits inferred; excessive history retrieved; distress or complaint targeted; operational consent reused for marketing; decline or opt-out ignored
  • Included or mandatory item presented as optional, unavailable or incompatible item ranked, stale inventory called live, hidden paid boost, cheaper suitable option concealed, price unit unclear, mandatory charge hidden, paid extra preselected and artificial urgency or scarcity
  • View called interest, click called consent, selection called purchase, authentication called payment, authorization called settlement, payment called property commit, timeout retried, duplicate charge or order and guest correction lost
  • Order confirmation called physical delivery, cancellation called refund, complaint closure called satisfaction, acceptance called guest benefit, position bias hidden, harmed exposure averaged away and recommendation activity presented as incremental conversion, revenue, margin or satisfaction proof

Fit test

Use this pattern when one optional addition can be traced into service.

Good reason to begin

  • One property has a versioned optional catalog, explicit inclusions, authoritative inventory, eligibility, price and policy, clear consent and suppression rules, named accessibility, safety and service owners and observable fulfillment or refund evidence.
  • Context, candidate generation, deterministic exclusion, model rank, commercial influence, exposure, decline, selection, purchase, charge, property acknowledgment and physical delivery can remain linked but distinct.
  • The guest can understand and correct the context, decline as easily as accept, avoid repeated prompts, review exact terms, reach human help and remove or cancel under current policy.
  • Sparse context, sensitive proxy, popularity feedback, paid boost, sold-out item, price change, accessibility mismatch, duplicate submit, payment uncertainty, service failure, complaint and refund can be tested with synthetic or explicitly sanitized fixtures.

Resolve before beginning

  • Recommendation purpose, allowed context, consent, suppression, item owner, inclusion, eligibility, inventory, price unit, policy, accessibility or safety source, purchase authority, service task or outcome evidence is undefined.
  • The process cannot distinguish eligible candidate, ranked recommendation, promoted placement, exposure, click, selection, purchase, charge, property confirmation, physical delivery, cancellation, refund and guest outcome.
  • Success is defined only by acceptance, average order value, margin or revenue without eligibility, informed choice, decline persistence, unfair exposure, staff work, fulfillment, refund, complaints, guest effect and attribution evidence.
  • The agent is expected to infer sensitive needs, rank unavailable items, hide commercial influence, preselect charges, create urgency, obstruct decline, sell during distress, blind-retry purchases or guarantee conversion, revenue, satisfaction or compliance.

Source basis

Sources behind the control model.

  • 01

    International Organization for Standardization

    ISO 22483:2020: Hotels service requirements

    ISO states that this international standard was confirmed in 2026 and remains current. Its public abstract covers hotel staff, service, events, entertainment, safety and security, maintenance, cleanliness, supply management and guest satisfaction, including subcontracted services. It does not define guest recommendation context, catalog eligibility, inventory, price, ranking, consent, purchase, payment, fulfillment, certification or any property's outcome.

  • 02

    International Organization for Standardization

    ISO 10008:2022: Guidance for B2C electronic commerce transactions

    This published international standard gives guidance for planning, implementing, maintaining and improving a fair, effective, efficient, transparent and secure business-to-consumer electronic commerce transaction system. It does not define a hospitality catalog, lawful consent, recommendation objective, dark-pattern test, price, eligibility, inventory, payment result, legal compliance, guest satisfaction or commercial outcome for a specific journey.

  • 03

    National Institute of Standards and Technology

    NIST SP 1270: Identifying and managing bias in AI

    NIST describes the final March 2022 publication as a first step toward methods for assurance, governance and practice improvements around harmful bias, treating bias as a socio-technical concern. It does not provide a hospitality taxonomy, sensitive-proxy list, fairness metric, legal test, recommendation threshold, ranking validation, consent decision or proof of equitable exposure or guest benefit.

  • 04

    PCI Security Standards Council

    PCI DSS v4.0.1 document library

    The PCI SSC document library lists PCI DSS v4.0.1 as the published payment-card data security standard. Its scope concerns protection of payment account data and cardholder-data environments. It does not prove item eligibility, price accuracy, guest consent, fraud disposition, authorization, capture, settlement, order correctness, delivery, refund or compliance outside its scope.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD