House Desk uses narrow integrations rather than giving another service broad access to its data.

IntegrationWhat crosses the boundary
Transactional emailThe minimum delivery information for confirmation, management, and renewal messages
Abuse protectionA verification result for higher-risk public forms
Calendar applicationsA resident’s private calendar feed when that app presents the private URL
Pub event displaySelected fields from published Programs entries only
Staff identityA verified identity assertion; House Desk still decides product permissions

Each consumer receives only what its task requires. Pub does not receive resident subscriptions, the identity provider does not decide House Desk permissions, and calendar clients do not gain access to the staff console.

Reliability principle

Integrations fail independently where possible. A publication or resident task should not silently succeed when a required delivery or authorization step failed, and an optional downstream display should not be able to mutate House Desk source records.