House Desk uses narrow integrations rather than giving another service broad access to its data.
| Integration | What crosses the boundary |
|---|---|
| Transactional email | The minimum delivery information for confirmation, management, and renewal messages |
| Abuse protection | A verification result for higher-risk public forms |
| Calendar applications | A resident’s private calendar feed when that app presents the private URL |
| Pub event display | Selected fields from published Programs entries only |
| Staff identity | A verified identity assertion; House Desk still decides product permissions |
Each consumer receives only what its task requires. Pub does not receive resident subscriptions, the identity provider does not decide House Desk permissions, and calendar clients do not gain access to the staff console.
Reliability principle
Integrations fail independently where possible. A publication or resident task should not silently succeed when a required delivery or authorization step failed, and an optional downstream display should not be able to mutate House Desk source records.