Lead Hospitality

Hotel AI Needs an Authority Matrix

THE IDEA

A practical framework for deciding what artificial intelligence can monitor, recommend or execute in a hotel—and which decisions must remain under human authority. The right level depends on impact, reversibility, context, traceability and accountability to guests, employees and the business.

In a recent meeting, we were reviewing a tool capable of recommending rates, prioritising requests, identifying problematic bookings and suggesting responses to certain complaints. The demonstration was convincing, and each new feature seemed to save a few additional minutes. Then I asked a fairly simple question: what specific authority are we willing to hand over to this system? An uncomfortable silence followed. We had discussed accuracy, integration, speed and return on investment, but we had still not decided what artificial intelligence could do on its own, when it should ask for permission and where it should stop.

That scene captures a confusion I am seeing with increasing frequency in Hospitality. We assess tools when we should be assessing decisions. We ask what features a platform includes, but not what consequences each one may produce. We celebrate the fact that an algorithm can act in real time without considering whether speed adds value or merely allows an error to travel faster through the hotel. Automation is appealing because it promises to remove work, although it can also remove the space in which a person might have spotted an exception, interpreted the context or prevented an absurd decision.

I have learned that the right boundary is not between human tasks and technological tasks. That distinction is too superficial for hotel management. The same tool can be exceptionally useful when forecasting demand and deeply inappropriate when deciding how to treat a vulnerable guest. An algorithm can rank thousands of alternatives better than we can and, at the same time, lack the context required to understand a single important exception. Its computing power does not automatically grant it operational, commercial or moral authority.

The most dangerous mistake is to think that there are only two options: automate or do not automate. Between the two lie several degrees of intervention that should be designed carefully. AI can observe, alert, recommend, prepare an action, execute it within limits or be expressly prohibited from intervening. Each degree requires different data, controls and accountable owners. If the hotel does not define those differences, the vendor’s default settings will ultimately decide how much power the team retains. And few strategic decisions should be hidden inside a settings menu.

That is why I propose building a Hotel Algorithmic Authority Matrix. Its purpose is not to slow innovation or turn every project into an endless control committee. It seeks something far more constructive: allowing artificial intelligence to act autonomously where it delivers speed, consistency and analytical capability, while protecting decisions that require judgement, empathy, legitimacy and human accountability. A modern hotel should not have to choose between efficiency and hospitality. It must learn to distribute authority properly between the two.

Profesionales hoteleros analizando una matriz de autoridad para decisiones de inteligencia artificial

Authority must be assigned to the decision, not the tool

An AI platform should never receive blanket authorisation to “optimise operations”, “personalise the experience” or “improve revenue”. These expressions describe ambitions, but conceal hundreds of different decisions. Optimising revenue may mean recommending a rate, closing a channel, declining a booking, removing a benefit or selecting which guest receives an offer. Personalisation may mean remembering an innocuous preference or exposing information the customer did not want made visible. The function appears to be the same; the impact changes completely.

The unit of analysis must be the individual decision. Before connecting an algorithm to the PMS, CRM, booking engine or operation, it is worth setting out clearly what it will be allowed to decide. “Assign rooms” is still too broad. We need to specify whether it can select a room within the booked category, change the category, separate linked rooms, use historical preferences, block an accessible unit or defer pending maintenance. Each verb contains a different consequence.

AI Hotel Intelligence

AI is only as smart as the context you give it. HotelGEX gives it your whole hotel.

Guests, Revenue, operations, F&B, Groups & Events and Management connected in one intelligent context, so HotelGEX AI can understand what is really happening across your hotel.

HotelGEX Intelligence
AI
One AI.
Full hotel context.
Intelligence that connects what your hotel already knows.
Understand
Anticipate
Recommend

The first lesson of this matrix is therefore highly practical: there are no low- or high-risk tools in the abstract; there are uses and decisions with different levels of impact. A generative model may draft an internal description with few consequences and, minutes later, be used to respond to a serious allegation of discrimination. The technology is identical. The decision, exposure and responsibility are not.

The six questions that determine how much AI may decide

To assign the appropriate level of autonomy, I use six dimensions. I do not treat them as a mathematical sum that creates a false sense of precision. They function as a structured conversation that forces the hotel to consider what a sales demonstration usually leaves out.

  • Human impact. We must identify who may benefit or be harmed by the decision, and to what extent. Sorting an internal task list has limited impact. Denying a service, penalising a person, changing an employment condition or flagging a guest as suspicious affects their dignity, opportunities and relationship with the hotel. The greater the impact on a person, the lower the algorithm’s autonomy should be.

  • Reversibility. A decision is more suitable for automation when it can be corrected quickly and without causing meaningful harm. Reordering a maintenance queue can be reversed. Communicating a false accusation, cancelling a family booking on a date with no availability or revealing a private preference in front of third parties cannot be fixed by pressing “undo”. Reversibility does not depend only on recovering money; it also includes trust, reputation, time and emotional safety.

  • Context ambiguity. Algorithms perform best when the objective, constraints and exceptions are defined. They become less reliable when a decision depends on intentions, contradictions, social norms or information that never reached the system. A late arrival may appear to be a simple delay, but it could be connected to a medical emergency, a cancelled flight or an error by the hotel itself. If context substantially changes the correct response, AI must escalate before acting.

  • Evidence traceability. The hotel needs to know what information the system used, what rules it applied and which version of each data point was in force. Authority should never grow faster than the ability to explain the decision. This requirement is linked to the need for hotel AI to demonstrate how it knows what it knows. A recommendation without verifiable provenance may guide a conversation; it should hardly execute an action with material consequences.

  • Error asymmetry. Not all mistakes carry the same cost. If recommending an unsuitable time to send a campaign slightly reduces its performance, the harm is limited. If a system misinterprets an accessibility need, a risk situation or a dietary restriction, the consequences may be far greater. When the cost of being wrong in one direction is much higher than in the other, we need more conservative limits.

  • Relational content of the decision. Some decisions do not merely produce an outcome; they express how the hotel understands its relationship with guests and employees. Compensation communicates recognition. An exception communicates judgement. A sanction communicates fairness. A refusal communicates boundaries. AI can calculate alternatives and recall precedents, but final authority must remain with someone who can listen, explain, own the decision and answer for it.

These six dimensions avoid a misleading question: “Can AI do it?” In most cases, the technical answer will eventually be yes. The professional question is different: should we allow it to do so alone, and under what conditions? Technical possibility is only the beginning of hotel strategic planning.

The five levels of algorithmic authority

The matrix translates those dimensions into five levels. Every hotel decision should be placed in one of them and have a human owner, even when autonomous execution is authorised.

Level AI role Operating condition
0 Prohibited AI neither recommends nor executes the final decision. There is a serious impact on dignity, rights, safety, employment or access to service that requires human assessment.
1 Observer Collects, classifies and presents information. It may detect signals, but does not independently interpret the response the hotel should take.
2 Adviser Proposes alternatives and explains its reasoning. A competent person reviews the context and retains genuine authority to accept, amend or reject.
3 Conditional executor Acts within a previously approved corridor. It respects financial, operational and relational limits, and escalates any exception.
4 Bounded autonomous Executes and records routine decisions without prior approval. The impact is limited, errors are reversible, rules are stable and post-decision controls exist.

Level 4 does not mean absolute freedom. It means bounded autonomy. The system may act within a defined territory, for a set period and with the ability to be stopped immediately. An algorithm could automatically replenish certain supplies between minimum and maximum levels, but it should stop if the supplier changes, consumption rises abnormally or a quality issue emerges. It could also assign routine housekeeping tasks while respecting workloads, skills and restrictions, but not use opaque metrics to systematically punish certain people with the most demanding work.

Level 3 will probably be the most useful for many hotels. It makes speed possible without handing over unlimited authority. In hotel revenue management, for example, a system may adjust prices within an approved corridor, provided it does not breach positioning, commercial terms or certain commitments. When a change exceeds a threshold, affects strategic dates or substantially alters the business mix, it must seek validation. Well-designed autonomy does not eliminate boundaries; it makes them visible.

In distribution, AI can rank opportunities by contribution, risk and capacity, but that automation needs to reflect how the hotel actually makes decisions. The criterion explained in hotel distribution should rank bookings, not channels is particularly relevant. If the algorithm inherits a simplistic classification of good and bad channels, it will automate prejudice rather than improve the decision.

Something similar happens with room assignment. AI can combine category, occupancy, length of stay, maintenance, requests and housekeeping capacity with a level of precision that is difficult to replicate manually. It may be given authority to choose between equivalent available rooms. However, it should escalate if the assignment means disregarding an accessibility need, separating linked bookings, using sensitive information, consuming a strategic upgrade or placing the guest in a unit with a known operational risk.

In hotel marketing, the algorithm may identify segments, rank audiences, propose content and adjust investment within approved budgets. It should not independently publish claims about services that have not been verified, use personal vulnerabilities to pressure a purchase or turn a correlation into a permanent label for the customer. Personalisation loses legitimacy when the guest no longer feels recognised and begins to feel watched. I have already addressed that tension in analysing why a CRM can know too much and make the guest start to feel suspicious.

The decisions an algorithm should never make alone

The word “never” should be used carefully, especially in innovation. Even so, there are boundaries I consider necessary. They do not mean AI must remain absent. It can organise information, retrieve precedents, identify inconsistencies and suggest alternatives. What it must not receive is the final say.

  • Hiring, dismissing, sanctioning or blocking a person’s professional development. A system can help rank candidates or identify training needs, but it should not decide who deserves an opportunity, who is acting in bad faith or who must leave the hotel. Employment data contains absences, historical errors, subjective assessments and contextual inequalities that can quickly become a mathematical appearance of fairness.

  • Denying an essential service or removing a guest from the property. AI may detect patterns of fraud, non-payment, threats or breaches. The decision to refuse, cancel or remove someone requires verifying facts, assessing safety, hearing accounts and accepting responsibility before the affected person. A risk indicator is not a verdict, even if it appears in red and has many decimal places.

  • Determining the credibility of a serious complaint. Tone, vocabulary or historical behaviour cannot automatically establish whether someone is telling the truth. AI may summarise communications and identify previous cases, but it must not decide that a guest is exaggerating, an employee is lying or a report is unfounded.

  • Disclosing or activating intimate information without considering the audience. A stored preference can improve the stay and, at the same time, create unwanted exposure if mentioned in front of a companion, company or group. The algorithm may prepare the service discreetly; it must not decide by itself when private information may become socially visible.

  • Resolving incidents involving safety, discrimination, harassment or vulnerability. AI can help identify signals and activate protocols, but the response requires professionals able to protect, listen, document and adapt their actions. These situations do not tolerate automation that confuses uniformity with fairness.

  • Setting final redress after significant harm. An algorithm can calculate the financial value of a stay, retrieve the history and suggest options. It cannot determine on its own what it means to remedy a humiliation, a sleepless night, a major loss or a serious failure. Moreover, compensation does not always repair harm. The decision needs to acknowledge both economic and relational damage.

  • Unilaterally changing principles that define the hotel’s promise. AI may identify that a policy reduces margin or that special attention consumes time. It should not automatically eliminate it if that practice forms part of the positioning, a commercial commitment or the guest experience in hotels. Some efficient decisions destroy precisely what made the rate defensible.

These boundaries do not stem from romantic distrust of algorithms. Humans also make mistakes, apply biases and take inconsistent decisions. That is precisely why we need a system that combines capabilities, distributes responsibilities and allows correction. Replacing a poor human decision with a poor automated one is not innovation; it merely improves its productivity.

Governing AI means designing permissions, limits and accountability

A matrix adds value only when it is embedded in the operation. If it remains filed away alongside policies nobody consults, real authority will continue to reside in system configurations, project urgency and team habit. Hotel AI governance must be translated into specific permissions, identifiable owners, useful records and stop mechanisms.

I would begin by creating an Algorithmic Decision Inventory. Not a software inventory. The aim is to discover where artificial intelligence already has influence, even where we do not yet call it that. An RMS suggests prices, a CRM selects audiences, an anti-fraud system blocks payments, a reputation platform classifies comments and a scheduler allocates shifts. Every recommendation changes human behaviour, even indirectly.

For each decision, it is worth recording who is affected, what data is used, what result the hotel seeks, what errors are possible, who answers for them and what level of authority has been granted. This review often reveals particularly dangerous “informal” automations. I mean recommendations that are officially advisory, but which nobody dares question because the system appears more objective than the team.

Human oversight must be real, not decorative

Many implementations claim that human oversight exists because someone has to click an approval button. That guarantees nothing. If the person receives fifty recommendations in succession, has only a few seconds, does not understand the logic used and will be challenged every time they contradict the system, their intervention is ceremonial. They are signing off on someone else’s decisions.

Meaningful human oversight requires five conditions. The person must understand what they are reviewing, have sufficient information, be given reasonable time, hold effective authority to amend the proposal and be able to justify an exception without being automatically penalised. If any of these is missing, the hotel retains an approver but has lost the decision-maker.

It is also worth monitoring automation bias. With continued use, a recommendation stops being seen as an opinion and starts being treated as the correct answer. The team learns to obey while its capacity for judgement weakens. When a serious exception finally appears, nobody is prepared to spot it. It is an uncomfortable paradox: the more reliable the system appears, the more important it becomes to retain people trained to challenge it.

To prevent this, the hotel can periodically review a sample of accepted, rejected and corrected decisions. It is not enough to analyse obvious errors. We must also study apparent successes that generated side effects, such as a profitable rate that attracted operationally unsuitable demand, a campaign with strong conversion that increased cancellations or an efficient assignment that undermined the experience of a repeat guest.

The execution corridor makes autonomy governable

A level 3 or 4 decision requires an algorithmic execution corridor. This corridor defines the precise space in which AI can act without requesting authorisation. It includes financial, temporal, operational and relational limits. It must also establish exit signals that require the system to stop and escalate.

  • Value limits. The algorithm may approve a refund, adjust a price, authorise a purchase or grant a benefit up to a specified amount. Above that amount, the accountable owner changes and the review requirement increases.

  • Context limits. Autonomy may be suspended during critical events, high occupancy, safety incidents, system failures, refurbishments, supplier changes or periods when input information is less reliable.

  • Population limits. Some decisions require additional protection when they affect minors, people with accessibility needs, employees, vulnerable guests, complainants or customers exposed to significant contractual consequences.

  • Frequency limits. A reasonable action applied once can become a problem if repeated. The system should detect accumulations of discounts, messages, room changes, blocks, offers or adverse decisions concerning the same person or segment.

  • Confidence limits. When data is incomplete, contradictory or old, AI must reduce its autonomy. It is not acceptable for a recommendation to become more categorical precisely when it has less evidence.

  • Cross-impact limits. A commercial decision may shift work to Operations, a Housekeeping optimisation may delay arrivals and an improvement in conversion may increase demand for an overloaded service. The corridor must protect the entire hotel, not merely the tool’s KPI.

This last point deserves particular attention. Artificial intelligence tends to optimise the objective assigned to it, not the hotel business as a whole. If we ask for maximum occupancy, it may ignore operational capacity. If we ask for productivity, it may concentrate workloads at unsustainable levels. If we ask for conversion, it may offer discounts to customers who would have purchased anyway. If we ask to reduce human contacts, it may create more repeat contacts and corrections, as happens when a chatbot generates more work than it eliminates.

The algorithm is not necessarily failing. It may be doing exactly what its narrow objective requires. Responsibility belongs to those of us who defined that objective without counterbalances. In Hospitality, optimising one part can surprisingly easily undermine the overall guest experience, operation and hotel profitability.

A decision card for every AI use case

To ensure the matrix does not depend on interpretation, I recommend creating a brief record for each automated decision. I call it an Algorithmic Authority Card. It should be understandable to someone in Operations without needing to know the tool’s technical architecture.

  • Authorised decision. It should be described with a specific verb, avoiding broad formulations such as improve, personalise or optimise. For example, “adjust the public rate within the approved corridor for the next eight weeks”.

  • Objective and counterbalances. Alongside the primary outcome, the conditions that must not deteriorate should be stated. A system may maximise contribution while respecting positioning, capacity, contractual parity, commercial promises and the expected experience.

  • Permitted data and excluded data. The card determines what information may be used and what must not enter the decision, even if the hotel has it. Possessing data does not automatically grant permission to turn it into a criterion.

  • Authority level. One of the five levels is assigned, indicating who approves any subsequent change. The vendor should not expand functions or connect new data without reviewing this authorisation.

  • Corridor and stop signals. Thresholds, exceptions, protected populations, schedules, validity periods and events requiring escalation are documented.

  • Human owner. Every decision needs a person or role responsible for reviewing results, handling incidents and ordering suspension. “The system” and “the vendor” are not valid operational owners.

  • Minimum record. The hotel defines what it must retain to reconstruct a decision without accumulating unnecessary data. At a minimum, it should know what happened, when, using what information, under which version of the rules and who intervened.

  • Expiry date. Authorisation should not be indefinite. Demand, teams, policies, positioning and data sources change. An autonomy level that was reasonable a year ago may be inappropriate today.

This card adds important discipline: every new function must earn its authority. A tool’s ability to execute a decision does not mean it automatically inherits permission granted to another similar function. Nor should an identical configuration be transferred between hotels with different operations, segments and risks.

What to measure after granting autonomy

Algorithmic accuracy is necessary, but insufficient. AI can be statistically correct and cause concentrated harm in minority situations. It can also produce correct decisions that generate so much review work that the expected saving disappears. Assessment must combine technical performance, operational outcome and human impact.

  • Human intervention rate. This measures how many decisions are amended or stopped by the team. A high rate may indicate poor calibration, incomplete data or an overly broad corridor. An extremely low rate is not necessarily positive either; people may have stopped reviewing.

  • Time to detection and correction. It matters how long the hotel takes to discover an error, stop it from spreading and remedy its effects. A small mistake can grow rapidly when replicated in rates, messages, assignments or profiles.

  • Residual work. Reviews, escalations, explanations, complaints, repeat contacts and data cleansing must be counted. Efficiency is measured by net capacity released, not by the number of actions executed automatically.

  • Distribution of outcomes. It is worth checking whether certain languages, channels, nationalities, booking types, spending profiles or employee groups consistently receive worse outcomes. The average may conceal a persistent inequality.

  • Full economic cost. An automated decision should be linked to revenue, cost to serve, compensation, displacement and future value. In certain commercial applications, assessment improves when each booking has its own profit and loss account.

  • Relational harm. Not everything appears in the immediate P&L. We must observe loss of trust, perceptions of unfair treatment, additional guest effort, team frustration and deterioration of the brand promise.

In addition, every system needs an interruption mechanism known to the operation. It should not be necessary to locate three vendors, open a ticket and wait for a response while the algorithm continues acting. The accountable person must be able to reduce autonomy, switch to recommendation mode or stop the function without paralysing the rest of the hotel.

Training must change as well. It is not enough to teach people where to click. The team needs to understand what the tool is trying to optimise, what information it does not know, which signals indicate an exception and how to document a discrepancy. The best defence against unsuitable automation is not a distrustful workforce, but professionals able to use it with judgement.

It is also worth explaining that contradicting the algorithm does not represent project failure. A good exception provides learning. If the team repeatedly corrects the same recommendation and nobody reviews the system, the hotel is paying twice: it maintains the tool and retains the manual work it was meant to improve. If, by contrast, every correction is used to refine rules, data and corridors, the relationship between people and AI becomes progressively more valuable.

If your hotel introduces a new artificial intelligence solution tomorrow, avoid starting by asking how many tasks it can automate. Bring together the people who understand the operation and list the decisions the tool intends to influence. Then assign each one impact, reversibility, context, evidence, asymmetry and relational content. That conversation will reveal more about the project’s risk and value than a long list of features.

My practical advice is to grant autonomy progressively. First observe, then recommend, later execute within a narrow corridor, and extend permission only when sufficient evidence exists. Trust in hotel AI should not be bought with the licence; it must be built decision by decision. And there must always be a person able to explain why the hotel allowed the system to act.

Artificial intelligence can help us run more consistent, agile and profitable hotels, but it cannot carry a responsibility that belongs to the organisation. The definitive question is not what an algorithm can decide. The question is what authority we are willing to hand over, what values must limit it and who will answer when the decision reaches the room, the team or the guest. That is where genuine governance begins, and where Hospitality becomes better prepared to innovate without relinquishing its judgement.

KEEP EXPLORING

This article ends here. The archive does not.

Lead Hospitality brings together 1200 English articles published since 2018: years of experiences, decisions and lessons you can keep exploring.

CONTINUE FROM HERE

What would you like to explore next?

Choose a direction and keep reading around what you want to solve, learn or challenge.

Discover something interesting ↓Surprise me ↗
01MAKE MOREProfitability, revenue and decisions that reach the bottom line. 02LEAD BETTERTeams, culture, talent and the conversations that matter. 03SELL BETTERPositioning, marketing, distribution and customers. 04CREATE EXPERIENCESService, loyalty and details guests remember. 05UNDERSTAND WHAT'S NEXTInnovation, AI and new ways of thinking about Hospitality. SURPRISE MEShow me something worth five minutes of my time.
✦ LEAD AI · KEEP THINKING

Take this analysis one step further