Enterprise playbook

Enterprise API key & SCIM token management playbook

Suite Profit runs Profitroom Suite extensions across hotel groups of three to fifteen properties, and every deployment sits on top of a governed inventory of API keys and SCIM tokens issued from the group's corporate directory. This playbook is the reference we publish for the CIO office, the group revenue office and the head of hotel systems when a portfolio consolidates its Profitroom access under a single credentials programme.

Who this is for

Group CIO or head of IT, group information-security lead, corporate revenue office, and the Suite Profit onboarding architect assigned to the portfolio. If a property GM has never spoken to your central IT function, this playbook will not land — talk to us about a phased governance uplift first.

Prerequisites

  • Corporate identity provider live (Okta, Microsoft Entra ID / Azure AD, or Ping) with SCIM enabled and a named security engineer as owner.
  • A group-approved secrets vault: HashiCorp Vault, 1Password Teams, AWS Secrets Manager or Azure Key Vault. Personal password managers are out of scope.
  • A Profitroom account manager who can raise API applications at group level rather than per property.
  • A signed data-processing agreement between Suite Profit Sp. z o.o. and the operating entity of the group.

Step 1 — Corporate directory as the source of truth

Every human operator and every service account that eventually touches the Suite Profit operator console is provisioned from the group's corporate directory over SCIM. Human accounts sit under a security group named SuiteProfit-Operators; service accounts sit under SuiteProfit-ServiceAccounts. Removing a user from the group in Okta or Entra ID revokes their console access within the next SCIM push, typically under a minute. There is no local password store on the Suite Profit side.

Step 2 — Request Profitroom API applications at group level

Ask your Profitroom account manager to open one API application per property under a single group namespace. Naming convention: suiteprofit.[group-slug].[property-slug].[env], for example suiteprofit.rivercollection.warszawa.prod. This name is what appears in Profitroom Suite audit logs, in the Suite Profit rotation ledger and in your SIEM. Consistency here saves hours during quarterly reviews.

Step 3 — Store secrets in the group vault, never in the console

Suite Profit's operator console does not accept a pasted key from any workstation outside the vault-issued short-lived session. During onboarding we install a vault-broker that fetches the Profitroom API key at connection time, injects it into the Suite Profit configuration record, and destroys the local copy. The console displays only a masked fingerprint. Access to unmask a fingerprint is a break-glass event logged to the group SIEM.

Step 4 — SCIM token lifecycle

SCIM tokens between Suite Profit and the group IdP are issued for 12 months, rotated on the calendar quarter boundary, and stored twice: once in the IdP's admin console and once, encrypted, in the group vault. A rotation event triggers a signed webhook to the CIO office. Any manual rotation raised through the Suite Profit operator console requires a two-eyes approval from a named security engineer.

Step 5 — Quarterly rotation cadence

Production Profitroom API keys rotate every 90 days. The Suite Profit onboarding architect runs the rotation window on the first Tuesday of each quarter, coordinated with the group revenue office so it does not collide with a rate publish. The full portfolio typically completes rotation in six to nine business days: one property per hour with automated overlap, plus a 24-hour observation window before the previous key is revoked.

Step 6 — Break-glass and staff turnover

When a group revenue director or a corporate systems engineer leaves the organisation, the SCIM removal is the trigger, not a ticket. Suite Profit closes their operator console session, revokes any personal access token they held, and — if they held admin access on any property — forces an out-of-band rotation of every Profitroom API key on that property within the following business day.

Estimated timeline

For a portfolio of three to fifteen properties, initial credentials programme rollout runs three to five weeks: one week of corporate directory scoping, one to two weeks of vault integration, and one to two weeks of per-property Profitroom API application issuance and connection under the naming convention above.

Next steps

Open Corporate Identity & SSO Hub Back to playbooks