Keep permissions proportionate
Ask only for access needed by a defined feature. Explain the reason at the appropriate time and provide a useful path when a user declines an optional permission. Keep the original result alongside the updated version.
Define which service owns records and how the app reads or updates them. Handle expired sessions and unavailable systems explicitly. Set a review deadline and identify the person responsible.
Make the plan fit your market
Discuss whether users in New York need appointments, field-service access, local inventory, or delivery features. Use the actual workflow to decide whether location data is necessary; do not request device permissions merely because the app serves a local market. Base local references on service coverage and customer needs, not invented examples.
Document APIs, authentication, failure handling, and data ownership. Test slow responses and unavailable external systems, not just the successful path. Agree how sensitive material will be shared and stored.
- Current accounts and assets
- Verified business information
- Customer questions
- Budget and team capacity
Discuss Your Priorities