Keep permissions proportionate
Ask only for access needed by a defined feature. Explain the reason at the appropriate time and provide a useful path when a user declines an optional permission. Use dated records rather than relying on memory at the next review.
Define which service owns records and how the app reads or updates them. Handle expired sessions and unavailable systems explicitly. Document responsibilities so delivery does not depend on assumptions.
Make the plan fit your market
Discuss whether users in Philadelphia need appointments, field-service access, local inventory, or delivery features. Use the actual workflow to decide whether location data is necessary; do not request device permissions merely because the app serves a local market. Use accurate service coverage for customers in Philadelphia.
Document APIs, authentication, failure handling, and data ownership. Test slow responses and unavailable external systems, not just the successful path. Confirm permissions before sharing customer information or assets.
- Current accounts and assets
- Verified business information
- Customer questions
- Budget and team capacity
Discuss Your Priorities