Map the boundary
Identify whether the booking experience opens a same-page element, a cross-origin iframe, a popup or an external page. Browser security boundaries can prevent the host website from reading the provider's internal state, and SiteAirbag does not bypass those boundaries.
Provider-specific hosted compatibility must be verified before it is advertised. Consult the dated matrix rather than assuming that generic installation guidance proves a provider integration.
Protect evidence the host can see
The host page may be able to observe whether the launcher responds, whether the expected iframe or dialog appears, whether a same-origin navigation occurs, or whether a known request fails. Do not interpret an unrelated provider or page error as proof that the configured booking action failed.
Choose an independent spare door
Use a backup booking page hosted separately by the business, a staffed telephone route, or a minimal callback/preferred-time request. Keep the language explicit: the backup captures a request and does not confirm an appointment.
Exercise provider and browser variations
Test the current provider flow on desktop and mobile, with popup and content blockers where appropriate. Repeat the check when the provider, embed code, consent manager or content-security policy changes. If the evidence is ambiguous, alert for review instead of interrupting the visitor.
Verify before relying on it
Test the original action and configured backup on desktop and mobile after installation and after material site changes. Review the dated compatibility matrix, installation instructions, and security model. SiteAirbag is a fail-open recovery layer, not a guarantee that every failure is detectable or every request becomes a business outcome.