All insights

How should a not-for-profit handle accounts for volunteers and high turnover?

6 min readBy Brendon Whiting, Founder · 9 July 2026

Grant access by role rather than person, make onboarding fast enough that nobody works around it, and attach account removal to something that reliably happens when people leave. The exposure in this sector is rarely a weak password; it is the account nobody closed.

The pattern is consistent across not-for-profits and it is nobody's fault. People arrive quickly, often as volunteers or on short placements, and somebody sets them up so they can be useful. That somebody varies, the setup varies, and nobody records exactly what access was granted. Then the person finishes, there is no formal exit process because they were a volunteer, and the account persists. Multiply by several years of turnover and the user list contains people the organisation no longer knows.

That is a genuine exposure rather than untidiness. Those accounts can typically reach participant records, donor information and organisation files. They are protected by whatever password was set on day one, which may be reused elsewhere and may since have appeared in a breach. Nobody is monitoring them because nobody knows they are active. And if one is used, the audit trail points at a person who left, which makes any investigation considerably harder.

Role-based access is the structural fix. Define the handful of roles your organisation actually has, volunteer, support worker, coordinator, finance, board member, and attach an access set to each. Then onboarding becomes assigning a role rather than making individual decisions, which is faster and more consistent, and offboarding becomes removing it. It also means access is documented by design, so you can answer what a volunteer can see without inspecting individual accounts.

Speed matters more here than in most sectors, because slow onboarding produces workarounds. If getting a new volunteer set up takes a week, someone will share their own login to be helpful, and shared logins destroy the audit trail entirely. Making the process fast, ideally same-day, removes the incentive. At nonprofit licensing rates, giving people their own account is usually affordable, and it is what makes any accountability possible.

Offboarding needs to be attached to something that already happens. Returning a key, a badge, a uniform or a vehicle is remembered because it is physical and someone is waiting for it; disabling an account is invisible and gets forgotten. Putting account removal on the same checklist, owned by the same person, is a process change rather than a technical one and it is the single most effective thing most not-for-profits can do about this.

Personal devices need their own step, since volunteers and staff commonly use their own phones. Enrolling the organisation's applications on those devices means access can be withdrawn cleanly at the end without touching anything personal, which is both more effective and less intrusive than the alternatives. TAPS applied Zero Trust across organisation computers and staff-owned mobiles precisely because personal devices are unavoidable in this sector.

Board members deserve a specific arrangement rather than being treated as staff. They need board material and rarely operational systems, and board papers frequently contain sensitive discussion that should not sit in general storage. A restricted area with its own access list, reviewed when the board changes, handles it. Board turnover is one of the few staffing changes an organisation knows about in advance, which makes it the easiest access review to get right.

Then review quarterly, and make it short. Pull the user list, and for each account ask whether that person is still involved and whether their access still matches their role. Twenty minutes, four times a year. In most organisations the first review finds several accounts nobody can explain, and after two or three cycles it becomes uneventful, which is the point.

The honest caveats. Some informality is inherent to a volunteer organisation and trying to impose corporate process wholesale will fail. The aim is a light structure that survives busy periods rather than a policy nobody follows. And this is unglamorous work that never feels urgent, which is exactly why it needs an owner and a recurring date. If you want role-based access set up so it holds, call 1800 456 567.

Start with the quarterly review rather than the policy, because pulling the user list once and asking who each of these people is will tell you more about your actual exposure than any amount of process design beforehand.

Make joining and leaving routine

We set up role-based access so bringing someone on takes minutes and removing them is a single action that genuinely happens.

Frequently asked questions

If they access organisation systems, yes. Shared logins destroy the audit trail, so you cannot tell who viewed a participant record, and they make removal impossible without disrupting everyone. Individual accounts cost little, particularly at nonprofit pricing, and they are what makes accountability possible.

They need access to board material and rarely to operational systems, and that distinction is often not made. Board papers containing sensitive discussion should sit in a restricted area with its own access list, and board access should be reviewed when the board changes, which is a date you already know in advance.

Attach it to something that already happens reliably. Returning a key, a uniform or a badge is remembered because it is physical; account removal is not, unless it sits on the same checklist. Tying the two together is a process change rather than a technical one and it works.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.