Charities and nonprofits · people and access

Charities depend on employees, volunteers, trustees and partners who may contribute for very different lengths of time. Stratiis helps nonprofit organisations across Scotland give each person the access they need, protect sensitive information and remove access promptly when their role ends.

What is staff and volunteer access management?

It is the process of giving each person a named account, the right applications and information for their role, suitable sign-in protection, support and a clear end date or review point. It covers onboarding, role changes and offboarding for employees, volunteers, trustees and temporary users. The goal is useful access without shared accounts or permissions that linger after someone leaves.

Support the mission

Why does access need a plan in a nonprofit?

People join for projects, events, seasonal work and board terms. A generic account or informal file sharing may feel quick, but it makes ownership, support and removal difficult. A simple access process saves time for coordinators while reducing the risk of donor, staff and service-user information reaching the wrong person.

Start quickly

Prepare accounts, tools and guidance before a person begins work.

Protect information

Match access to the role and the sensitivity of the work.

Use funds well

Assign licences and devices according to actual need and review unused access.

Leave cleanly

Remove accounts and retrieve organisational information when a role ends.

Different people, different needs

Should staff, volunteers and trustees have the same access?

No. Start with the tasks and information each role needs, then decide the account, device and support model. An individual’s access should be reviewed when their duties change.

Role Typical need Access decision
Core employee Email, collaboration, operational systems and a managed workstation. Which applications, data and security capabilities are needed for the job?
Volunteer Selected tools or information for a defined activity or period. Who approves access, how long does it last and what support is available?
Trustee Board papers, meetings and secure communications. How are confidential papers shared and personal devices handled?
Temporary worker or partner Limited access to a project or shared workspace. Is a guest or time-limited account appropriate, and who owns it?

Named accounts improve accountability. They also let the organisation remove one person’s access without disrupting everyone else.

Join, change, leave

How do you keep access current as people move through roles?

Give each user a sponsor or manager who can approve their access and confirm when it is no longer needed. The process should cover employees, volunteers and trustees, including those who return after a break.

1

Request

Name the person, role, sponsor and expected duration.

2

Approve

Confirm required tools and information access.

3

Provision

Create a named account, sign-in method and suitable device setup.

4

Review

Check access when duties or project needs change.

5

Remove

Disable access and recover devices or business data promptly.

6

Record

Keep an auditable record of approvals, changes and closures.

Microsoft 365 and collaboration

How should volunteers use Teams, SharePoint and email?

The answer depends on the work. Some users need an organisational email account; others may only need access to a specific workspace or meeting. Decide which Teams and SharePoint areas contain sensitive information, who owns them and how external or temporary access is reviewed.

Give access to the right workspace

Keep policies, programme documents, board papers and individual work files in appropriate locations. Avoid sending copies through personal email or leaving them in unmanaged storage.

Check licensing before assigning it

Microsoft nonprofit eligibility, features and pricing depend on the organisation and current provider terms. Review the capabilities each role needs rather than giving everyone the same plan.

Stratiis can help plan identity, Teams, SharePoint, OneDrive and device policies through our Microsoft 365 services.

Devices and locations

What if volunteers use personal or shared devices?

Personal devices can be useful, but the organisation should explain what standards apply and what it can manage or remove. Shared devices need a clear sign-in and sign-out process so one person’s files or messages do not remain available to the next. For sensitive work, a managed device may be the better choice.

Organisation-owned devices

Standardise setup, updates, encryption, approved apps and support.

Explore Workstations and Lifecycle →

Personal phones and tablets

Use proportionate work-app protection and clear privacy boundaries where supported.

Explore Mobile Device Management →

Shared or multi-site work

Plan who signs in, how data is cleared and where people get help when a device fails.

Explore Managed IT Services →

Trust and protection

How do you protect donor and service-user information?

Give access only to people whose role requires it, use suitable multi-factor authentication and train users to report suspicious messages or unexpected sign-in prompts. Review sharing links and guest accounts, especially where information relates to people the organisation supports. Secure access also needs a response plan for a lost device or compromised account.

Protect the sign-in

Use named accounts, appropriate MFA methods and clear account recovery. Offer an approved alternative for users who cannot use a personal smartphone for authentication.

Protect the information

Define workspace ownership, permissions, external sharing and what happens to documents when a user leaves.

These controls fit into a broader cybersecurity approach for charities and nonprofit organisations.

Trustees and governance

What should trustees be able to see about access risk?

Leaders need a clear view of how accounts are approved, reviewed and removed, rather than a raw list of technical settings. Useful reporting shows inactive accounts, overdue access reviews, shared or exceptional access, and actions planned for sensitive systems. It should identify an owner and decision for each significant gap.

Who has access?

Keep a current record of employees, volunteers, trustees and guests.

Who approved it?

Make sponsors and workspace owners accountable for permissions.

When was it reviewed?

Check that temporary access has not become permanent by default.

What changes next?

Show actions, owners and timing in plain language.

Our strategic technology guidance can connect access decisions to risk, funding and a practical roadmap.

Keep the process affordable

How do you control access costs without weakening security?

Use role-based templates for common jobs, remove licences and accounts when people leave, and review the devices and subscriptions each role genuinely needs. Standard onboarding also reduces repeated manual work. Savings should be weighed against the cost of poor access, lost service time or exposed information.

Check current nonprofit offers and licence terms before deciding who qualifies for which Microsoft 365 plan. Keep the choice tied to necessary features and support, not only the headline price.

How Stratiis helps

How can Stratiis improve staff and volunteer access?

We review current accounts, devices, applications and approval routes, then help design a workable access model for the organisation’s roles and information. The result should make joining easy, changes visible and departure reliable.

1

Discover

Map roles, services, users, devices and sensitive data.

2

Design

Agree sponsors, access templates, MFA and review points.

3

Configure

Set up accounts, groups, workspaces and suitable device rules.

4

Pilot

Test employee, volunteer and trustee journeys.

5

Support

Give coordinators and users a clear help route.

6

Review

Check inactive accounts, exceptions, costs and leavers.

Related services

Connect access to your wider nonprofit IT plan

Identity and permissions work best alongside device support, cybersecurity and continuity.

Staff and volunteer access FAQs

Frequently asked questions

Answers to common questions from charity leaders, coordinators and trustees.

Should every volunteer have an organisational account?

Not always. Base the decision on the work, information, duration and support needed. Anyone who does receive access should have a named, accountable identity.

Can volunteers share one login?

Shared logins make it hard to know who did what and to remove one person’s access. Named accounts are usually the better approach, with permissions matched to role.

How long should volunteer access last?

Set an expected end or review date when access is approved. Renew it when the role continues, and remove it promptly when the person leaves.

Who should approve access?

A named manager, programme lead or workspace owner should confirm the tasks and information required. IT can then apply the agreed access template.

Do trustees need different access from staff?

Often. Trustees may need board papers and meetings but not operational systems. Review confidential sharing and the use of personal devices.

Can a volunteer use a personal laptop or phone?

Yes, where policy and information risk allow it. Explain minimum device standards, support boundaries and how work information will be protected or removed.

Can we protect work apps without managing a whole personal phone?

Supported app-protection options can help separate organisational data from personal content. The available controls depend on the platform, apps and licences.

Does everyone need the same Microsoft 365 licence?

No. Features and licensing should follow the role. Check current nonprofit eligibility and provider terms before selecting plans.

What if someone cannot use a smartphone for MFA?

Agree an approved alternative authentication method and support process. Security should not depend on every user owning a compatible personal phone.

How should guests use Teams or SharePoint?

Give access only to the needed workspace, name an owner and review it regularly. The owner should remove access when the project or partnership ends.

What happens when a volunteer changes programme?

Review the old and new role together. Remove permissions no longer needed and grant the new ones through the usual approval route.

What should happen when a person leaves?

Disable access, recover organisational devices and numbers, review shared workspaces and decide how their work files and communications will be retained by the organisation.

How often should permissions be reviewed?

Frequency depends on information sensitivity and turnover. Temporary and external access generally need shorter review cycles than stable employee roles.

Can access rules protect donor and service-user information?

They help by limiting who can open and share it. Combine them with secure devices, authentication, awareness, monitoring and an incident response process.

How can trustees see whether access is controlled?

Provide a concise report on account numbers, overdue reviews, exceptions, leaver completion and the actions needed to reduce risk.

How much does staff and volunteer access management cost?

It depends on user numbers, licences, device choices, setup and ongoing review. A useful proposal separates initial work from recurring subscriptions and support.

Make access simple for people and accountable for the organisation

Tell us how staff, volunteers and trustees use your systems today. We’ll review accounts, devices, approval routes and information risk, then recommend a practical access process.

Book a nonprofit technology reviewExplore nonprofit IT support

Email hello@stratiis.com