Skip to content

Nonprofit service operations guide

Guide 3: Protect administrator and access continuity

Keep control of critical systems through staffing, contractor, and leadership changes.

Find single-person dependencies

Inventory who controls tenant ownership, billing, domains, integrations, backups, exports, identity providers, recovery methods, vendor portals, and elevated roles. Mark any area that depends on one person's account or memory.

Confirm that the nonprofit, not an employee or provider, owns the enduring accounts and recovery paths wherever the service permits it.

Create a usable continuity record

Document recurring duties, approval paths, safe recovery steps, audit locations, vendor contacts, renewal dates, known limitations, and the first actions during an outage or staff departure.

Store credentials and secrets in approved protected systems. The runbook should explain where and how authorized people gain access, not contain the secret itself.

Practice the handoff

Have a backup administrator perform a representative task, locate evidence, contact support, and explain the recovery path. Correct the runbook while the primary administrator is available.

Use joiner, mover, leaver, contractor-end, and emergency-access reviews to keep permissions aligned with current work and approved purpose.