Practical guide

Review nonprofit account access before a staff handover

Last materially reviewed 2026-09-30

Quick answerMatch access to the incoming person’s actual task, preserve continuity and route changes through an authorized administrator.
What to know

List tasks before requesting permissions

Start with the work the incoming person must perform: read a report, handle a donor request, change a setting or administer users. 4aGoodCause documents Admin and Read-only roles, with materially different abilities. Do not choose the broadest role simply because it avoids a handover question. This guide prepares an access review; it does not authorize access changes or decide an employee’s status. Keep the organization’s own approval process and use its trusted source for the person’s identity and responsibilities.

What to know

Review the whole workflow, not one login

Our original handover inventory separates platform access, gateway access, approved file storage and the route for requesting help. Access to one does not establish access to the others. Record the responsible owner for each without placing passwords or recovery codes in the checklist. An incoming colleague may be able to read gift history but still lack authority to change an instruction. Make that gap explicit rather than handing over a shared account or asking the departing person to forward a secret in ordinary email.

What to know

Plan the transition and the removal

NCSC guidance supports managing joiners, role changes and leavers, and reviewing access that is no longer needed. Agree the transition with the authorized administrator so that necessary ownership and open cases are not lost. 4aGoodCause’s user-removal help requires Admin access. Do not delete a user merely because this guide says a review is due. The appropriate organization owner must determine what to retain, transfer or remove and verify the result through the approved account process.

What to know

Accept access by the intended task

A successful login is only one check. The incoming owner should confirm the permitted task in a safe, approved way without making an unnecessary payment or data change. Record which task was observed, what was not checked and who handles exceptions. For example, a fictional reviewer can view reports but cannot administer settings; that may be the correct outcome, not an error. Keep a named backup and a current support route, then revisit the review when responsibilities change. Use staff handover for the wider unfinished-work record.

Continue when useful

Next: Staff handover

Hand over responsibilities, authorized access and unresolved cases—not shared passwords or an unexplained export.

Open Staff handover →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. 4aGoodCause staff roles — Merchant documentation · help.4agoodcause.com · Merchant-controlled · checked 2026-09-30
  2. 4aGoodCause: Removing a nonprofit user — Merchant documentation · help.4agoodcause.com · Merchant-controlled · checked 2026-09-30
  3. NCSC: using SaaS securely — Research study · ncsc.gov.uk · Publisher independence not verified · checked 2026-09-30