Private internal working artifact Last updated: July 24, 2026

Pinnacle Pathways / Volunteer fractional CTO assessment

Miami Valley Meals Security Assessment Control Board

A source-controlled working view for steering discovery, research, decisions, and the on-site visit. It summarizes reviewed evidence only; it is not a raw transcript, system inventory, or client-facing report.

Current operating view

Assessment status

The work is in discovery. Candidate risks remain questions until the on-site visit confirms the relevant people, process, system, and control.

Current phaseKickoff complete
Next gateOn-site visit scheduling
Lean scope8-12 donated hours
Production controlSource repo -> Quantum Web

End-to-end engagement

Strategic path forward

01

Scope and source control

Confirm volunteer boundary, no-change rule, confidentiality, and the Lean deliverable shape.

Complete
02

Kickoff and preparation

Reconcile meeting evidence, prepare research, and turn the on-site visit into a focused observation plan.

Current
03

On-site discovery

Trace real account, device, financial, documentation, and network handoffs while MVM staff operate their systems.

Next gate
04

Assessment synthesis

Separate confirmed facts, candidate risks, recommendations, owner decisions, and excluded follow-on work.

Planned
05

Lean handoff

Deliver a current-state summary, prioritized findings, and a 30-day quick-win plan.

Planned

Evidence discipline

What the meeting established

Transcript-backed context informs the questions. It does not substitute for on-site confirmation.

AreaCurrent evidenceAssessment stanceOn-site proof needed
Google Workspace and recoveryContext

Administration appears concentrated in one operational role, with limited shared recovery knowledge.

Candidate

Key-person and account-recovery dependency.

Admin ownership, recovery methods, multi-factor authentication, Drive sharing, and local sync.
Devices and Microsoft accountsContext

Mixed Macs and PCs, employee-managed devices, and past shared-account setup were discussed.

Candidate

Accountability, data-boundary, and continuity gap.

Device ownership, profiles, encryption, updates, screen lock, local data, and individual-account transition.
Financial change controlsContext

Donor and accounting systems are reconciled through reports; ACH and vendor-impersonation risk was discussed.

Candidate

Manual reconciliation alone is not a security defect.

Payment-change request, verification, approval, recordkeeping, and escalation workflow.
Continuity and knowledgeContext

MVM is documenting processes and planning for growth, facility change, and eventual staff transitions.

Candidate

Knowledge and recovery may be concentrated in people.

Critical process list, document owners, account recovery, onboarding, and offboarding practice.
Network separationContext

Separate staff and guest Wi-Fi was reported as an existing improvement.

Validate

Positive baseline pending confirmation.

Network ownership, staff/guest separation, access model, and future-facility requirements.

Execution queue

Immediate action items

Keep the queue thin. Schedule the visit, prepare the evidence questions, then observe before deciding on tools or changes.

  1. KalenReview DonorPerfect security and administrative guidance relevant to MVM's use.Before visit
  2. KalenPrepare Google Workspace questions for administrator ownership, recovery, sharing, and local sync.Before visit
  3. KalenPrepare a vendor-neutral minimum baseline for Macs and PCs, without selecting a product yet.Before visit
  4. Taylor / MVMProvide options for a one- to two-hour on-site visit.Awaiting reply
  5. MVM leadershipAfter workflow review, decide whether to adopt an independent phone-verification rule for sensitive financial changes.After visit
  6. Kalen + MVMConfirm which optional follow-on items fit the donated scope: checklists, a policy draft, partner education, or board memo.After findings

Preparation backlog

Research and decision packages

Identity and recovery package

Map organization ownership, individual administrators, recovery routes, multi-factor authentication, and the access review cadence that a small nonprofit can realistically maintain.

Endpoint baseline package

Develop options from minimum personal-device controls to a future managed baseline. Use decision criteria: effort, cost, Mac/PC support, encryption, updates, data access, and offboarding.

Financial-change control package

Draft a simple phone-verification and escalation flow. It becomes a recommendation only after the real workflow and accountable owner are confirmed.

Continuity package

Identify the few processes that must survive an absence: system ownership, account recovery, vendor access, onboarding, offboarding, and facility-move dependencies.

Potential pathways

Path A: minimum viable baseline

Prioritize account ownership, multi-factor authentication, encryption, individual profiles, update expectations, and the financial-change verification process. This is the likely Lean recommendation path.

Path B: documented operating baseline

Add concise onboarding, offboarding, laptop, and account-recovery checklists after the current state is understood. Use when MVM has an owner for routine upkeep.

Path C: broader partner resilience

Turn the payment-fraud and phishing discussion into a short partner communication or annual meeting segment. Keep this separate unless MVM explicitly expands the engagement.

Operational context

High-level value stream to observe

Technology controls should support the service flow, not become a detached checklist.

Food donorsOffer surplus or donated food
IntakeAccept and handle inputs
Production planChefs select meals and batches
PrepareCook, portion, package
StageFreeze and make ready
Partner pickupSchedule and fulfill
DistributionPartners serve people and families
Learning loopFeedback, impact, funding, and capacity

Control boundaries

How this board stays useful and safe

Evidence and confidentiality
  • Repo source material is the durable operating record.
  • Notion retains the raw meeting transcript and meeting source context.
  • Quantum Web hosts a sanitized internal projection only.
  • Candidate findings remain questions until confirmed by MVM.
Update contract
  • Edit this source file in the MVM project workspace.
  • Validate locally before publication.
  • Use exact-slug upsert after the initial Quantum Web creation.
  • Record the source and hosted SHA-256 in each release receipt.