Scope and source control
Confirm volunteer boundary, no-change rule, confidentiality, and the Lean deliverable shape.
CompletePinnacle Pathways / Volunteer fractional CTO assessment
A source-controlled working view for steering discovery, research, decisions, and the on-site visit. It summarizes reviewed evidence only; it is not a raw transcript, system inventory, or client-facing report.
Current operating view
The work is in discovery. Candidate risks remain questions until the on-site visit confirms the relevant people, process, system, and control.
End-to-end engagement
Confirm volunteer boundary, no-change rule, confidentiality, and the Lean deliverable shape.
CompleteReconcile meeting evidence, prepare research, and turn the on-site visit into a focused observation plan.
CurrentTrace real account, device, financial, documentation, and network handoffs while MVM staff operate their systems.
Next gateSeparate confirmed facts, candidate risks, recommendations, owner decisions, and excluded follow-on work.
PlannedDeliver a current-state summary, prioritized findings, and a 30-day quick-win plan.
PlannedEvidence discipline
Transcript-backed context informs the questions. It does not substitute for on-site confirmation.
| Area | Current evidence | Assessment stance | On-site proof needed |
|---|---|---|---|
| Google Workspace and recovery | Context Administration appears concentrated in one operational role, with limited shared recovery knowledge. | Candidate Key-person and account-recovery dependency. | Admin ownership, recovery methods, multi-factor authentication, Drive sharing, and local sync. |
| Devices and Microsoft accounts | Context Mixed Macs and PCs, employee-managed devices, and past shared-account setup were discussed. | Candidate Accountability, data-boundary, and continuity gap. | Device ownership, profiles, encryption, updates, screen lock, local data, and individual-account transition. |
| Financial change controls | Context Donor and accounting systems are reconciled through reports; ACH and vendor-impersonation risk was discussed. | Candidate Manual reconciliation alone is not a security defect. | Payment-change request, verification, approval, recordkeeping, and escalation workflow. |
| Continuity and knowledge | Context MVM is documenting processes and planning for growth, facility change, and eventual staff transitions. | Candidate Knowledge and recovery may be concentrated in people. | Critical process list, document owners, account recovery, onboarding, and offboarding practice. |
| Network separation | Context Separate staff and guest Wi-Fi was reported as an existing improvement. | Validate Positive baseline pending confirmation. | Network ownership, staff/guest separation, access model, and future-facility requirements. |
Execution queue
Keep the queue thin. Schedule the visit, prepare the evidence questions, then observe before deciding on tools or changes.
Preparation backlog
Map organization ownership, individual administrators, recovery routes, multi-factor authentication, and the access review cadence that a small nonprofit can realistically maintain.
Develop options from minimum personal-device controls to a future managed baseline. Use decision criteria: effort, cost, Mac/PC support, encryption, updates, data access, and offboarding.
Draft a simple phone-verification and escalation flow. It becomes a recommendation only after the real workflow and accountable owner are confirmed.
Identify the few processes that must survive an absence: system ownership, account recovery, vendor access, onboarding, offboarding, and facility-move dependencies.
Prioritize account ownership, multi-factor authentication, encryption, individual profiles, update expectations, and the financial-change verification process. This is the likely Lean recommendation path.
Add concise onboarding, offboarding, laptop, and account-recovery checklists after the current state is understood. Use when MVM has an owner for routine upkeep.
Turn the payment-fraud and phishing discussion into a short partner communication or annual meeting segment. Keep this separate unless MVM explicitly expands the engagement.
Operational context
Technology controls should support the service flow, not become a detached checklist.
Control boundaries