Church Defense · General guidance for leadership discussion
Name an Owner for the Transition
People changes can affect email, giving tools, social accounts, shared drives, child check-in, and website administration. A single checklist and named owner help keep those systems from being overlooked.
The checklist should cover employees, privileged volunteers, and vendors, with timing approved by the appropriate church leader.
Review Shared and Inherited Access
Removing one account may not remove access through shared logins, groups, delegated permissions, or recovery contacts. Ask your technical owner to review the actual access paths.
Preserve church-owned information appropriately and transfer ownership before removing the departing person’s account. Avoid deleting records or disabling essential processes without a plan.
Confirm the Result
Record what was removed, who verified it, and any exception leadership accepted. Recheck privileged roles and account recovery arrangements.
A documented exception needs an owner and a review date; it should not quietly become permanent.
Further reading: NIST small business cybersecurity guide.
Apply these questions with the people responsible for your systems. An assessment can help turn them into a prioritized plan for your church.