Your donor CRM holds the relationships that keep your nonprofit funded. It tracks gifts, pledges, communication history, and often personal notes about major donors. Both the choice of system and its setup matter, because a poor fit or a weak configuration can cost you data and trust.
This guide covers both parts: picking a system that fits how your team works, and configuring it so donor information stays protected.
Define donor CRM requirements before demos
Demos make every system look easy. So write down what you actually need before you talk to vendors.
Start with daily tasks. For example, list how you enter gifts, send acknowledgments, manage recurring donors, and track grants. Next, add reporting needs for the board and auditors.
Finally, note which systems the new platform must connect with, such as your payment processor, email marketing tool, event platform, and accounting software. Also involve the people who will use it every day, because a development associate often spots gaps that a director misses.
Ask vendors hard security questions
A cloud platform shifts some security work to the vendor, but you still own the risk to your donors. Therefore, ask each finalist the same questions and compare the answers.
- Does the system support MFA and single sign-on with Microsoft 365 or Google?
- Can you set role-based permissions down to specific fields or records?
- Does the vendor provide an independent security report, such as a SOC 2 report?
- How does the vendor encrypt data in transit and at rest?
- What backups does the vendor keep, and how would you restore deleted records?
- Does the system keep an audit log of logins, exports, and changes?
- Can you export all your data in a usable format if you leave?
- How will the vendor notify you of a security incident?
Then ask for references from organizations similar in size and mission. Also, ask how the vendor handles support requests and outages.
Clean your data before migration
Moving to a new donor CRM gives you the best chance to fix old data problems. Duplicate records, outdated addresses, and inconsistent codes all slow staff down.
First, merge duplicates and standardize gift and campaign codes. Then decide how much history to move. Also, delete data you no longer need, such as old card details or sensitive notes with no business purpose, because less data means less exposure.
In addition, test the migration with a sample before moving everything. Check that gift totals, donor counts, and recurring gift schedules match the old system.
Set permissions by role
Not everyone needs to see everything. For instance, event volunteers may need to check in guests but not view giving history. Similarly, a gift processor may need to enter donations but not export the full database.
Build roles around job tasks, and review membership every quarter. In addition, limit export rights to a few trusted people. Bulk exports to spreadsheets often end up in personal email or on unmanaged laptops.
Also, avoid shared logins. Each person needs a named account, so the audit log shows who did what.
Secure integrations and connected apps
Modern fundraising platforms connect to many other tools. Each connection uses an account or token that can reach donor data.
So keep an inventory of integrations, and remove any you no longer use. Also, tie integrations to a dedicated service account instead of a staff member’s login. That way, connections do not break, or stay open, when someone leaves.
Finally, review what each connected app can read or change. Many integrations ask for broad access by default, even when they need only a small part of the data.
Plan for staff changes and daily hygiene
Development teams often see turnover, and each departure leaves an account behind. Therefore, remove access on a person’s last day, and transfer their saved reports and lists.
Meanwhile, review login and export logs each month for unusual activity. A sudden large export late at night deserves a quick question.
Also, keep a written list of who owns each role and report, so nothing gets lost when people move on.
How WEBIT helps
WEBIT helps nonprofits evaluate donor CRM options against security and integration needs, then plan a clean migration. We can connect the platform to Microsoft 365 single sign-on and roll out MFA, so every login gets stronger protection.
We also protect the devices staff use to reach donor data with Security Essentials. Learn more about our strategic IT services or our workflow automation options for gift processing.
Key takeaways
- Write down real daily tasks and integrations before you watch demos.
- Ask every vendor the same security questions, including MFA, audit logs, and data export.
- Clean and trim data during migration to reduce exposure.
- Role-based permissions and limited export rights protect a donor CRM from misuse.
- Service accounts and prompt offboarding keep integrations and logins under control.