Guides

Guide · How-to

Role handover: handing over accounts cleanly.

Whether it’s the board, the treasurer or the secretary: volunteers change, the task stays. The digital handover is the part no one thinks of, until the departing person is still sitting in the mailbox months later and the new one cannot get in. Here is how to do it properly.

Why it gets stuck

Roles change in an orderly way. Accounts often don’t.

For a change of office there are statutes, an election, minutes. For the accounts that half the association’s work now hangs on, usually nothing. The password to the association mailbox sits in the private inbox of an active member, the cloud runs through an account someone set up years ago, and no one knows exactly any more who can access what.

This is rarely bad intent. It is disorder that builds up over the years. It only shows when someone leaves: the new person cannot get to the old emails, the old one still has access to member data for weeks, and at the change after next the same searching starts all over.

The way out is not stricter discipline but a different foundation: data belongs to the task, not to the person. Then the handover is not a project but a change of access.

The principle

Tasks get accounts. People get access.

The trick is to separate data and person: what belongs to a task sits in a role account, not in a person’s private mailbox.

A role account is a mailbox, a calendar or a file store that belongs to a task, not to a person, such as kasse@ihr-verein.de or the shared store of the membership administration. In OX there are such role accounts for email, calendar and contacts, in OpenCloud for files and shared folders.

Volunteers keep their own, personal account and through it get access to the role accounts of their task. They write from the role mailbox and look after the shared files, but the data belongs to the role account, not to them.

When the person changes, you take away their access and give it to the successor. The role account and everything in it stays. The new person signs in with their own account and picks up where the last one left off, without any password being passed along.

So that the successor does not start from scratch, an internal wiki and training are part of it: they set out how the task runs, and new volunteers get up to speed at their own pace before the first real task is needed.

Before / after

What causes it. And what changes.

On the left, what a handover looks like when everything hangs on a person’s private account. On the right, when the data sits in role accounts and people only get access to it.

Everything on the person

Why it’s a chore.

  • Passwords lie scatteredIn someone’s head, on a note, in the private mailbox of the departing person. At the change the whole group joins the search.
  • Every service is handed over one by oneEmail, cloud, chat, membership administration, each with its own login. Whatever gets missed stays open.
  • The data hangs on the personIf everything runs through a volunteer’s private account, it leaves with them when they go. The successor starts from scratch, and the old account stays open all the same.
  • No traceLater there is no telling who received or lost which account and when, not even when someone asks.

A role account per task

Why it’s then a single move.

  • A personal account, plus role accountsEvery volunteer has their own login and through it access to the task’s role accounts. If you know the person, you know their accounts.
  • The data hangs on the role accountThe mailbox, calendar and files of a task belong to the role account, not to the person. What sits there stays where it is at the change.
  • A handover is a change of accessThe successor is given access to the same role accounts, and the departing person is taken off them. They pick up where the last one left off.
  • TraceableWho gained or lost access and when is logged, in every account. For the next change and for the data-protection question.

The five steps

The handover, step by step.

This is how the handover runs when the data hangs on role accounts, whether you do it yourself in the administration or ask us to.

  1. Take stock

    Which role accounts belong to the task? The role mailbox, the shared file store, rights in the membership administration. Because they hang on the task and not on the person, they are in one place, instead of being gathered from four systems.

  2. Create the successor

    The new person gets their own, personal account. Through it they receive access to exactly the role accounts that belong to the task, no more and no less. How rights move through an organisation.

  3. Hand over access

    The successor is given access to the role accounts, and the departing person is taken off them. A role mailbox like kasse@ihr-verein.de and the task’s files stay unchanged; only who operates them changes. The new person picks up where the last one left off.

  4. Close the old account

    As soon as the handover is in place, the departing person’s personal account is deactivated, in one place, for all services at once. Access to the role accounts ends with the task, not at some later point. The role accounts themselves remain.

  5. Record the handover

    What was switched on and what was switched off is logged. This helps at the next change and answers the data protection officer’s question of who had access and when. The technical framework for it is on the security page.

How a first move of your existing mailboxes and files works is covered separately on the Switching over page.

Common questions

What associations ask before the change.

Seven answers on role accounts, access and data protection, short and without sales prose.

What is a role account?

A role account belongs to a task, not to a person, such as kasse@ihr-verein.de or the shared store of the membership administration. In OX this exists for email, calendar and contacts, in OpenCloud for files and shared folders. Volunteers get access to it through their personal account and work with it, but the data stays with the role account.

What happens to the data of the person who has left?

Everything that belongs to the task sits in the role account and stays there: the mailbox, the appointments, the files. The successor is given access and finds it all in place. Purely personal data in someone’s own account can, if wished, be archived or forwarded for a while. What happens to it is your decision, not ours.

Does the person who has left really have no access afterwards?

Their personal account is deactivated in one place, and with it access to all role accounts, not service by service, where one is easily missed. The role accounts themselves remain and stay open to the successor.

Does the whole group have to change at once?

No. The handover happens person by person. If only the treasurer changes, only access to their role accounts is handed over, and the other tasks stay untouched.

How does the successor find their way?

Because the data sits with the role account, the new person picks up where the last one left off. Part of this are an internal wiki and training: they set out how the task runs, and new volunteers get up to speed at their own pace before the first real task is needed.

Who is actually allowed to carry out the handover?

The administration appointed for it in the association, or, in an organisation with several levels, the level above. Admin rights can be delegated: a district branch can let its local branches manage themselves, without handing them the keys to the whole federation. More on this on the page for federations and organisations.

Is handing over accounts a data protection matter?

Yes. Anyone who manages member, counselling or donation data should end access when the task ends; an open old account is an avoidable risk. The logging in the account helps you, if in doubt, to prove who had access and when. It is no substitute for legal advice, but it makes the duty of proof manageable.

Who writes here

We’ve supported many handovers. Orderly and chaotic.

This guide comes from czichos.net GmbH in Berlin, the team behind Connecteeva. For many years we have looked after the IT of Germany’s largest social federation, with constant changes at every level, from the national level down to the local branch.

More about us is on our About page.

A change coming up? We’ll set you up with a trial.

Try the handover on a no-obligation trial before you switch over. Write us a few lines about how your roles are shared out, and you will get an honest assessment of what an orderly handover would look like for you.

We set up a trial and usually send the login details to your contact email within one working day.

No contract and no payment details. You decide whether it stays an enquiry or you try Connecteeva right away.

Prefer to reach us directly? Send an email · call 030 994048000

Address czichos.net GmbH
Königsweg 220
14129 Berlin