Operations & Administration

Systems inventory, security controls, HR and personnel management.

Systems Inventory

This page lists the technology systems SHHA uses. For each system, we document what it does, who administers it, and how it is accessed.

Items marked TODO need information filled in by someone with direct knowledge of that system.

1. Microsoft 365

Microsoft 365 is SHHA's primary platform for email, mailing lists (Microsoft Groups), shared role mailboxes, and file storage (SharePoint).

TypeCloud-based (Microsoft-hosted)
Primary adminAnna (office staff) handles day-to-day membership changes; IT admin handles mailbox permissions and configuration
Backup adminTODO: Identify and document a backup administrator
Loginadmin.microsoft.com (admin), outlook.com (email), SharePoint links (files)
LicensingOnly office staff and IT admin need paid licenses; volunteers are free external guests

2. QuickBooks

Used for SHHA financial accounting.

TypeCloud-based
Primary admin / userTODO: Who is the primary user? (Treasurer? Office staff?)
BackupTODO: Is there a backup user with access?
LoginTODO: URL and login method
NotesTODO: Version (Online vs Desktop), billing, who pays for the subscription

3. Membership Database

TODO: Document the membership database system.

System nameTODO: What system/software is used?
TypeTODO: Cloud-based or local?
Primary adminTODO: Is Ryan the primary outside admin?
Backup adminTODO: Is there a backup?
Data storedTODO: What member data is in this system? (names, addresses, dues status, etc.)

4. Gusto

Used for payroll and employee benefits administration.

TypeCloud-based
Primary adminTODO: Who manages Gusto? (Office manager? Treasurer?)
BackupTODO: Is there a backup admin?
Loginapp.gusto.com
NotesTODO: How many employees are on payroll? Billing responsibility?

5. SHHA Website

The public-facing website at sandiahomeowners.org.

TypeTODO: What platform/CMS runs the website? (WordPress, Squarespace, custom?)
HostingTODO: Where is it hosted? Cloud-based?
Primary ownerTODO: Who manages content updates?
Backup ownerTODO: Is there a backup person?
Outside consultantTODO: Is there a web consultant? If so, who? How are they paid?
LoginTODO: Admin URL and login method

6. GRIT Newsletter

The GRIT is SHHA's community newsletter, currently produced monthly.

Production toolTODO: What software is used for layout? (InDesign, Canva, Google Docs, etc.)
Distribution methodTODO: Print, email, or both?
Editor / layout personTODO: Who currently does layout and editing?
Gmail accountshhagrit@gmail.com — TODO: document what this Gmail is used for (submissions? Google Drive access? legacy?)
Related pageSee the GRIT Layout Monthly Guide in the Specialty Topics chapter for the step-by-step production process

7. Square

Used for Sandia Tram ticket sales and advertising payments.

TypeCloud-based
Primary userTODO: Who manages Square transactions?
BackupTODO: Is there a backup?
Loginsquareup.com
NotesTODO: What specific transactions go through Square? Revenue amounts?

8. Other Systems

TODO: Are there additional systems not listed above? Examples might include:

Controls & Security

This page documents access controls, cybersecurity practices, and data backup procedures for SHHA systems.

Items marked TODO need information filled in. These questions originated from Andrea's controls review.

Access Controls — Who Has Access to What?

Microsoft 365 Admin Access

Global AdministratorTODO: Who currently has Global Admin access? (There should be a primary and a backup.)
User / Group managementAnna (office staff) manages day-to-day membership. IT admin handles mailbox permissions.
Who manages access?TODO: Is there a documented process for granting/revoking admin access? Who approves changes?

Other System Access

SystemPrimary AccessBackup Access
QuickBooksTODOTODO
Membership DatabaseTODOTODO
Gusto (Payroll)TODOTODO
SHHA Website (admin)TODOTODO
SquareTODOTODO
Domain registrarTODOTODO
Google accountsTODOTODO

Cybersecurity

Current Practices

Data Access

Data Backup

Cloud-Based Systems

Most SHHA data resides in cloud services. Each provider has its own backup/redundancy:

SystemBackup Approach
Microsoft 365 (email, SharePoint)Microsoft provides built-in redundancy and retention policies. TODO: Do we have a separate backup solution (e.g., third-party M365 backup)? What are our retention policy settings?
QuickBooks OnlineIntuit maintains backups. TODO: Do we also export periodic backups locally?
GustoGusto maintains payroll records. TODO: Do we keep local copies of payroll reports?
SHHA WebsiteTODO: Who backs up the website? How often? Where are backups stored?
Membership DatabaseTODO: How is the membership database backed up?

Local Data

Other Security Considerations

HR & Personnel Management

This page covers staff management, outside consultants, and volunteer administration. Much of this is non-IT operational information.

Items marked TODO need information from someone with direct knowledge (e.g., Jim Stewart, current President, or office manager).

Staff Management

Current Staff

TODO: List current office staff positions and names (e.g., Office Manager, Administrative Assistant).

Evaluation & Compensation

Who gives yearly evaluations?TODO: (President? Executive Committee? Office manager for junior staff?)
Who sets salaries?TODO: (Board approval required? Budget process?)
Where are salary and benefits records?TODO: (Gusto? QuickBooks? Paper files?)

Hiring

Who hires new staff?TODO: (President? Executive Committee? Board vote?)
What is the hiring process?TODO: (Job posting, interviews, background check, Board approval?)

Work Priorities & Training

Who assigns work priorities?TODO: (President? Office manager self-directs?)
Who trains new staff?TODO: (Outgoing staff? Office manager? Written procedures?)
President's specific roleTODO: Does the President have a defined role in day-to-day staff management, or is it delegated?

Outside Consultants

TODO: Document each outside consultant or contracted service provider.

Firm / attorney nameTODO
CompensationTODO: Hourly, per project, or retainer?
Who oversees / approves work?TODO: (President? Board?)
Who manages expenditure rate?TODO

Web Consultant

Consultant name / firmTODO
CompensationTODO: Hourly, per project, or retainer?
Who oversees / approves work?TODO
Scope of workTODO: Website maintenance? Design? Both?

Other Consultants

TODO: Are there other outside consultants (accounting/audit, landscaping, etc.)? List them here.

Volunteer Management

Adding Volunteers to Committees

Who appoints committee members?TODO: President? Committee chair? Both? (Refer to SHHA Bylaws for the formal process.)
ProcessTODO: Document the step-by-step process for adding a new volunteer (nomination → approval → IT setup)
IT setup when addingCommittee chair notifies office staff → staff sends Microsoft invitation → volunteer accepts → staff adds to mailing list. See the Quick Start for New Volunteers page.

Removing Volunteers from Committees

ProcessTODO: Who initiates removal? (Chair? Volunteer self-removal? Board?)
IT cleanupOffice staff removes from mailing list; IT removes SharePoint and mailbox access if applicable.

Replacing a Committee Chair

ProcessTODO: (Refer to Bylaws — link needed.) Who nominates the new chair? Board approval required?
IT transitionShared role mailbox access is transferred (revoke outgoing, grant incoming). See the FAQ section on email transitions.

Insurance

E&O (Errors & Omissions) insuranceTODO: Do we have E&O coverage? What does it cover? Policy details?
General liability insuranceTODO: Coverage details? Does it extend to volunteers?
D&O (Directors & Officers)TODO: Do we have D&O insurance?
Cyber liabilityTODO: Do we have cyber liability coverage?
Insurance broker / carrierTODO: Company name and contact