01 · The challenge
Growth had turned flexible tools into critical infrastructure.
Airtable had grown from a flexible database into a core operational platform. It held member information, supported service delivery and powered numerous automated processes.
Some volunteers needed to retrieve information about individual members, but direct access to Airtable would expose significantly more data than their role required. It would also increase the number of database users the organisation needed to manage and make access removal harder to control.
The organisation also lacked a dependable backup outside Airtable. Occasional spreadsheet exports were not sufficient because a credible recovery process needed to preserve records, relationships and database schemas - not simply the visible contents of individual tables.
Behind both requirements sat a wider identity problem. Staff, consultants and volunteers accessed cloud services from a mixture of organisational and personal devices. The charity needed stronger authentication, clearer access boundaries and a practical route towards Cyber Essentials without attempting an unrealistic enterprise transformation overnight.
The central challenge was not choosing another platform. It was understanding who needed access, what information they genuinely needed and how the organisation could continue operating if one of its core services became unavailable.
02 · The analysis
Access, resilience and identity were parts of the same operating model.
We began by mapping the organisation’s systems, identities, information flows and operational dependencies.
This separated the controls that could be delivered immediately from the wider decisions that required organisational ownership. It also showed that the volunteer-access and backup requirements were not standalone development projects.
Both depended on broader questions:
- Who should have an organisational identity?
- What information does each role genuinely need?
- How should access be approved, logged and removed?
- Which devices can be trusted?
- What would happen if a critical SaaS platform became unavailable?
- Which responsibilities belonged to technology, management or governance?
This provided an architecture against which individual technical decisions could be assessed, rather than addressing each request independently.
03 · What we delivered
Practical controls that reduced exposure without obstructing service delivery.
Controlled volunteer access
We designed and built a record-retrieval workflow that allows an authorised volunteer to access the information required for a specific task without using a paid Airtable seat or having visibility of the wider database.
The volunteer submits a small set of identifying details, including their own email address and information about the member they are supporting. The system validates the request, identifies the matching record and issues time-limited access to the permitted information.
The workflow provides:
- Access limited to an individual matching record
- Time-limited tokens that expire automatically
- Logging of access requests
- Validation of the volunteer’s identity
- Information constrained to the stated operational purpose
- No direct volunteer access to the underlying Airtable base
This replaced a choice between excessive database access and volunteers recording sensitive information elsewhere for later use.
Independent backup and recovery
We also built an automated cloud backup system for the organisation’s Airtable estate.
The system:
- Exports schemas and records from every accessible base
- Handles API pagination across large tables
- Creates timestamped archives and export manifests
- Records table counts, record counts and API activity
- Generates checksums to verify archive integrity
- Encrypts backups before storage
- Stores credentials and encryption material in managed secret services
- Runs as a scheduled cloud job
- Separates the identity triggering the process from the runtime identity
- Reports failures without generating unnecessary routine notifications
The resulting backup is independent of Airtable and preserves enough structural information to support a credible recovery process rather than simply producing a collection of spreadsheets.
Security and identity roadmap
Alongside the delivered controls, we produced a staged roadmap covering:
- Multifactor authentication
- Individual staff and volunteer identities
- Administrative access
- Device management
- Joiner, mover and leaver processes
- Role-based information access
- Removal of unnecessary permissions
- Cyber Essentials preparation
The roadmap allowed immediate risks to be reduced while giving the organisation time to make proportionate decisions about licensing, managed devices and volunteer access.
04 · The outcome
Safer access now, with a clearer route to stronger operations.
Volunteers can now retrieve the information required for their role without being given access to the organisation’s underlying database or the records of other members.
The charity’s Airtable data is backed up independently through an automated, encrypted and verifiable process that preserves both records and database structure.
The organisation has also moved beyond treating security as a collection of unrelated settings. It now has a clearer model for deciding:
- Who receives an organisational identity
- Which devices and sessions can be trusted
- What information each role should be able to access
- How access should be recorded and reviewed
- How permissions are removed when responsibilities change
- How critical operational information can be recovered
The wider identity and device transformation remains a staged programme. The difference is that future decisions can now be made against a coherent architecture instead of emerging independently in response to each new technical problem.
Services demonstrated
Digital operations consultancy · Airtable architecture and automation · Secure access workflows · Cloud backup and recovery · Cyber-security review · Identity and device strategy
Explore planned operational change