Keep all of it.
handled.
minutes.
fundraiser.

Why FutureFund Discourages Shared and Positional Email Accounts

Most PTAs have them: president@mygreatpta.org, treasurer@, secretary@. They feel tidy. Yet, they are also one of the weakest links in a volunteer organization's security posture, and at FutureFund we strongly discourage using them to access our administration portal.
Start with security. A shared account is, by definition, an account nobody owns. Because more than one person needs to get in, two factor authentication and passkeys almost never get enabled: the second factor has to live on somebody's phone, and no one wants to be the bottleneck. So the strongest protection available is quietly switched off. The password that remains is usually the organization's name with a few numbers sprinkled in. That is not a password, it is a hint.
Then there is turnover, which is the part people underestimate. Most PTA leadership positions typically turn over every two years, and in many units it happens more often than that. The outgoing president and the incoming president usually share the account for months, sometimes six or more, while things get handed off. During that window the old password is not rotated, and two or three people have simultaneous access. If we later need to audit who changed a bank account, who issued a refund, who edited a store item, we cannot answer with certainty. Every action is attributed to a mailbox, not a person. Accountability is the whole point of an audit trail, and a shared account destroys it by design.
There is also no reason to do this on our platform. We have never charged based on the number of seats or users with access to the administration portal, and we never will. The usual justification for account sharing, which is licensing cost, simply does not apply here. Every volunteer who needs access can have their own login at no cost.
The operational drag is real too. A large share of our support volume is people trying to change the name on a shared account, change the email on it, change the phone number on it, and untangle everything that follows. Phone numbers are the worst case. Someone adds a personal number to president@, moves on a year later, and our text messages keep going to the wrong phone. That is a security problem and a deliverability problem at the same time. All of this work exists only to maintain a fiction: that a role is a person.
None of this means positional addresses have to disappear. If you want the community to be able to reach whoever currently holds the office, use an email alias. president@mygreatpta.org forwards to the individual serving as president, and when the office changes you update one forwarding rule. If you want a durable record of everything sent to that address, create a Google Group instead. The group holds the archive, membership is managed explicitly, and mail fans out to the current officers. Both approaches give you the continuity you wanted without giving anyone a shared password.
So the recommendation is straightforward. Every person who administers a FutureFund account should sign in with an individual account they own and control, secured with their own second factor. It can be a personal address. It can be an address on the PTA's domain. It should never be an account that two people log into.
Individual accounts are safer, because they support real authentication. They are more accountable, because every action has a name attached. They are more efficient, because handoff becomes adding and removing a user rather than resetting a password and chasing down a phone number. And they are easier for everyone, because nobody has to remember what the shared password was changed to last spring. We strongly recommend them.
Darian Shimy is the founder and CEO of FutureFund Technology, a fundraising and selling platform for K-12 school groups. He has 25+ years in web-based technologies, managing engineering teams, and building products.


