play icon for videos
← Academy
SOPACT ACADEMY · CONNECTED DATA INTELLIGENCE · PROVE

AI Data Access Controls: What Your Assistant May See

Define who can access which records, test retrieval and sharing, and keep a useful AI workflow within clear boundaries. Includes a practical access-policy exercise.

Sopact Academy · Course review

Practical Academy guide

AI Data Access Controls: What Your Assistant May See

How do you control what an AI assistant can access?

Define the purpose, authorize the user and limit the data the application retrieves before it reaches the model. Then check the answer, citations, exports and shared reports against the same intended audience. A prompt can guide behavior, but it should not be the only barrier protecting information someone is not allowed to see.

Use this reference within your governance module when an assistant will work with survey responses, notes, documents or reports. Create a small access policy and test it with fictional records. Keep the policy with your course plan as roles, purposes and permissions change.

These are evaluation practices, not a claim that every control below is a built-in Sopact feature. Confirm the behavior of your configured system, connected services and reporting tools. Your organization's privacy and security owners should resolve requirements that depend on jurisdiction, contracts or the sensitivity of the work.

Start with the task, not a blanket permission

A case worker preparing for a conversation may need identifiable details for an assigned person. A program analyst comparing cohorts may need linked observations without contact details. A board member may need a reviewed aggregate report. “Can use AI” is not a sufficient access rule for all three tasks.

Write a sentence for each use: who needs which information, for what decision, within which population and period. Include documents, transcripts and comments, not just form fields. A redacted spreadsheet does little if an attached file still exposes the same details.

Data access, permission to quote and permission to publish are different questions. Someone may be entitled to review a case note internally without permission to reproduce it in a public story. Keep the intended audience attached to the output as well as the source.

If a survey was designed to be anonymous, do not add identifiers or infer identities merely to support a connected-record workflow. Use an aggregate analysis appropriate to that collection promise. Longitudinal linkage is useful where it is intended and appropriately governed.

Separate instructions from enforced access

An instruction such as “do not reveal names” can help shape a response. An access check determines whether a user or service is allowed to retrieve a record or field at all. These serve different purposes and should be evaluated separately.

OWASP's system-prompt guidance recommends enforcing authorization independently of the language model. A model's apparent compliance in one conversation does not prove that the underlying permissions are correct.

Ask what is actually sent to the model: the entire folder, selected records or an authorized extract. Check which identity the connector uses. A broadly privileged service account can expose more than the person asking the question should receive if the application does not enforce the user's scope.

Removing unnecessary data reduces exposure, but it is not the only control. Authentication, authorization, limited retrieval, safe output handling, monitoring and appropriate sharing controls work together. None should be described as a guarantee against every possible disclosure.

Build a small, explicit access policy

The following is a fictional policy for a training organization. It is an exercise to adapt, not a universal rule or a description of an existing customer's configuration.

Role and purposeAllowed viewExcluded from this viewOutput boundary
Assigned support worker preparing follow-upRelevant assigned records and approved notesOther caseloads and unrelated restricted filesInternal use within the assigned role
Analyst reviewing cohort progressAuthorized linked scores and reviewed comment extractsContact details and restricted personal narrativesReviewed analysis with disclosure checks
Board reader assessing program resultsApproved aggregate reportRaw responses, person-level exports and restricted citationsNamed or otherwise approved report audience
Public website visitorMaterial approved for public releaseUnderlying records and private report linksPublicly shareable content only

For each row, assign an owner and a review date. Record how access is granted, changed and removed. If a person holds two roles, test the actual session and task rather than assuming the more restrictive view will automatically win.

Classifying data helps, but categories can overlap. A location, rare role or distinctive event can identify someone without a name. Avoid a catch-all “open” category for anything not marked sensitive. Establish what is genuinely approved for the relevant audience.

Removing names does not make a record anonymous

A stable contact ID preserves a useful link over time. If the organization can connect that ID back to a person, it should not call the record anonymous merely because the name is absent. The ICO's anonymisation guidance distinguishes anonymous information from pseudonymous personal data.

Free text needs its own review. A comment about being the only night-shift parent at a small site may identify someone to a reader familiar with that site. Names, phone numbers and emails are only part of the problem.

Use purpose-appropriate extracts and keep the original under the appropriate access rules. If you generalize a detail or paraphrase a passage, preserve that transformation in the review record. Do not present an edited paraphrase as an exact quotation.

For internal analysis, identifiable information may sometimes be necessary and authorized. The decision is not “always remove all identity” or “give the model the whole record.” It is which information this task legitimately requires and how that access is enforced.

Check small groups, quotes and combined reports

A minimum group size can be one disclosure-control rule, but it is not a universal anonymity guarantee. A larger group can still contain a unique person, and two separately released tables may reveal more when combined.

Suppose a fictional site has six participants and only one person in a particular role. Hiding one cell may not help if totals or another breakdown allow the value to be derived. A quote can reveal the same person even when the numeric cell is hidden.

Review the report, underlying export, drill-down, citations and repeated queries as a connected release surface. Depending on the context, combine groups, omit detail, suppress related cells or choose another presentation. Have the privacy owner define the applicable rules.

Do not delete legitimate source evidence merely because it cannot be shared with a particular audience. Restrict that audience's access and produce an appropriate output. Authorized staff may still need the original for a valid operational purpose.

Record purpose and permissions precisely

A single “consent: yes” field rarely explains the full situation. Record what was agreed, for which purpose, when, under which notice or terms, and whether any use restrictions apply. Permission to contact someone is not automatically permission to publish their words.

Consent is not the only possible legal basis for processing personal information. The ICO's AI lawfulness guidance discusses assessing the purpose and appropriate basis for distinct uses. This is UK-specific guidance and is marked as under review; use current advice relevant to your organization rather than treating this lesson as a legal determination.

When a permission changes or a person makes a rights request, route it to the responsible owner. Determine which uses, copies and retention obligations are affected. Do not assume either that everything must vanish instantly or that updating a mailing-list field resolves every downstream use.

For the exercise below, the policy explicitly prohibits a withdrawn quote permission from being used in a new public report. That is a defined test condition. It does not imply that every withdrawal has the same effect on every lawful internal record.

Protect the report after the answer is generated

An internal answer and a public report have different audiences. Check whether a report link requires sign-in, whether access expires and whether the recipient can export or forward the content. A protected source does not make every generated copy protected automatically.

Review citation links as well as the prose. A short summary may be suitable for a board reader while its source link opens a restricted participant file. The reader should receive an appropriate evidence reference, not unintended access to the source.

Keep an owner, intended audience and review date for recurring reports. Revisit access when staff, partner roles or board membership change. Revoking a link can prevent future access to that link; it does not retrieve copies someone already downloaded.

Ask how corrections, deleted sources and changed permissions affect saved answers, search indexes, caches, logs and exports. The answer may differ across services. Document those boundaries instead of assuming a permission change propagates everywhere immediately.

Treat documents as evidence, not new authority

An uploaded document can contain text that looks like instructions to an AI system. In this workflow, its job is to provide evidence for analysis; it should not grant access to another folder or authorize an external action.

OWASP's prompt-injection guidance describes risks from instructions embedded in content supplied to a model. Use that distinction when testing transcripts, files and retrieved passages. A quote inside a document is not a permission change.

Start with read-only analysis where that meets the need. If an assistant can send messages, edit records or trigger another process, evaluate those permissions separately from its ability to read. Sensitive actions should have appropriate review and accountability.

Run a synthetic acceptance test before using real records

Create a small fictional dataset containing two caseloads, a restricted note, a distinctive small-group comment and a quote whose public-use permission has changed. You do not need to expose real participant information to test these boundaries.

TestExpected behavior under the exercise policy
Worker requests another caseload using two phrasingsUnauthorized records remain inaccessible; wording does not expand scope
Analyst requests contact detailsOnly the authorized analysis view is available
Board reader follows a restricted citation or exportNo unintended access to raw records
Report includes a distinctive small-group quoteThe release review applies the agreed disclosure rules
Quote permission changes before a new public reportThe prohibited quote is excluded under the defined policy
Uploaded text asks the assistant to open another folderSource text does not grant authority or broaden retrieval
Report reader's role is removedFuture access follows the updated rule; downloaded-copy limits are documented

Record the role, policy version, test input, expected result, actual result and reviewer. Check both allowed and denied requests: a system that returns nothing for everyone is not a useful implementation. An appropriate safe explanation or aggregate answer may be preferable to an unexplained blank result.

These tests are a starting point, not proof against every attack. Rerun relevant cases after configuration, connector or role changes. Escalate failures to the responsible technical owner before expanding the workflow.

Ask vendors to demonstrate the mechanism

For Sopact or another provider, ask which controls are native, which are configured and which require another system. Request a demonstration of your policy with synthetic records, including retrieval scope, document access, citations, exports and permission changes.

Ask where prompts and source data go, which service providers process them, what is retained and whether any use supports model training. Review the applicable product settings and agreements. Do not infer an answer from a generic statement that a product is “secure” or “AI-native.”

The useful result is a documented boundary: what the assistant can read for each task, what a reviewer can share and where responsibility remains with your team. This lets data owners work confidently without assuming that every data-governance decision requires an unrestricted central repository.

Explore related demonstrations

Browse the video library → Use the source, definition and access checks in this lesson when evaluating a demonstration. A video does not verify the controls in your own configuration.

Frequently asked questions

Can a prompt enforce data permissions?

A prompt can guide behavior, but authorization should be enforced by the application and connected systems. Test what data is retrieved, not just whether one answer omits a name.

Is a contact ID anonymous?

Not necessarily. If it can be linked back to a person, it preserves identity linkage rather than guaranteeing anonymity. Treat the record according to the applicable purpose and protections.

Must all identifiable data be removed before any AI use?

Not in every authorized use. Limit information to what the task requires and verify the processing arrangements and access controls. Aggregate reporting often needs less detail than individual service delivery.

Does a minimum group size guarantee privacy?

No. Unique details, quotes and combined reports can still identify someone. Apply context-specific disclosure review across the output and its supporting access paths.

Should we test with real participant data?

Start with synthetic records that exercise the relevant boundaries. Use real information only within an approved validation process with appropriate safeguards.

What happens when a permission changes?

Assess the affected purpose, records and outputs under the applicable policy and obligations. Check new analysis, saved answers and sharing separately; do not assume one field updates every copy.

Who owns a consequential decision?

Assign an accountable person with authority to review the evidence and challenge the output. AI preparation should not obscure responsibility for decisions affecting people or organizations.

Apply the access policy to the report

Carry the access policy and sharing boundaries into writing a cited impact narrative. A useful report connects claims to evidence while giving each reader only the detail appropriate to their role.

Reviewed September 12, 2026. Policies and test records are fictional exercises. Product behavior must be verified in the configured workflow; legal requirements depend on context.

Return to your course →

Put this guide into practice.

Start with data your teams struggle to bring together. Agree shared definitions, keep each source identifiable, and decide who can see what before asking AI for an answer.

Explore Connected Data Intelligence →
Prepare data governance before using AI
Prepare your data governance
nonprofit-data-governance-before-ai
Feedback
Foundation
Prepare an evidence register and a tested governance baseline before applying AI to program data.
Make learning part of the work you already do
The Loop — the method in one read
the-loop
Loop
The method
0
One continuous method for reliable, traceable AI reporting across case, application, grant, and program workflows: collect clean, analyze on arrival, and improve in time.
Teams running cases, applications, grants, or programs that need AI-assisted reporting they can reproduce, trace to source evidence, and act on before the cycle ends.
What Is Case Intelligence?
What Is Case Intelligence?
what-is-case-intelligence
Case
Foundation
1
One current, traceable record for each person—connecting intake, services, notes, surveys, documents, outcomes, decisions, and follow-up.
Workforce and training · Youth and mentoring · Case management · Scholarships · Accelerators · Education · Nonprofit programs
What Is Grant Intelligence?
What Is Grant Intelligence?
what-is-grant-intelligence
Grant
Foundation
1
One connected evidence record from application and committee review through the awarded grant, grantee reporting, renewal, and board accountability.
Foundations and grantmakers · Public grant programs · Scholarships and fellowships · Accelerators
What Is Portfolio Intelligence?
What Is Portfolio Intelligence?
what-is-portfolio-intelligence
Portfolio
Strategy
1
A source-linked portfolio view that connects each investee or grantee's agreed plan, reporting cadence, evidence, risks, and results.
Impact funds and investors · Foundations with grant portfolios · Family offices · Blended-finance vehicles
What Is Connected Data Intelligence?
What Is Connected Data Intelligence?
connected-data-intelligence
Feedback
Foundation
1
Keep evidence from surveys, files, notes, documents, systems, sites, and reporting periods connected to one continuing record.
Multi-program nonprofits · Member and chapter networks · Research associations · Training and coaching teams · Organizations with scattered evidence
Build an impact report from evidence you can explain
What Is Impact Measurement and Reporting?
embedded-impact-measurement
Reporting
Align
1
Define intended change, align organization and funder context, govern measures, interpret evidence, and produce traceable reports for decisions.
Program and impact teams · MEL leads · Funders and donors · Foundations · Impact funds · Organizations building rigorous impact reports
Build a repeatable collect, review and improve cycle
Methodology — continuous, not annual
loop-methodology
Loop
The method
1
The continuous collect–analyze–improve cycle, adopted as an experiment: start with the step that already pays and add one data-collection step at a time.
Teams tired of rebuilding spreadsheets and forms who want a measurement system that compounds instead of resetting.
How to Build a Theory of Change with AI: Prompts and Examples
Build a Theory of Change You Can Test
how-to-build-a-theory-of-change
Reporting
Align
2
How Do You Onboard a Portfolio and Track Results?
Agree the Portfolio Reporting Plan
onboard-portfolio-lock-impact-agreement-track-results
Portfolio
Data Dictionary
2
Test whether an AI-assisted result is repeatable and correct
Reliability — the same answer twice
loop-reliability
Loop
The method
2
Determinism as a feature: the same question over the same data returns the same answer every run — the opposite of a generic AI chat that drifts.
Anyone who has watched a general AI tool give two different numbers for the same question and needs results they can stand behind.
Design application intake around a defensible decision
Design an Application Process
how-to-design-an-application-process
Grant
Foundation
2
How to Structure Stakeholder Data: Four Common Patterns
Choose your record structure
which-shape-is-your-data
Feedback
Foundation
2
Map the people, observations and relationships your workflow needs before collecting data.
How to Build a Logic Model: Steps, Example and AI Prompt
Build a Logic Model You Can Use
how-to-build-a-logic-model
Reporting
Align
3
How Do You Onboard a Grant or RFP Program?
Onboard a Grant or RFP Program
how-to-onboard-a-grant-rfp-program
Grant
Foundation
3
Turn your theory of change into a data-collection plan
Turn a Theory of Change into a Data-Collection Workflow
theory-of-change-to-data-collection-workflow
Case
Foundation
3
Build a portfolio data dictionary without forcing false comparisons
Map Portfolio Data to Reporting Standards
portfolio-data-dictionary-standards-mapping
Portfolio
Chapters
3
Keep a clear trail from a finding to its evidence
Traceability & Transparency
loop-traceability
Loop
The method
3
Every figure links back to the exact response, note, or document it came from — a full audit trail from headline result to raw evidence.
Teams whose numbers get scrutinized — by funders, boards, auditors, or standards — and who need to answer where did this come from on the spot.
How to Change Survey Questions Without Losing Comparability
Change questions with a clear history
change-questions-without-breaking-the-record
Feedback
Control
3
Create a question-change log and decide how old and new versions should appear in reports.
Programme & MEL leads · Teams whose questionnaire has ossified · Anyone evaluating a platform where configuration is a purchased service
Five Dimensions of Impact: How to Review Your Evidence
Use the Five Dimensions to Test the Evidence
five-dimensions-of-impact
Reporting
Align
4
How Do You Design a Grant Rubric and Eligibility Rules?
Design Your Rubric & Eligibility Rules
grant-rubric-eligibility-rules
Grant
Foundation
4
How to Measure Outcomes Across an Investment or Grant Portfolio
Frame Outcomes Over Outputs at Portfolio Level
frame-outcomes-portfolio-level
Portfolio
Chapters
4
Adapt the learning cycle to your workflow
Flexibility — one method, four workflows
loop-flexibility
Loop
The method
4
The same collect–analyze–improve cycle, shaped to four kinds of impact work — case, grant, portfolio, and feedback — each shown end to end.
Anyone deciding where the Loop fits their work, who wants to see the full path from messy input to a report they can defend.
How to Collect Feedback Offline and Keep Records Connected
Collect offline and reconcile the batch
collect-feedback-offline
Feedback
Connect
4
Build a field protocol and reconcile a test batch across devices, visits and delayed uploads.
Field & multi-site programs · Low-connectivity contexts · Nonprofits collecting in person
How Do You Design an Intake Form for a Baseline?
Design an Intake Form That Captures a Usable Baseline
intake-form-usable-baseline
Case
Nonprofit Track
5
Turn a proposed outcome into a reporting definition
Outcomes vs Outputs
frame-outcomes-over-outputs
Grant
Foundation
5
Impact Due Diligence: Review Evidence Before Investment
Pre-Investment Due Diligence & Screening
pre-investment-due-diligence-screening
Portfolio
Chapters
5
Plan and review your first workflow pilot
The Guarantee — first workflow in 2 months
loop-guarantee
Loop
The method
5
How to Build an Organization Evidence Model
Build the Organization Evidence Model
build-organization-evidence-model
Reporting
Align
5
How to Analyze Documents as Evidence: Sources, Context and Review
Read documents as traceable evidence
read-documents-as-evidence
Feedback
Connect
5
Create a document register and reviewed findings with source locations, context and explicit exceptions.
How to Clean Open-Ended Survey Responses Without Losing Meaning
Clean responses and define the denominator
clean-open-ended-survey-responses
Feedback
Clean
6
Create a cleaning log, response-status table and reproducible report statement.
How to Review Participant Support Needs Mid-Program
Spot At-Risk Participants Mid-Program
spot-at-risk-participants-mid-program
Case
Nonprofit Track
6
How to Write a Nonprofit Grant Application: Template and Example
Grant Application for Nonprofits
grant-application-for-nonprofit-organizations
Grant
Foundation
6
Design quarterly portfolio reporting that investees can complete
Collect Investee Reporting Without Repeated Rework
collect-investee-reporting-without-burden
Portfolio
Chapters
6
How to Build a Funder Context Profile: Research to Reporting
Build a Sourced Funder Context Profile
build-funder-context-profile
Reporting
Align
6
How Do You Measure Change at Exit?
Measure Change at Exit (Not Just Completion)
measure-change-at-exit
Case
Nonprofit Track
7
How Do You Collect Applications Clean at the Source?
Collect Applications Clean at the Source
collect-applications-clean-at-source
Grant
Collect
7
How to Follow Up on Missing Investee Data
How to Follow Up on Missing Investee Data
chase-missing-investee-data
Portfolio
Chapters
7
How to Analyze Multilingual Feedback and Evaluate Software
Analyze and review multilingual feedback
analyze-multilingual-feedback
Feedback
Clean
7
Build a language review sheet and test software on original responses, translations, codes and reporting bases.
Multi-country programs · Multilingual survey data · Global networks & chapters
How to Define Impact Metrics Your Team and Funder Can Use
Define Measures the Organization and Funder Can Both Use
define-impact-metrics-funders-want
Reporting
Align
7
Survey Attrition in Longitudinal Studies: Track Missing Waves
Track missing waves and matched outcomes
survey-attrition-longitudinal-studies
Feedback
Read
8
Build a wave-status register, compare response groups and report paired change with coverage and limitations.
How to Use Mentor Notes to Review Participant Support
Use mentor notes for support review
mentor-notes-early-warning
Case
Nonprofit Track
8
How Do You Reduce Applicant Burden?
Reduce Applicant Burden
reduce-applicant-burden-auto-clarification
Grant
Collect
8
Find inconsistencies in portfolio returns before reporting
Analyze Investee Reports Across Sources
read-investee-reports-multi-signal
Portfolio
Chapters
8
Impact Metric Definitions: A Practical Worksheet and Example
Give Every Number One Definition
one-definition-for-every-number
Reporting
Define
8
How to Connect Quantitative and Qualitative Survey Data
Connect scores and comments
connect-quantitative-qualitative-survey-data
Feedback
Read
9
Build a linked analysis view and joint display, with clear groups, reporting bases and evidence limits.
How to Calculate SROI as New Evidence Arrives
Calculate SROI — Live, Sourced, and Honest
calculate-sroi-live
Case
Nonprofit Track
9
How to Collect Grantee Reports with Less Burden
Collect Grantee Reports Without Burden
collect-grantee-reporting-without-burden
Grant
Collect
9
Keep company, investment and reporting history connected
Track Results Against the Impact Agreement
track-investees-impact-agreement-variance
Portfolio
Chapters
9
Turn Reporting Requirements into Evidence: A Practical Mapping Guide
Turn Requirements Into Collectable Evidence
turn-reporting-requirements-into-evidence
Reporting
Define
9
Connect baseline, follow-up and different rater perspectives
Analyze pre, mid and post surveys
analyze-pre-mid-post-survey-data
Feedback
Read
10
Build a matched pre/mid/post analysis, interpret score movement and retain clear rules for missing waves.
How to Report a Job-Training Program to Grant Funders
Turn a Cohort into a Funder Impact Report
job-training-grant-impact-report
Case
Nonprofit Track
10
How to Follow Up on Missing Grantee Data
Chase Missing Grantee Data
chase-missing-grantee-data
Grant
Collect
10
How to Build Useful Portfolio Impact Monitoring Alerts
Build Useful Portfolio Impact Alerts
portfolio-risk-monitoring-alerts
Portfolio
Chapters
10
How to Collect Clean Data Inside Your Workflow
Collect Clean Evidence Inside the Workflow
collect-clean-data-at-the-source
Reporting
Embed
10
How to Analyze Longitudinal Survey Data
Analyze longitudinal survey data
analyze-longitudinal-survey-data
Feedback
Read
11
Build a continuing analysis record with clear time scales, observed trajectories and limits.
How to Turn a Job Description into a Requirements Checklist
Clarify employer requirements
job-description-requirements-checklist
Case
Social Enterprise Track
11
Review applications with evidence, clear criteria and human judgment
Review Without Reviewer Bias
review-applications-without-reviewer-bias
Grant
Analyze
11
How to Ask AI Questions About Your Portfolio Data
Ask AI Questions About Portfolio Data
ask-your-portfolio-anything
Portfolio
Chapters
11
How to Keep Impact Reporting Numbers Consistent
Get Stable Results From Governed Data
same-numbers-every-time
Reporting
Read
11
How Do You Analyze a Batch of Grant Applications?
Analyze a Whole Round
how-to-analyze-a-batch-of-grant-applications
Grant
Analyze
12
How to Measure Outcome Duration and Drop-Off
Measure outcome duration and drop-off
measure-outcome-duration-drop-off
Feedback
Read
12
Build a dated outcome claim, distinguish missingness from outcome loss and test forecast assumptions.
How to Score Candidate–Role Matches with a Clear Rubric
Review candidate–role evidence
score-candidate-role-matches-without-bias
Case
Social Enterprise Track
12
Evidence Traceability: Link Every Report Claim to Its Source
Trace Every Result Back to Its Evidence
where-every-number-came-from
Reporting
Read
12
How Do You Roll Up a Grant Portfolio?
Aggregate Outcomes Across a Grant Portfolio
how-to-roll-up-a-grant-portfolio
Portfolio
Chapters
13
How to Report Job Placements to Impact Investors
Turn a Cohort into a Social-Enterprise Investor Report
job-placement-investor-impact-report
Case
Social Enterprise Track
13
How Do You Track Reviewer Conflicts of Interest?
Track Reviewer Conflicts of Interest
track-conflicts-of-interest-audit
Grant
Analyze
13
How to Write a Donor Report: Format, Evidence and Example
Design a Report for a Real Funding Decision
donor-report-funders-trust
Reporting
Decide
13
Build a report brief and claim-and-evidence table before drafting. Explain delivery, outcomes, spending, limitations and next actions.
Program managers, grant leads and reporting teams
AI Data Access Controls: What Your Assistant May See
Control what the assistant can access
what-the-assistant-may-see
Feedback
Prove
13
Define task-specific access, test synthetic records and verify report-sharing boundaries.
How to Write an Evidence-Based Impact Narrative
Write a cited impact narrative
impact-narrative-funder-report-cited
Feedback
Prove
14
Build and check a report paragraph using a claim-and-source table, appropriate quotations and clear limitations.
How Do You Read a Grantee Report?
Read a Grantee Report
read-grantee-report-multi-signal
Grant
Analyze
14
How to Use SROI Across a Portfolio Without Double Counting
Use SROI Across a Portfolio
monetize-impact-sroi-across-levels
Portfolio
Chapters
14
How to Write a Funder Report with AI—and Check It
Generate the Audience-Specific Report From Evidence
assistant-writes-the-funder-report
Reporting
Decide
14
Draft from approved sources, check the claims, and save an accountable report version. Bring the brief from the previous lesson.
Program managers, grant leads and reporting teams
How Do You Compute Grantee Variance?
Compute Grantee Variance
how-to-compute-grantee-variance
Grant
Analyze
15
When Is a Monetary Value on Social Impact Credible?
Add a Credible Dollar Value With SROI
credible-dollar-value-on-impact
Reporting
Optional method
15
Prepare a valuation brief. Decide what the evidence supports, what needs more work, and when an outcome account is enough.
Program, evaluation and investment teams considering social-value estimates
Keep a person’s history connected across programs and staff changes
Follow one person over time
one-person-followed-for-years
Feedback
Shapes
15
Build a participant record that preserves episodes, dates, versions and missingness across repeated collection.
How Do You Build an SROI Value Map?
Build an SROI Value Map
how-to-build-an-sroi-value-map
Reporting
Optional method
16
Build a first value map, keep missing evidence visible, and give each unresolved outcome a next action.
Evaluation, program and investment teams preparing an SROI analysis
How Do You Track Budget and Actual Spend?
Track Budget vs Actual Spend
how-to-track-budget-invoices-actual-spend
Grant
Analyze
16
Multi-Rater Feedback: Connect Perspectives and Protect Context
Connect several perspectives on one person
several-people-describing-one-person
Feedback
Shapes
16
Design subject-rater relationships, reporting rules and a tested multi-perspective feedback record.
How Do You Pick a Financial Proxy for SROI?
Pick a Defensible Financial Proxy
how-to-pick-a-financial-proxy-for-sroi
Reporting
Optional method
17
Compare candidate valuation sources and document why one fits your outcome, stakeholder and reporting period.
Evaluation and reporting teams selecting financial proxies
How Do You Analyze Grantee Reporting Longitudinally?
Analyze Grantee Reporting Over Time
analyze-grantee-reporting-longitudinal
Grant
Analyze
17
How Do You Compare Investees When Each One Defines Its Metrics Differently?
Compare & Benchmark Investees
compare-benchmark-investees
Portfolio
Chapters
17
Cross-Program Reporting: Combine Results Without Losing Meaning
Combine evidence across programs
many-programs-one-picture
Feedback
Shapes
17
Build a defensible cross-program result with comparable measures, correct denominators and documented exclusions.
How Do You Calculate the SROI Ratio?
Calculate the SROI Ratio With a Range
how-to-calculate-the-sroi-ratio
Reporting
Optional method
18
Build a reproducible SROI calculation, test its assumptions and explain the result in a reviewed report.
Evaluation and reporting teams reviewing an SROI calculation
How to Read Form 990 for a Grant Review
Read a 990 for Compliance
how-to-read-a-990-for-compliance
Grant
Analyze
18
How Do You Build Dashboards and Compliance Reports?
Build Dashboards and Reviewed Reports
dashboards-sroi-compliance-reports
Portfolio
Chapters
18
Plan evidence collection across your network
Run a member-network survey
member-network-survey
Feedback
Shapes
18
Design and test a member reporting cycle with continuing records, coverage checks and authorized results.
Ask Your Whole Grant Round Anything (Assistant + MCP)
Ask Your Whole Grant Round Anything
ask-your-grant-round-anything
Grant
Analyze
19
Produce portfolio reports that trace back to approved evidence
Produce the LP and Board Impact Report
portfolio-lp-board-impact-report
Portfolio
Chapters
19
How Do You Build a Grant Audit Trail?
Build a Grant Audit Trail
grant-audit-compliance-trail
Grant
Communicate
20
How Do You Connect Your Stack Without Lock-In?
Connect Systems and Test Data Portability
portfolio-connect-your-stack
Portfolio
Chapters
20
How Do You Produce Grant Compliance Reports?
Produce Compliance Reports
grant-compliance-regulatory-reports
Grant
Communicate
21
How Do You Roll Grantees Into a Board Report?
Roll Grantees Into a Board Report
roll-grantees-funder-board-report
Grant
Communicate
22
How Do You Build Grant Dashboards and Maps?
Grant Dashboards & Maps
grant-dashboards-geographic-mapping
Grant
Communicate
23