Daily content to rocket your growth plan
I’ve got plenty of ways we can work together, but if you’re looking for a zero-cost source of inspiration, insights, and stories from the trenches, you might enjoy these posts from my daily mailing list.
I LOVE the daily thoughts that result from subscribing to you. They are forward-looking, optimistic in every way.
— Adrienne R. Smith, New Mexico Caregivers Coalition
I just wanted to let you know how much I enjoy your emails. You have an amazing knack for explaining tech topics so that non-tech people can easily understand them and make it interesting to read. The personal touch of storytelling shows your ability to connect with people. It is a skill you rarely see anymore in this day and age.
— Fiona Williams, Sacred Art of Living Center
If you like what you see here, sign up below to join the list. Yes, it’s really daily. Yes, people really stay subscribed. And yes, I do read (and usually reply to) all responses. See you in the in-box!
Looking for more free resources?
Mastering CiviCRM Crash Course
A free 10-day email course to teach you how to leverage CiviCRM for your organization’s goals.CiviCRM Upgrade Messages Previewer
Before you start a CiviCRM upgrade, check here to preview the kind of messages you can expect to see, based on your current and target CiviCRM versions.Tools and other resources
A collection of tools and services I love, plus recommended reading on various topics.
Daily Emails
Engagement means nothing
Engagement itself is valuable.
But as a word, saying you want "more engagement" is almost meaningless.
Unless you define it for yourself:
Decide what you hope people will do;
Form an idea of how your actions will lead them to do it;
And test whether that idea fits reality.
Once you're doing that, you'll have something measurable to improve upon.
And continual improvement is your secret weapon, isn't it?
All the best,
A.
Import/export pro tip
Your CRM's export and import features are pretty powerful and useful, once you get to know them.
List member Emily passed along a great tip in conversation today:
Always export the Contact ID.
Because you're probably going to do something with that exported list.
And sooner or later, you'll want to import some of those contacts back into the CRM.
To update their info,
or to put them in a group,
or to send them a mailing.
If your spreadsheet already includes the Contact ID, that import will be pretty easy.
If not, you'll have a little adventure trying to get them all imported without creating duplicates.
Thanks, Emily!
All the best,
A.
“Social” media?
Remember when social media was, you know, social?
When you could actually communicate with it, create connections, build community?
I'm almost sure I can remember it.
But now I think that time is just as gone as knowing your neighbors.
So ...
Since we need connections and community now, no less than we ever did ...
And "social" media just might not be cutting it ...
How are you building connections with the people who matter to you?
All the best,
A.
P.S. That’s not an entirely rhetorical question. I’m trying to figure this out, too!
Over-committed
You ever feel over-committed?
I think I’m pretty good at not over-promising to my clients (and hey, if you're reading this, let me know).
But with family, and home, and volunteering in the community, and helping out a friend, and taking care of my own damn self...
Yeah, sometimes I feel it.
And often, for me, the way through that is surprising.
It's not (usually) going back on my commitments.
It's not (usually) doing less.
Usually, it's enough to take time every day or two to reflect on
why I care about those commitments,
how they're enriching me and the people I care about.
How do you handle it?
All the best,
A.
Not silly
Once you've solved a long-running problem, it might feel silly that it took so long to address.
But it's not.
If at the beginning you had understood the cause, and known the solution, you would have fixed it.
But you didn't.
Working through problems over time is not silly.
Often, it's necessary.
All the best,
A.
Downtime at 3am
This is a little silly, but I'll share it, because it might matter for you.
I have several online systems that help me run my business, and early on I found they'd sometimes go offline -- and stay that way until I noticed and rebooted them. I was not happy.
Lesson learned:
Systems go down.
When they do, I need a way to respond quickly.
So I arranged for monitoring that would send me a text message if anything important went offline.
Once in a few months or so, I'd see a downtime message, take corrective action, and be happy.
But then I noticed that if a text came in while I slept -- like at 3am -- I simply wouldn’t hear it. So a system might stay offline for hours. I was not happy.
Lesson learned:
Timely alerts need to be noisy,
interruptive,
hard to ignore.
So I arranged for downtime alerts to come in through a dedicated phone app with attention-getting alert sounds.
Once in a few months or so, I'd be awakened by an urgent alert, take the same old corrective action, and be happy.
Recently, I’ve found a couple of those systems triggering late-night alerts multiple times a month. I was not happy.
Lesson learned:
The downtime was unpredictable,
but the fix was always the same.
So I arranged for an extra step in my downtime monitor: before alerting me, try the standard fix a couple of times (and email me about that), and only alert me if that doesn't solve the outage.
This morning, I found an email from the monitor.
It had solved the problem while I was asleep.
All systems were live, and the downtime was less than a minute.
Maybe sometime I'll explain why this is a little silly (but only a little).
But for now, I think there's a winning pattern here:
Making everything run perfectly all the time
is an expensive proposition.
Often it's enough
to ensure you notice when something's amiss,
and to take corrective action.
And when the patterns reveal a consistent fix
for a common problem that's keeping you up at night (literally or figuratively),
automating that fix is surely worth the effort.
All the best,
A.
I hired a coach
I recently started working one-on-one with an expert coach, and it's made a huge difference for me.
I've spent several years trying to figure this stuff out on my own. And that's been fine, as far as it goes.
But now I have someone who:
Points out little things I'm doing that limt my results.
Suggests specific alternatives that actually help.
Reminds me to stay focused on my goals and actually improve specific things, not just "keep trying stuff."
Shares his own expertise and experience about what's actually possible or worth pursuing -- and what isn't.
Adapts our work together to fit my own goals, not some generic roadmap he imagines for “most people.”
We meet once a week, and after a month I can already see improvements I just wasn't getting before.
So who's this coach?
He's a black belt at the gym where I train in Brazilian Jiu-Jitsu.
Sure, this is a hobby.
It's not my job.
It's "not that important."
But the things is:
If you can find the right coach for you, one-on-one coaching has huge benefits.
And not just for hobbies. For any area where you believe your results really matter.
It's just night and day different from trying to figure it out all by yourself.
All the best,
A.
Easy segmentation by county
Doing geographic segmentation by county — rather than proximity like “within X miles of Y” — can make a lot of sense.
But how do you know the right county for any given contact address?
It's not a question you'd normally ask on a form, e.g. next to City and State.
You can't really expect your staff to look up the county for every single address they enter.
Fortunately, in CiviCRM, you can make the right county populate automatically.
You’ll need to use Google as your geocoder service.
You'll need one of these CiviCRM extensions: County Lookup or Geocoder
Once you have that, CiviCRM uses its existing geolocation fetures to automatically assign a county to every address, right when it's entered.
No manual lookups, no requiring your constituents to fill in yet another field.
Just correct counties for every address, automatically, for easy segmentation when you need it.
Easy!
All the best,
A.
P.S. If your CiviCRM setup doesn't yet have all the counties you need (that is, you can't even manually specify the right county for any given address), and if you're dealing with US addresses, you can install the US County Loader extension. Merely installing it will make all US counties available for your contact addresses.
Segmenting by location?
Your CRM probably lets you find contacts by geographic proximity (CiviCRM does).
The problem is, "X miles from Y" is the formula for a circle.
And your constituents don't live in perfectly round geographic areas.
If you're segmenting by circular areas, your segments will have either big overlaps or big gaps.
Fortunately, there are better options, namely:
ZIP codes
and counties.
Any contact with an address will appear in exactly one of those.
Configure a few smart groups -- e.g. a "North Texas" group for anyone with a primary address in one of "these 36 counties" -- and your geographic segments are set, automatically updated for as long as you need them.
With no overlap, and no gaps.
Not bad, right?
All the best,
A.
When “clever” means “messy”
Making your CRM do something just the way you need it ... that can be a great thing.
But making it do things it was specifically designed NOT to do ... that can be a big mess.
Things like:
Intentionally maintaining duplicate contact records
Tracking "do not contact" in the Nickname field
Maintaining one Individual contact as "Mr. and Mrs. Smith"
Usually, these clever arrangements are meant to solve one important problem or another.
But because they go against some core assumptions in the CRM software (CiviCRM in this case), they also wind up creating new problems. Usually in ways you don't anticipate.
Sometimes it's hard to know whether your clever solution is really a winner or just a bad idea that goes against the core assumptions of the software.
Sometimes you can ask a trusted advisor beforehand and avoid trouble.
Sometimes you just try it, and find out later.
But this may be worth remembering:
If it feels like you're getting more then your share of surprises from your CRM, it may be that you're trying to make it do something it was designed not to do.
All the best,
A.
You have to do this
It seems like every few months I run into somebody who's having trouble with bounced emails.
And by “having trouble” I mean:
they're actually not tracking them.
This is totally understandable
because it might be one of the most overlooked bits of CRM configuration.
But it's also trouble
because failing to track bounces can make you look like a spammer.
And looking like a spammer is a good way to ensure nobody receives your messages.
Here's a quick test you can do right now if you're not sure you've covered this base:
Create a CiviCRM scheduled mailing that includes an address you know will bounce.
(For example, as of today, I happen to know that wJ04jxBqlfdYNQWwR5CR@gmail.com is a bogus address that will bounce; probably any random address like that will work as well -- and to verify that, you could just try manually sending an email yourself and see if you get a bounce.)If that address doesn't appear in the "Mail Bounces" report within a day or so, there's a good chance your bounce handling isn't configured correctly.
A test like that just takes a few minutes, and it can save you a ton of grief.
And if you're having trouble with this, I recommend you take a look at the docs here, or reach out to someone who can help you with this. (Heck, just hit reply here and ask me.)
All the best,
A.
No system is risk-free. But…
In yesterday's security-related email, I made an analogy with some holes in it:
If my house gets robbed, I can't really prevent it happening again just by moving to a different house.
Well, maybe. Sure, merely moving to a new house doesn't necessarily change things.
But in truth, moving to a different house absolutely can reduce the risk -- especially if the first house had crappy locks, no alarm, and was in a high-burglary area.
Likewise:
Changing CRM vendors or architectures can materially change security risk.
"No system is risk-free" does not imply "choice of system doesn’t much affect risk."
The stronger lesson is that security is risk management, not a simple "yes-or-no" attribute of a given product:
architecture,
maintenance,
access controls,
hosting,
backups,
organizational practices,
incident response,
the amount and type of data you're storing,
whether a single breach could expose many organizations at once (as in the Beacon CRM case) …
Improving any of them can reduce your actual level of risk.
All the best,
A.
Planning for the worst
So yesterday I mentioned that a major subscription-based (paid) CRM for UK nonprofits recently had a security breach with complete data disclosure.
In other words, the full CRM data of all the nonprofits who were using that CRM was copied out by attackers, and could potentially be misused.
There's a great write-up about it on the CiviCRM blog, if you'd like to read more — including some thoughtful views on what this means for folks like you and me using open-source CRM solutions.
Beyond that, I think this is a good example of an important point:
No matter what system you decide to use, there's always some chance that the bad guys will find a way in.
It’s just as true as for our own personal security:
If my house gets robbed, I can't really prevent it happening again just by moving to a different house.
If my neighbor's house gets robbed, it doesn't necessarily mean that my house is any less at risk than his was.
Instead:
We do what we can to keep ourselves secure.
Meanwhile, we make a plan for how we'll handle it if something does go wrong.
Here’s the thing:
Life is full of risk, but that doesn't stop us from enjoying it as we go along.
Not in our own homes, nor in our work.
If you have questions about how to keep your constituents' data safe,
shoot me a reply and we can get into the details.
In the meantime, you might take a few minutes today to consider:
How would you and your constituents be affected if your CRM data were compromised?
How much damage could that cause to your mission?
How could you handle it, if it happened?
Uncomfortable as it might be, it’s worth some consideration.
These question can actually be answered.
And having the answers is a lot better
than not having them
when you really need them.
All the best,
A.
AI’s dark side
I've been getting lots of questions about security.
WordPress has dropped more than one significant security fix in the past few weeks.
Beacon CRM -- a major subscription-based (paid) CRM for UK nonprofits -- announced a serious security breach and data disclosure at the end of last month.
There's more, and folks in the geeky circles I run in are taking about it.
What's going on?!
Part of it is just normal life.
Hackers gonna hack, defenders gonna defend, sometimes it be like that.
But...
AI-driven threats are on the rise.
Just as you're probably using AI tools to try and make your work easier, the bad guys are doing the same for themselves. Because of this, I think we can expect security threats -- and security fixes on supported software -- to come out with increasing frequency.
What this means for you and me:
Keeping your software up to date just keeps getting more important.
I've worked with organizations who’ve been bitten by this.
It's no fun for them. At all.
So...
Check your backup processes.
Check your update procedures.
Check your system monitoring.
If you stay on top of it, you might look back later and wonder what the hubbub was about.
But if you don't, you'll probably find out, sooner or later.
All the best,
A.
Easy emergency account recovery
Most organizations have at least a handful of user accounts for critical outside services.
Web hosting, payment processors, and more. Usually much more.
What happens when the person who manages one of those services leaves your organization?
How are you going to login to manage that service without the password that person was using?
But you've already decided to be smart and not store those passwords in a shared spreadsheet or document.
Your staff are each using a proper password vault for that, of course.
So there's a problem: your passwords are secure, but it's not easy to share them.
Here's the easiest solution I've found:
Make sure any outside service account uses an organization email -- not a staff member’s (or vendor’s) personal email address.
Record, in a shared spreadsheet or other document, which email address is used for each service account.
That's it.
If things really get bad, and the person who manages the account is inaccessible for whatever reason, at least you'll have a way to recover your access.
You'll know which email address to use, if you can reset the password by email.
And you'll have a way to access that email inbox, because it's an organization email address and not a personal one.
Sure, it's not perfect.
You might wish for a way to have secure password storage that can be easily shared across your organization.
But it's very likely that such a setup is more expensive or more complicated than your small organization wants to handle.
Still, just by documenting the email address for each service account, you get shareable documentation that can be pretty easily kept up to date, and you get a recovery method that works.
Not a bad compromise, I'd say.
All the best,
A.
Documenting passwords?
Imagine having your public website and your membership portal go completely offline for a week.
An organization I know recently had that problem, and you can imagine … it was not fun.
The problem was, a couple of key staff members had left the organization.
And when something went wrong, the organization simply did not know how to access those accounts.
So, what to do?
First, here's what not to do:
Storing usernames and passwords in a spreadsheet or document is a Bad Idea™. (See here and here for organizations who've been burned this way.)
So: Do you want a properly secure and safely shared password vault that's easy to use for all your staff?
Unfortunately (says me) that’s not likely.
For most small nonprofit teams, it's either too expensive or too complicated.
Fortunately, it's probably not necessary.
For now, start by ensuring that your passwords are stored safely.
Insist that all staff use a proper password valut for all passwords. No spreadsheets or Word documents.
(If you’re unfamiiiar, take 2 minutes right now to try one; I like KeePassXC.)
Then we can talk about a simple way to safely document the information you’ll need
to recover account access in case of an emergency.
More on that tomorrow.
All the best,
A.
Easiest way to start documenting your systems
If the wrong person suddenly departs your organization,
your whole team could have a really hard time using the systems that person has left behind
… unless those systems get documented.
That could be a big job, but the good news is:
you don't have to do it all at once.
A Google Doc can be your starting point.
And it's a very easy starting point.
You just open up a new document and use outline formatting.
Right away, you have sections
and structure
and even a table of contents.
Share it with your team.
Let them edit it alongside you if you like,
or just give them read-only access.
Then, take a few minutes now and then to add the information that matters:
Vendor names and contact information.
Which third party provider takes care of what services.
Structures and naming conventions for organizing your CRM data.
Anything that's hard to explain in a sentence, or impossible to explain if you or one of your team members becomes unavailable.
Now there's a big caveat here: this is not for account usernames and passwords. Ever.
But for everything else, this simple document can be your very easy starting point.
You can always formalize it more later, if you like.
But you can only do that if you've actually started somewhere.
Try starting with a humble Google doc.
Within a few weeks or months, you'll have a resource that could really save your bacon.
I bet you could start it today.
All the best,
A.
“What should we document?”
When I advise organizations to start keeping their own internal documentation, one of the first questions is:
“What should we be documenting?”
Well, it doesn't have to be "everything."
But it probably should -- eventually -- cover:
Frequently asked and re-asked questions about how to get something done within your system.
Every organization has unique workflows.
Unless you want your staff doing it differently every time, it's worth documenting.Definitions and policies you can't easily rattle off without a second thought.
What's a "returning member"?
What's the difference between those 12 separate permisson levels you've collected over the years?
What to do if you find a security vulnerability?Contact info and account credentials for outside services and vendors.
Who to call when your live sure goes down?
How to log in to GoDaddy or Domain.com to manage your 33 custom domain names?
Those things start to matter when somebody's out sick,
or the goose poop really hits the fan,
or someone departs the organization unexpectedly.
But here’s the thing:
You don't have to document it all at once.
You'll be updating it over time anyway.
But to start, you do need a place to document it.
That's the thing to decide first.
More on that decision tomorrow.
All the best,
A.
Hot dog = sandwich?
At age 16, my daughter could argue about anything.
Her favorite starter was:
"Okay, is a hot dog a sandwich?"
I mean …
Everybody knows what a hot dog is.
But what counts as a sandwich?
If you can't define them both, then you can't agree on an answer.
We know what a member is. But what's a "returning member"?
We know what a donor is. But what's a "major donor"?
We know what a contact is, but what's an "engaged contact"?
If you can define the terms, then you can say if someone is or isn’t.
But if not ...
You may just feel like you're arguing with a 16 year old.
All the best,
A.
Another security release for CiviCRM
In a fairly unusual move, CiviCRM has released its second security update (versions 6.16.5, 6.17.1, and 6.10.10 ESR) in two days.
A core team member explains:
This is quite unusual; but tldr -- it's very similar to another highly critical advisory from earlier today. So if we didn't fix it quickly, the odds are that someone else would recognize it soon.
If you were really on the ball and upgraded yesterday afternoon (versions 6.16.4, 6.17.0, and 6.10.9 ESR), you’ll want to upgrade again for this one. I’m re-doing some upgrades myself today.
Why this is a good thing:
First, let’s acknowledge that two security updates in two days is inconvenient. Nobody likes inconvenience.
But it’s also great to know that the CiviCRM security team is catching these things and pushing out the fixes.
Security and convenience will always be trade-offs.
In this case, I recommend trading in favor of security.
Any questions about this, pelase let me hear from you!
All the best,
Allen

