You’re onboarding a new volunteer next week. They need access to your Communications Team, a SharePoint library containing campaign resources and perhaps a shared inbox so they can assist in responding to enquiries.
Adding them only takes a few clicks, but have you paused to think about everything they’ll be able to access once they’re in?
Many charities assume volunteers will only see the files or conversations they’re expected to work on. Microsoft 365 doesn’t work like that. Depending on where you add someone, they may automatically inherit access to far more information than you intended. Without realising it, you could reveal draft funding applications, trustee discussions, financial records or sensitive beneficiary information.
Fortunately, avoiding these problems is much easier than most people think. Microsoft 365 includes robust built-in permission controls that allow you to onboard volunteers quickly while keeping confidential information secure. The solution is understanding what volunteers can see by default and knowing when to make a few simple adjustments before granting access.
This guide walks you through the decisions you’ll need to make when adding volunteers to Teams, SharePoint, Outlook, OneDrive and shared calendars. You don’t need to be an IT expert to get it correct. You just have to understand how permissions work and the right questions to ask. If you do need extra support, your managed IT provider can help configure, test and document everything so you can onboard volunteers with confidence.
What Volunteers Can See in M365 - The Defaults
Understanding Microsoft’s default permissions is one of the easiest ways to avoid accidental data exposure. Whenever you add someone to a Team, SharePoint site or shared mailbox, Microsoft 365 assumes you’ve already decided that person should have access to everything within that workspace. That’s not a design flaw; it’s how the platform is expected to work.
This means that every time you add a volunteer to a shared resource, you should pause for a moment and ask yourself a simple question: Should they be able to see everything in this space? If the answer is no, it’s worth reviewing the permissions before you click Add member.
Take Outlook shared inboxes as an example. Once a volunteer is given access to a shared mailbox, they can normally read every email stored there, browse previous conversations and reply to or forward messages on behalf of the organisation. For a volunteer coordination inbox, that’s usually exactly what’s needed. However, if that same inbox contains safeguarding concerns, HR discussions or confidential financial correspondence, you’ve instantly shared much more information than you intended.
OneDrive behaves very differently. Personal OneDrive storage remains private unless the owner purposely shares files or folders with someone else. Volunteers can’t browse another member of staff’s OneDrive or discover documents through search, making OneDrive one of the safest places to share specific resources without worrying about wider access.
SharePoint requires a little more consideration. When someone joins a SharePoint site, they generally inherit that site’s permissions. In practice, this means they’ll be able to browse documents, pages and libraries that everyone else on the site can access. If volunteer guidance sits alongside trustee minutes or financial reports, there’s a good chance they’ll see those too unless you’ve created additional restrictions.
The same principle applies in Microsoft Teams. Standard channels are visible to every member of the Team, including all conversations, shared files and previous discussions. Without careful Team organisation, bringing a volunteer onboard for a specific grant application may expose them to draft proposals, strategic conversations, and past records that weren’t intended for their eyes.
Shared calendars warrant similar consideration. Depending on how you’ve configured them, volunteers may be able to see meeting titles, attendees, locations and event details. While that’s often helpful for coordinating activities, it’s worth checking exactly what’s visible before granting access.
Before adding a volunteer to a workspace, think carefully about whether every file, conversation and email in that space is appropriate for them to see. If you’re uncertain, it’s well worth asking your IT provider to review your setup. They can help identify areas where permissions should be reviewed carefully without making collaboration more difficult.
What Volunteers Cannot See (Built-In Protections)
While it’s important to understand where volunteers inherit access, it’s equally reassuring to know that Microsoft 365 protects a great deal of information automatically. You don’t need to hide every file yourself because several important security boundaries already exist behind the scenes.
One of the biggest misunderstandings is that staff can browse each other’s OneDrive storage. They can’t, and neither can volunteers. Every user’s OneDrive remains private unless they explicitly choose to share a document or folder. That means you can confidently store personal working files without worrying that new volunteers will stumble across them.
Private channels in Microsoft Teams provide another layer of protection. Unlike standard channels, private channels are only visible to the people who have been specifically added. If a volunteer isn’t a member, they won’t see the conversations, files or even recognise the channel exists. This makes private channels ideal for coordinator discussions, safeguarding conversations or management planning that shouldn’t be shared more generally.
Microsoft 365 also supports sensitivity labels, allowing organisations to apply additional protection to important documents. Depending on how they’re configured, these labels can prevent unauthorised users from opening files, downloading them or forwarding them outside the organisation. Even if someone accidentally discovers a document, they may still be prevented from accessing its contents.
Permissions don’t always have to be all or nothing either. Read-only access is frequently the safest option when volunteers simply need to view guidance, policies or templates. They can access the information they need without risking accidental edits or deletions, reducing the likelihood of mistakes while still allowing them to work independently.
Restricted SharePoint sites add another layer of security. If volunteers aren’t members of a particular site, it won’t typically appear in their navigation or search results. Sensitive areas remain effectively hidden unless someone has been granted permission to access them.
Finally, many charities choose to strengthen security further with Conditional Access policies. These permit organisations to control how and where Microsoft 365 can be accessed, for example by forcing multi-factor authentication or limiting access from unmanaged devices. Although these controls work behind the scenes, they provide important protection for sensitive charity data.
The reassuring message is that Microsoft 365 already does much of the heavy lifting. Your role isn’t to lock down every piece of information separately, it’s to understand where additional controls are needed and where Microsoft’s built-in protections are already working in your favour. If you’d like help implementing sensitivity labels, Conditional Access or a secure permission structure, our Managed IT Support for Charities and Nonprofits team can help configure your Microsoft 365 environment, so volunteers only see what they need to see.
The Inbox Decision: Can Volunteers See All Emails?
Shared inboxes are one of the most general decisions you’ll make during volunteer onboarding, and they’re also one of the easiest places to expose confidential information accidentally.
What matters is how you structure those inboxes. A dedicated volunteer coordination inbox works well precisely because everyone should be seeing the same messages. It avoids duplicated replies and makes collaboration easier. However, using a single mailbox for everything can cause problems. If finance queries, safeguarding concerns, grant applications and volunteer enquiries all arrive in one place, adding a single volunteer instantly exposes information they were never meant to see.
Silver Salisbury Group encountered a similar challenge when updating the way staff and volunteers communicated. Before moving to Microsoft 365, outreach workers often relied on personal email accounts for organisational communication. That made governance inconsistent, created GDPR risks and made it difficult to control who could access different conversations.
As part of their Microsoft 365 implementation, they moved to organisation-managed email accounts and introduced role-based access to shared mailboxes. Volunteers could be added to coordination inboxes relevant to their work, while sensitive trustee, finance and management communications remained separate within staff-only mailboxes. The result was a far more protected and practical environment that supported collaboration without compromising discretion.
When deciding whether to add a volunteer to a shared inbox, ask yourself one simple question: Is there any email in this mailbox that a volunteer shouldn’t see? If the answer is yes, it’s worth creating a separate mailbox, moving collaboration into Microsoft Teams or restructuring how communications are organised.
A little planning at the start can avoid substantial governance issues later, and if you’re unsure about the best approach, your IT provider can help design a mailbox structure that keeps sensitive information safe while ensuring volunteers still have everything they need to do their role effectively.
SharePoint and OneDrive: What Is Safe to Share?
For many charities, SharePoint and OneDrive become the home for almost everything volunteers need to access, from induction packs and policies to event plans and marketing materials. Understanding the difference between the two is one of the most crucial parts of secure volunteer onboarding because they are designed to work in very different ways.
The reassuring news is that OneDrive is private by default. Every member of staff has their own personal storage area, and nobody else, including volunteers, can browse its contents unless individual files or folders have been consciously shared with them. That gives you total control over what people can access.
This makes OneDrive ideal when you want to share a small collection of documents with a volunteer. For example, you might create a folder containing branded templates, induction paperwork or campaign resources and share it with read-only permissions. Volunteers can download the files they need without inadvertently editing or deleting the originals, giving everyone assurance that the latest version will always be accessible.
SharePoint requires a little more planning because it is designed for collaboration across teams rather than individual file sharing. When you add a volunteer to a SharePoint site, they generally inherit the permissions for that site. If you’ve organised your content well, this makes onboarding extremely straightforward. If you haven’t, it can rapidly expose documents that were never intended to be shared.
As a rule, volunteer-facing SharePoint sites should contain resources that support day-to-day work, such as policies, volunteer handbooks, training materials, event information, templates and standard operating procedures. These are documents that benefit from being easily accessible and centrally managed.
More sensitive information warrants its own protected space. Financial records, beneficiary data, trustee papers, donor information and confidential HR documentation should be stored in locations with separate permissions, so they remain accessible only to authorised staff.
This is where role-based access really pays dividends. Rather than thinking about permissions one volunteer at a time, think about the different roles within your organisation. Event volunteers, fundraising volunteers, trustees, coordinators and staff all need different levels of access. Once you’ve organised SharePoint around those roles, onboarding becomes much simpler because you’re adding people to an existing permission structure rather than making decisions every time someone joins.
Silver Salisbury Group experienced precisely this transformation. Before adopting Microsoft 365, documents were frequently shared through personal email attachments and informal file exchanges. Not only did this create version control issues, but it also made it difficult to know who had access to which information. Working with Qlic, the charity moved to SharePoint and gained a structured document environment where volunteers could easily find the policies, guidance and resources they needed, while sensitive financial records and trustee documentation remained securely governed behind separate permissions. The result was less confusion, better collaboration and a far more manageable approach to information governance.
Creating that kind of structure takes some planning at the outset, but it’s an investment that continues to save time every time a new volunteer joins your organisation. If you’re looking for practical advice on organising files and folders, our guide to managing Microsoft 365 day-to-day for non-IT staff explains best practices for keeping SharePoint and OneDrive organised and easy to maintain.
If designing role-based document libraries feels overwhelming, you’re not expected to do it alone. An experienced managed IT provider can help design the structure, configure permissions and ensure volunteers always receive the correct level of access from day one.
Teams Channels: Public, Private, and the Volunteer Decision
Microsoft Teams has become the centre of collaboration for many charities, bringing together conversations, meetings, files and planning into one place. It’s often the first application volunteers use after they’ve been onboarded, which makes it particularly important to understand what they’ll see once they’re added.
The key distinction is between standard channels and private channels.
Standard channels are visible to everyone who belongs to the Team. Every conversation, shared file and announcement in those channels can be viewed by every member. That’s precisely what you want for general communication, project updates and information that everyone involved should be able to access.
Private channels work differently. Only the people who have been specifically invited can see that the channel exists, let alone access its conversations or files. They’re ideal for discussions that involve coordinators, safeguarding leads, senior management or trustees, allowing staff to work alongside volunteers without revealing sensitive information.
It’s also worth learning that the files shared within Teams are stored in SharePoint. That means SharePoint permissions continue to play an important role behind the scenes. If you’ve organised your document libraries well, Teams naturally benefits from the same secure structure.
Imagine you’re creating a Team for volunteer onboarding. The General channel contains welcome information, training resources and organisation-wide announcements that every volunteer must see. A Projects channel allows volunteers to collaborate on upcoming fundraising events and community activities. Alongside those sits a Coordinator Notes private channel where staff discuss volunteer issues, safeguarding concerns and operational decisions. Volunteers have everything they need without ever seeing conversations that aren’t applicable to their role.
This approach keeps everyone working within the same Microsoft 365 environment while maintaining correct boundaries between volunteer and staff communications.
Private channels are one of the easiest yet most effective tools for secure onboarding. Rather than creating entirely separate Teams for every scenario, you can use a combination of standard and private channels to strike the right balance between collaboration and confidentiality.
If you’re unsure how to structure Teams for your organisation, your IT provider can help you create a channel layout that supports volunteers while protecting sensitive discussions from preventable exposure.
Building a Safe Onboarding Checklist
Once you understand how Microsoft 365 permissions work, onboarding volunteers becomes much more consistent. Instead of making quick, careless decisions you can follow the same simple process every time someone joins your organisation.
The first step happens before you create the account or send an invitation. Rather than asking what systems a volunteer might like access to, start by thinking about what they need to do. Which Teams will they use? Which SharePoint libraries support their role? Do they genuinely need access to a shared inbox, or would a Teams channel achieve the same outcome more securely?
As you answer those questions, pause to consider three more. Is this resource free from sensitive information? If the volunteer can see everything inside it, are you happy with that? And if not, could a small adjustment, such as read-only permissions, a private Teams channel or a sensitivity label, solve the problem?
Only once you’ve answered those questions should you start granting access.
One step that’s often forgotten is testing. If possible, sign in using a test account or ask a colleague to verify what a volunteer can see. It’s surprising how often organisations discover unexpected permissions only once someone has already started using the system. Spending a few minutes checking access before day one can prevent difficult conversations and reduce the risk of confidential information being exposed.
The final step is just as important as onboarding itself: offboarding. When a volunteer leaves, remove them from Teams, SharePoint sites, shared mailboxes and any other resources they no longer require. Don’t just archive the account and assume everything is secure. A consistent offboarding process ensures former volunteers can no longer access organisational information and helps keep your Microsoft 365 environment organised.
Once you’ve added volunteers to Teams and SharePoint, they’ll also need to know how to use the tools you’ve given them. Our How to Use Microsoft 365 Guide for Volunteers walks new volunteers through accessing Teams, SharePoint and the other Microsoft 365 applications they’ll be using in their role.
A documented onboarding process doesn’t just upgrade security. It gives volunteers a better experience from their very first day, reduces administrative effort and gives your organisation confidence that everyone has exactly the access they need, and nothing more.
Conclusion
Onboarding volunteers into Microsoft 365 doesn’t have to be complicated. Once you understand how permissions work by default, it becomes much easier to make informed decisions about who should have access to what. Rather than worrying about every individual file or conversation, you can focus on creating a clear, role-based structure that gives volunteers everything they need while keeping sensitive information protected.
Whether you’re confident managing Microsoft 365 in-house or would prefer an experienced partner to configure everything for you, the important thing is knowing that you don’t have to tackle volunteer onboarding alone. A well-planned permission structure saves time, reduces security risks and creates a better experience for everyone involved. The right partner can also make the whole process much smoother. That is exactly what Alan Mitchell, Treasurer of Silver Salisbury Group, found when his charity turned to Qlic:
“We were well supported during the take-on period. Since going live we have been impressed by the rapid response of the support desk staff, their ability to identify the root cause problems and the quick fixes.”
If you’re reviewing your volunteer onboarding process or planning a move to Microsoft 365, Qlic IT can help you design secure permission structures, configure Teams and SharePoint, implement governance controls and ensure volunteers only have access to the resources they genuinely need. Whether you want guidance on best practice or someone to handle the technical setup on your behalf, we’re here to help.
Frequently Asked Questions
Can I see what a volunteer has accessed?
Yes, to an extent. Microsoft 365 includes audit capabilities that allow organisations to see who has accessed SharePoint sites and Teams resources, helping you understand how information is being used. However, standard Microsoft 365 licences don’t record every individual file view in detail unless advanced audit logging has been facilitated.
For most charities, that’s perfectly acceptable. Good permission management is far more important than trying to monitor every action after the event. If you have compliance or governance requirements that demand more detailed auditing, your IT team or managed IT provider can enable additional logging and configure reports that provide greater visibility into user activity.
What if a volunteer accidentally deletes something?
Accidental deletions are one of the reasons it’s worth thinking carefully about permission levels during onboarding. If volunteers only need to read documents, giving them read-only access eliminates the risk altogether.
Where volunteers do need editing rights, Microsoft 365 still provides several safety nets. Deleted files are normally retained in the SharePoint or OneDrive recycle bin for up to 93 days, allowing them to be restored in most situations. Version history also means previous versions of documents can usually be recovered if changes are made in error.
These features provide significant protection, but it’s still good practice to give volunteers the lowest level of access they need. Your IT provider can also configure versioning and other recovery features as part of your Microsoft 365 setup to provide additional reassurance.
Do I need to tell volunteers they have restricted access?
Yes. Being open about permissions helps set expectations from the very beginning and reinforces that good data governance is frankly part of how your organisation works.
A simple explanation during induction is often all that’s needed. For example, you might tell volunteers that they’ll have access to specific Teams, SharePoint libraries and documents relevant to their role, with some resources available as read-only unless they’re involved in a particular project. Framing permissions this way helps volunteers understand that restrictions are there to protect each person, not because they aren’t trusted.
Does this cost extra?
Not necessarily. Many eligible charities can access Microsoft 365 Business Basic licences at no cost through Microsoft’s nonprofit programme, making it an affordable foundation for organisation-managed email, Microsoft Teams and SharePoint.
Volunteers don’t usually require separate licensing in the way many organisations assume. Instead, they access the resources they’ve been granted through your existing Microsoft 365 environment. Additional costs generally only occur if you require advanced functionality such as enhanced auditing, bespoke development or specialist configuration beyond what’s included within your licence.
If you choose to work with a managed IT provider, there may also be a one-off implementation or consultancy cost to design your permission structure and configure your environment. For many charities, that’s a worthwhile investment because it creates a secure, repeatable onboarding process that continues to save time long after it’s been implemented.
What if I’m not sure whether a volunteer should see something?
If you’re unsure, it’s always better to restrict access first and review it later than to grant too much access from the outset.
A useful rule of thumb is to ask yourself whether there is any information within that Team, SharePoint site or shared mailbox that the volunteer doesn’t need to perform their role. If there is, it’s worth exploring a different permission structure before adding them.
These are exactly the kinds of questions your IT team or managed IT provider can help answer. They can review your Microsoft 365 environment, identify areas where sensitive information should be separated and recommend a permission model that supports volunteers without compromising security.
What if I get stuck during onboarding?
That’s exactly what your IT team or managed IT provider is there for.
Even with a well-documented onboarding process, there will occasionally be situations where you’re unsure which permissions to apply, how to organise a new Team or whether a SharePoint site should be restructured. Rather than trying to work it out through trial and error, it’s often quicker and far safer to ask for advice.
At Qlic, we support charities with Microsoft 365 setup, volunteer onboarding, permission reviews, troubleshooting and ongoing user training. Whether you need help configuring a single Team or designing a complete role-based permission structure, we’re here to make the process straightforward. A quick conversation today can save hours of frustration and help ensure your volunteers have exactly the access they need from their very first day.


