Nonprofit implementation guide
Guide 3: Discover data and integration reality
Map authoritative records, movement, ownership, quality, and failure before configuration hardens.
Trace representative records
For each important record class, identify where it originates, which system is authoritative, how it moves, who can change it, where it is duplicated, and which reports or services depend on it.
Use approved, redacted, fictional, or representative examples until the responsible owners approve a specific data purpose and access boundary.
Write migration and integration rules
Document field mapping, transformation, deduplication, retention, exception handling, reconciliation, frequency, monitoring, retry, and ownership. Mark assumptions that need a rehearsal rather than presenting them as facts.
A successful API response does not prove an end-to-end business result. Test the record, decision, notification, report, and recovery path that people rely on.
Protect reversibility
Define backups, cutover authority, rollback conditions, prior-system access, exception queues, and the time available to restore service. Keep the former operating path available until the acceptance authority closes it.
Protected data and high-impact systems require controls and qualified review appropriate to the organization, information, jurisdiction, and mission context.