Event attendee access controls
Volunteers, committee members and suppliers all have a login to the registration system, and no one knows which of them still need it.
The short answer
Decide access by role: for each person or group, which attendee data they need, in what form and until when. Write it as a table, give each person only that, and remove it on a set date.
The technical settings are for your IT or privacy reviewer. This page gives you the access sheet and the questions.
Roles first, names second
Most events need only four or five roles: secretariat administrator, committee reviewer, desk volunteer, supplier with a task, and sponsor or partner if a separate decision has been made.
Give each role the least data that does the job. A desk volunteer needs name, organisation and ticket status, not dietary needs or contact numbers.
Access sheet
| Role | Needs to see | Does not need | Form of access | Ends on |
|---|---|---|---|---|
| Secretariat administrator | Full registration data | Nothing withheld, but named individuals only | Platform login with individual accounts | Event close and review |
| Committee reviewer | Counts and summaries | Individual contact details | Summary report | Event end |
| Desk volunteer | Name, organisation, ticket status | Dietary, phone, payment details | Search-only role or printed list | End of event day |
| Caterer | Dietary category counts | Names | Extract | Delivery date |
Joiners, leavers and shared logins
- Give every person an individual account. Shared logins cannot show who did what.
- Review the access list a week before the event and again the day after.
- When a volunteer or committee member leaves, remove access the same day.
- Ask your IT or privacy reviewer about stronger sign-in settings for administrators.
Related decisions
Spreadsheet extracts are covered in confidential spreadsheet sharing. What you collect in the first place is in the data minimisation checklist. Where access has been removed, record it in the deletion handover.
Worked example · Fictional example
A fictional secretariat cuts 14 logins to six
Fictional organisation and figures, for illustration only.
Persatuan Fiktif Perancang Bandar had 14 people with registration system access for a 240-delegate event, including three past volunteers and two committee members who only wanted totals.
The secretariat sets four roles, gives the two committee members a weekly summary report instead of a login, removes the past volunteers, and issues three desk volunteers a search-only role that expires the day after the event. Six logins remain, each in an individual name.
Use this yourself
Attendee access review checklist
Complete this a week before the event and the day after. Keep both copies.
- List of everyone with access today (name, role, date given):
- Role each person actually needs:
- Data each role needs and does not need:
- Shared logins found and replaced with individual accounts:
- People who no longer need access, removed on (date):
- Administrators' sign-in settings put to IT or privacy reviewer on (date):
- End date set for each temporary role:
- Supplier access listed, with named contact on their side:
- Access reviewed again the day after the event on (date):
- Open items passed to the deletion handover:
Handle it in-house, or bring in help?
Your team can usually handle this when
- A small team and a registration tool with roles you can set.
- One administrator who can keep the list.
- A reviewer who has seen your settings.
Outside planning help earns its fee when
- Many volunteers, committees and suppliers need different views.
- Access has built up over several years and no one knows who has what.
- You want access rules written into supplier requirements and the event handover.
Want the access rules agreed before registration opens?
An Event Blueprint can set out roles, the data each needs, end dates and who reviews the list, and write these into supplier requirements. Technical settings stay with your IT or privacy reviewer.
Questions organisers ask
Should committee members see the full attendee list?
Ask what decision they need to make. Often counts and summaries are enough.
Can volunteers share one login on the day?
Shared logins hide who did what. Ask your reviewer about alternatives such as individual search-only accounts.
Who reviews the access list?
A named person in the organisation, usually the secretariat head, with IT or privacy review where available.
Related resources
Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.