Security for booster clubs, PTAs, band and orchestra parent groups, and every other volunteer-run organization that moves real money with no IT department. Written for the treasurer with a day job, in 2026, when the scam calls sound exactly like your president.
A high school band booster program can move six figures a year: trips, uniforms, instruments, concessions, fundraisers. It runs on a shared Gmail, a spreadsheet, a Venmo, and volunteers who hand everything to strangers every June. Fraudsters know all of this. This repo is the defense, and every control in it is free.
The internet will tell you to fear hackers. The loss data for volunteer organizations says something more uncomfortable: the two big risks are payment fraud, fake invoices and impersonated presidents, and misuse by a trusted insider with no oversight. The same small set of controls, two people on the money, verification before payment, and sunshine on the books, handles both, without accusing anyone of anything. Nothing You Can't Check is a kindness in a volunteer org, it protects the honest treasurer as much as the funds.
More in PRINCIPLES.md.
- Booster club boards: band, orchestra, choir, athletics, robotics, theater
- PTAs and PTOs, youth sports leagues, scout units, church committees
- The incoming treasurer who just inherited a binder and a bad feeling
- School administrators who want to hand their parent orgs something better than good luck
Schools and districts themselves, you have IT departments and regulations this deliberately skips.
Anybody looking for accounting or tax guidance. Your state association and a CPA own the 501(c)(3) rules; this repo stops at security.
- Two people on every payment. No single person, however trusted, moves money alone.
- Verify before you pay. Any new or changed payment request gets a call to a number you already had. The full protocol is a sibling repo; the club version fits on an index card.
- The club owns its accounts, not the volunteers. Email, bank, socials, and website belong to roles, live in a shared password manager, and survive every June.
- Sunshine on the books. Reconciled numbers at every meeting, bank statements visible to more than one person.
- Keep less kid data, guard what you keep.
| File | What it is |
|---|---|
the-treasurers-page.md |
The money controls, and why they protect the treasurer most of all |
accounts-and-handover.md |
Surviving June: role-owned accounts and the officer transition |
scams-that-target-clubs.md |
The actual repertoire, president gift cards to fake trip invoices |
families-and-kids-data.md |
Rosters, medical forms, photos, and posting less |
events-and-fundraisers.md |
Concessions, QR codes, Square readers, and cash with two humans |
Not legal, tax, or accounting advice, and your state's rules on raffles, gaming, and charitable registration are real, ask your state association or a professional. Not a district policy, where your school has rules, theirs win.
Nothing here comes from a client engagement or any specific club.
Want: the scam your club actually saw, scrubbed to the pattern. Handover checklists that survived a real June. State-specific wrinkles, labeled as such.
Nothing club-identifiable, nothing about specific kids or schools, ever. See CONTRIBUTING.md.
CC BY 4.0. Copy it into your club binder, print it for the board, share it at the district roundtable. Just say where you got it.
© 2026 Harrison Ward
Cyber risk and technology exec, and a band parent. This repo exists because I watched volunteer organizations handle real money with none of the protections any business would consider mandatory, and realized nobody had ever written them down for a treasurer with a day job.
github.com/HarrisonWard · LinkedIn
Published under these principles. Security Shouldn't Be Paywalled.