Author: Lisa Montague | Category: Practical AI Readiness for Nonprofits

A friend of mine leads technology strategy at a nonprofit. She's sharp, experienced, and exactly the kind of person organizations hope is managing their tech decisions. Last week she sent me a quick note: Work has been busy, she said. Her organization is deep in evaluating AI tools right now — comparing platforms, sitting through demos, trying to figure out what fits.

She mentioned Salesforce Agentforce by name. She mentioned Claude. She's doing her homework.

And she's not alone. This is the conversation I'm having everywhere right now, across organizations of every size. Nonprofit leaders are rolling up their sleeves, doing real research, and trying to make smart decisions about AI.

Here's the thing that keeps me up at night: most of them are jumping to Step 3.

There's a sequence to this. It matters.

At Coat Rack, we've built an AI Readiness framework specifically for nonprofits. It has five steps. They're sequential on purpose, because each one makes the next one possible.

Here's what they are, and here's an honest look at where most organizations actually are.

Step 1: Identify Restricted and Sensitive Information

Before you look at a single vendor, you need to know what information you're responsible for. Which data, if exposed, mishandled, or retained in the wrong place, would cause real harm to the people you serve?

This isn't a compliance exercise. It's foundational. AI risk doesn't begin when someone types into a prompt. It begins when a tool connects or integrates with a live system, or when a feature is switched on without anyone understanding what it can reach.

Most organizations haven't done this mapping. They have a general sense that donor data is sensitive and that client records need to be protected. But they haven't sat down and documented it with the specificity that AI decisions require.

Step 2: Document Current AI Usage

Before you can decide what tools to bring in, you need to know what's already running.

And it's probably more than leadership realizes.

AI doesn't arrive through formal IT requests anymore. It arrives as a feature inside a platform your team already uses. It gets tested by one person and quietly becomes a workflow. It gets switched on by default when a vendor updates their product. Most organizations find, when they actually look, that AI is already woven into their operations in ways nobody formally approved.

You can't govern what you haven't mapped.

Step 3: Evaluate Vendor and Platform Risk

This is where my friend is working right now. This is where almost everyone is.

And platform comparison is genuinely important work. I want to be clear about that. The question isn't whether to do Step 3. It's whether you've done Steps 1 and 2 first, because without them, you don't actually know what you're evaluating.

Here's the specific problem.

Salesforce Agentforce is deeply integrated into Salesforce's CRM. That means it can access your donor records, your communication history, your staff notes, your relationship data. It can be a powerful tool. But the risk profile depends entirely on what's in your CRM, who has access to what, and what your data is connected to.

If you haven't done Step 1, you don't know what's sensitive in there. If you haven't done Step 2, you may not know that AI features are already active inside your Salesforce instance right now, before you've made any formal decision.

So when a vendor shows you "enterprise-grade security" in a demo, they're telling you how your data is stored. They're not telling you what the vendor does with it once they have it. They're not telling you which features access which records, what data is available to plugins, partners, or other integrations, or whether you can selectively turn things off. Most nonprofits don't know to ask those questions, because the questions only become obvious after you've done the groundwork.

"AI-powered" is on every vendor slide right now. What it doesn't say is what those features can reach, what happens to your data, or whether the free tier operates under the same rules as the enterprise contract.

Step 4: Set Your Internal Rules

Once you understand your data landscape and your vendor risk, you can actually make decisions: what's allowed, what's not, who approves new tools, what happens when something goes wrong.

Clear, plain-language decisions. Not a policy document that lives in a shared drive. Rules someone actually communicates directly to the team.

Step 5: Build or Update Your AI Policy

A first draft that reflects what your organization has actually decided. Ready for legal review. Not a ten-page compliance template downloaded from somewhere. A real document your team can use, that reflects your specific situation.

Why Everyone's at Step 3

None of this is about blame. Technology is moving faster than any organization can keep up with, and vendors are doing an excellent job making their tools feel urgent. The pressure to decide is real. The fear of falling behind is real.

But the sequence matters. Skipping to platform comparison before the foundational work is done doesn't just create governance risk. It means you might spend significant resources implementing a tool, only to discover later that it's connected to data you didn't intend to expose, or that your team has been using it in ways nobody approved.

Getting Step 3 right depends on having done Steps 1 and 2. There's no shortcut through that.

Where to start

If your organization is in the middle of an AI platform evaluation right now, that work doesn't have to stop. But it's worth pausing to ask: Do we know what data we're responsible for? Do we know where AI is already running in our existing tools?

If the answer to either question is "not really," that's the place to start.

We built the Nonprofit AI Readiness Toolkit to help organizations work through exactly this sequence. It's free, it's practical, and it's designed for the realities of nonprofit operations, not for enterprise IT departments.

 Download the Nonprofit AI Readiness Toolkit

If you'd rather talk through where your organization is, I'm happy to make time for a free 30-minute conversation. Reach us at  info@coat-rack.io .

The platforms will still be there when you're ready. Getting the foundation right first means you'll actually be ready.


About Coat Rack: We're a nonprofit technology strategy firm helping mission-driven organizations reduce tech chaos and build future-ready technology plans. We serve as the dedicated tech strategist that most nonprofits don't have at the leadership table.