leftymagazine

Uncompromising journalism for a just planet.

A column by Harrison Lockwood

Mutual aid safety: lessons from our community network

Mutual aid networks often begin with a spreadsheet, a messaging group, and a simple promise: if someone needs food, medicine, transport, rent support, or a safe place to sleep, the community will respond. That speed can save lives.

Harrison Lockwood, Lead Columnist on Systemic Justice & Climate Action·Updated: August 24, 2026·20 min read

Mutual aid safety: lessons from our community network

It can also expose vulnerable people to surveillance, harassment, fraud, doxxing, and physical harm before the group has built even the most basic safety infrastructure.

The central problem is not that grassroots organizers lack technical sophistication. It is that mutual aid operates under permanent pressure. People coordinate during crises, with limited money, exhausted volunteers, urgent requests, and no dedicated security team. Meanwhile, the platforms that offer convenience often monetize personal information, retain records, and create a false sense of safety. A public form may look harmless. A shared document may appear temporary. Neither assumption deserves trust.

Mutual aid network safety protocols cannot be an afterthought added once something goes wrong. They have to shape how a network collects information, assigns work, communicates with volunteers, handles money, and decides what it will never publish.

Data minimization is the first security measure

The most reliable way to protect sensitive information is not to collect it.

That sounds obvious until a network starts designing an intake form. Suddenly, every field seems defensible. Full names. Home addresses. Phone numbers. Household size. Immigration status. Medical conditions. Income. Disability information. Proof of need. Emergency contacts. Photos of identity documents. The form becomes a bureaucratic machine built in the name of solidarity.

Most of that data does not belong in the system.

The Electronic Frontier Foundation has consistently emphasized data minimization for organizers: collect the smallest amount of personal information necessary to provide the service, and do not retain it simply because a platform makes storage easy. Every additional field creates another possible disclosure. Every retained record expands the damage a hostile actor, careless volunteer, compromised account, or subpoena could cause.

A mutual aid network should ask a blunt question before collecting any information: what decision does this data enable?

If the answer is unclear, the field should disappear. If the service requires a delivery location, the network may need an address for a limited period. It probably does not need a participant’s legal name, date of birth, or documentation status. If volunteers need to know dietary restrictions, they may need the relevant restriction—not a medical history. If a person needs cash assistance, the group may need a payment method, but not a permanent financial profile.

A practical data-minimization policy usually includes several commitments:

  • Collect only the information required for the immediate task.
  • Separate identifying information from service details whenever possible.
  • Set a deletion schedule before collecting the data, not after.
  • Restrict access by role rather than giving every volunteer the full database.
  • Avoid copying sensitive information into multiple chats, documents, and personal devices.
  • Never publish participant information without explicit, informed permission.
  • Explain to people what the network collects, who can access it, and when it will be deleted.

The deletion rule matters because storage creates institutional memory that grassroots groups rarely have the capacity to protect. A volunteer may leave. A password may be reused. A device may be lost. A shared document may remain accessible to someone who no longer participates. The network may dissolve, while its records continue circulating.

Data is not neutral infrastructure. In the hands of a vulnerable community, unnecessary data becomes a liability with a deadline attached.

Data minimization also protects organizers. Volunteers often become informal data custodians without realizing it. They download lists, save phone numbers, photograph receipts, and forward screenshots because the work feels urgent. But an activist network safety plan that depends on every volunteer making perfect decisions under pressure is not a plan. It is wishful thinking with better branding.

The system should make the safer action the easier action: limited fields, limited access, short retention periods, and clear rules for deletion.

What a safer intake process looks like

The strongest intake forms are often shorter than organizers expect. They distinguish between information needed to decide whether a request can be fulfilled and information that is merely interesting, convenient, or familiar from institutional forms.

A group arranging grocery deliveries may need a way to contact the recipient, a delivery area, dietary constraints, timing, and any access issue that affects the handoff. It does not automatically need a scan of an identity document or a detailed account of the household’s finances. A tenant-support project may need the type of problem and a safe way to communicate. It may not need to retain every document exchanged during an initial conversation.

There should also be a difference between operational notes and case histories. An operational note helps a volunteer complete a defined task. A case history accumulates context over time and is therefore more sensitive. If a network does not have the capacity to protect a long-term case-management system, it should avoid quietly creating one through scattered messages and folders.

Retention should be understandable to participants and realistic for volunteers. A rule that requires complicated manual deletion across several systems will fail. Fewer copies and fewer storage locations are often more protective than an elaborate policy no one can follow.

Commercial convenience is not secure infrastructure

Many mutual aid networks rely on familiar commercial platforms because those platforms are cheap, accessible, and already installed on everyone’s phone. That practical reality matters. A security policy that requires expensive hardware, specialist software, or advanced technical knowledge will exclude the very people the network needs to reach.

But convenience does not equal protection.

A website using HTTPS encrypts data in transit between a browser and a server. That does not mean the service provides end-to-end encryption. It does not automatically protect information from the platform operator, account administrators, compromised accounts, malicious insiders, or other forms of access built into the service. A public spreadsheet is not a secure case-management system simply because the link is difficult to guess. A private social-media group is not private in any meaningful political sense if the platform controls the infrastructure and records the activity.

The Berkeley Center for Long-Term Cybersecurity and Fight for the Future produced Securing Mutual Aid, a guide focused on cybersecurity practices and financial technology for grassroots groups. Its basic implication is difficult to avoid: community networks need to treat digital infrastructure as part of organizing strategy, not as a neutral set of tools.

That does not mean every group needs to abandon every commercial platform overnight. It means organizers should classify information before choosing where it belongs.

Information typeSuitable handlingWhy it matters
Public event detailsPublic website or social channelExposure creates limited risk when the information is intentionally public
Volunteer schedulingAccess-controlled tool with minimal identifying dataVolunteers need coordination, not unrestricted visibility
Sensitive participant informationRestricted system with strong access controls and encrypted communicationDisclosure may expose people to state, employer, landlord, family, or community retaliation
Financial assistance recordsDedicated financial process with multi-factor authentication and limited administratorsFinancial data can enable fraud, coercion, and identity exposure
High-risk organizing discussionsEnd-to-end encrypted messaging with strict device and account practicesThe platform should not hold readable copies of sensitive conversations

For sensitive communications, organizing guidance commonly recommends moving beyond transport-layer encryption on commercial platforms and using end-to-end encrypted services such as Signal. That transition only works if the group also handles the surrounding risks: device security, disappearing messages, account recovery, contact verification, and the possibility that someone’s phone is seized or accessed by another person.

Signal cannot protect a phone that remains unlocked on a kitchen table. Two-factor authentication cannot compensate for a volunteer sharing credentials. A secure application does not solve the problem of putting a participant’s full name, address, and immigration status into a message that five unrelated people can read.

Security is a chain of decisions, not a brand choice.

Financial tools deserve particular scrutiny. Mutual aid groups may process donations, reimbursements, emergency transfers, and purchases through systems designed for commercial transactions rather than community protection. Organizers should limit the number of people with administrative access, enforce multi-factor authentication, separate personal and organizational accounts, and maintain clear approval procedures for payments.

They should also understand transaction risk rather than treating digital finance as frictionless. Even in the world of trading platforms, where the stakes and incentives differ, lessons from platform slippage turning small technical assumptions into material financial losses show why tools should be understood, not trusted by default. Mutual aid organizers do not need to imitate trading systems. They do need the same basic discipline: know what the tool does, what it records, what it cannot guarantee, and who absorbs the loss when it fails.

Moving platforms without losing people

A platform transition can create its own risks. If a group suddenly closes a familiar channel, participants may lose access, miss a delivery, or move to unofficial spaces where no one knows who has administrative control. Security work that ignores accessibility is not neutral; it transfers the burden to people with less time, less bandwidth, or less reliable connectivity.

A careful transition separates public information from sensitive coordination. The public channel can explain where general updates will appear. Trusted coordinators can contact people individually about changes that affect their participation. New tools should be tested with a small group before they become the only route to support.

Every transition should answer a few practical questions:

  • What information is being moved, and what can be left behind?
  • Who has administrative access to the old and new systems?
  • How will participants verify that a new account or channel is genuine?
  • What happens to people using older phones, shared devices, or limited data plans?
  • How will the group recover access if a coordinator is unavailable?
  • Which conversations should not be migrated at all?

The aim is not technological purity. It is to reduce unnecessary exposure while keeping the network usable.

Threat modeling turns fear into decisions

Grassroots groups sometimes approach security in one of two unhelpful ways. They assume nobody cares enough to target them, or they imagine an unlimited threat capable of defeating every measure. The first produces negligence. The second produces paralysis.

Threat modeling offers a more useful route. It asks what the network is protecting, from whom, and under which conditions.

A community group does not need to predict every possible attacker. It needs to identify credible threats and prioritize the material harms they could cause. The answers will differ between a neighborhood food distribution project, a climate direct-action campaign, a migrant support network, and a tenant union. Their security measures should differ too.

A basic threat model should examine:

1. The assets. These may include participant identities, addresses, health information, donor records, volunteer schedules, payment accounts, internal discussions, or evidence of political activity.

2. The adversaries. Possible actors include abusive partners, employers, landlords, online harassers, far-right groups, scammers, hostile officials, data brokers, or simply an unauthorized volunteer with access to more information than they need.

3. The points of exposure. Look beyond the central database. Risks often enter through personal phones, shared passwords, public photos, delivery routes, email forwarding, social-media posts, donation platforms, and printed lists left in cars or community spaces.

4. The consequences. A breach may cause inconvenience. It may also result in eviction, job loss, immigration consequences, violence, stalking, financial theft, or the collapse of trust that keeps the network functioning.

5. The available protections. These can include data deletion, role-based access, encrypted messaging, two-factor authentication, pseudonyms, separate accounts, buddy systems, incident procedures, and restricted public communications.

The goal is not to create a perfect fortress. The goal is to make deliberate trade-offs rather than drifting into exposure because a platform’s default settings made decisions for the group.

For example, a network supporting people facing domestic violence should treat addresses and phone numbers as high-risk data. A climate campaign planning civil disobedience should separate public mobilization from sensitive operational discussions. A food-distribution project may need a route and a delivery contact, but not a permanent record of every recipient. A group assisting undocumented workers should assume that documentation and identity information could create serious harm if disclosed, and should design its intake process accordingly.

This is where mutual aid volunteer vetting becomes more complicated than a background check. Formal screening may be impossible, legally inconsistent, or inaccessible to a volunteer-run group. Trust matters, but trust cannot mean unrestricted access. A person can be welcomed into the network without being given every participant record, financial credential, or operational detail.

A safer structure uses graduated access:

  • New volunteers begin with bounded, supervised tasks.
  • Sensitive deliveries or direct support involve at least two people where appropriate.
  • Financial authority remains with a small, accountable group rather than one individual.
  • Access changes when a volunteer changes roles or leaves.
  • The network keeps a simple process for reporting suspected breaches, harassment, lost devices, and unsafe conduct.
  • People know whom to contact when they need help, without having to disclose the problem publicly.

These measures are not an attempt to turn mutual aid into a police department. They recognize that solidarity requires accountability. A group that refuses to discuss internal risk often shifts the cost of its informality onto the people with the least power to absorb it.

Vetting without reproducing institutional gatekeeping

Volunteer screening can easily become either meaningless or exclusionary. A demand for extensive personal documentation may be impossible for people whose lives already involve surveillance, unstable housing, or insecure immigration status. At the other extreme, accepting everyone into every role because the group wants to appear welcoming creates preventable vulnerabilities.

The useful question is not whether a volunteer is permanently “safe.” It is what access is appropriate for a particular task at a particular point in the relationship.

A new volunteer may start with public-facing work, supply sorting, translation, or supervised deliveries. More sensitive roles can require additional training, references from trusted members, or a longer period of participation. The standard should be proportional to the risk, and the process should be explained rather than treated as a secret test.

Groups should also distinguish between accountability and punishment. If a volunteer makes a mistake, the response should address the harm, preserve the safety of participants, and prevent repetition. If someone deliberately seeks information they do not need, pressures participants, or violates boundaries, the network needs a way to restrict access and support those affected.

No screening process replaces supervision. No reference replaces role-based permissions. A person who has earned trust in one context does not automatically need access to every part of the network.

Physical safety belongs in the operating model

Digital security receives more attention because it can be discussed from a laptop. Physical safety remains less glamorous and more consequential.

Distribution sites, food deliveries, medicine runs, protest support, and emergency housing coordination all create physical exposure. Volunteers may work at night, enter unfamiliar buildings, carry cash or supplies, transport people, or interact with individuals whose circumstances they cannot independently verify. Participants may face danger from family members, landlords, law enforcement, immigration authorities, hostile groups, or unsafe environments.

The response should begin before the first distribution day. Mutual aid toolkits recommend establishing explicit physical safety and sanitation protocols at the outset rather than relying on informal habits that vary from volunteer to volunteer.

That means defining how the network handles:

  • Site access and exit routes.
  • Contactless or low-disclosure deliveries.
  • Buddy systems and check-in procedures.
  • Transport, especially for people at heightened risk.
  • Cash handling and supply movement.
  • Weather, heat, cold, fire, and other environmental conditions.
  • Medical emergencies and overdose response.
  • Harassment, threats, and hostile surveillance.
  • Food handling, protective equipment, and sanitation.
  • The separation of public-facing volunteers from sensitive case information.

The point is not to build a rigid command structure. It is to remove ambiguity when conditions become dangerous. Under stress, people do not reliably invent good procedures. They fall back on whatever the group established beforehand—or whatever seems fastest.

Sanitation deserves the same seriousness as digital security. During a health emergency, a distribution network can unintentionally spread infection if it treats cleaning, ventilation, food handling, and protective equipment as optional expressions of personal preference. The people most dependent on mutual aid may also face the greatest health risks. A careless operation can harm the community it intends to support.

Physical safety protocols also need to account for power inside the network. A volunteer coordinator who demands a participant’s private address, insists on unsupervised transport, or dismisses a safety concern can create risk even without malicious intent. Networks need a culture where people can refuse an assignment, request a second volunteer, or change a delivery method without being accused of betraying the cause.

That culture has a material function. People who fear social punishment will conceal incidents. Concealed incidents become repeated incidents. Repeated incidents drive away the volunteers and participants who most need protection.

Make safety operational, not aspirational

A protocol is useful only if a tired volunteer can follow it during a difficult shift. Long policy documents have their place, but the operating version should be brief enough to consult quickly and specific enough to guide action.

For a delivery network, that might mean confirming the safest contact method, sharing only the information needed for the route, checking in at agreed points, and documenting an incident without copying sensitive details into a public channel. For a distribution site, it might mean identifying who can pause operations, where people can leave, and how the group responds to a threat or medical emergency.

The network should also plan for ordinary failures:

  • A volunteer loses their phone.
  • A coordinator becomes unreachable.
  • A participant says the planned handoff is no longer safe.
  • Cash or supplies go missing.
  • A screenshot containing sensitive information is sent to the wrong person.
  • Someone appears at a site asking for names or access.
  • A volunteer experiences harassment or injury.

None of these situations requires a dramatic response in every case. All of them require someone to know what happens next. Incident response is not an admission that the network has failed. It is a way to keep one mistake from becoming a system-wide crisis.

Publicity can help a movement—and expose its infrastructure

Grassroots groups need visibility to recruit volunteers, raise money, distribute information, and build political leverage. Public communication is not the enemy. Uncontrolled amplification is.

A directory that lists local mutual aid groups may appear useful to journalists, donors, and people seeking support. It may also reveal where organizers meet, which communities they serve, how frequently they operate, and who can be approached for information. A photograph from a distribution site can identify a participant who expected privacy. A celebratory post can disclose the location of a shelter or the schedule of a delivery operation. A fundraiser can expose the names of people receiving assistance if the group does not design the campaign carefully.

Ethical amplification starts with consent that is specific and informed. Someone agreeing to have their story shared with a small organizing team has not necessarily agreed to appear on a public account. Someone accepting a photograph at an event may not understand that it will be searchable indefinitely. Consent should account for audience, platform, permanence, and the possibility of hostile interpretation.

The safest default is to publicize the work rather than the people who depend on it. Organizers can describe a need, a campaign, or a political demand without revealing the names, faces, addresses, or personal histories of participants. When a story is important to the movement, the person involved should be able to set boundaries, review the material where practical, and withdraw without losing access to support.

Public communication should also avoid operational detail. A network can announce that it distributes food without publishing a live schedule, storage location, delivery route, or list of partner sites. It can recruit volunteers without explaining exactly which coordinator handles sensitive cases. It can report how donations were used without exposing individual recipients.

Visibility should strengthen collective power, not turn vulnerable people into evidence that the movement is working.

The same discipline applies to group privacy. Public channels should not be used to discuss individual cases. Internal channels should have clear membership, limited forwarding, and a process for removing people who leave. Screenshots should not be treated as harmless documentation. They can preserve names, profile photographs, phone numbers, timestamps, and context that the original sender never intended to travel.

Networks should decide in advance:

  • Who can speak publicly on behalf of the group.
  • Which information is always off-limits.
  • How participant stories and images are approved.
  • Whether public posts reveal locations, schedules, or partner organizations.
  • How donations and expenses are reported without exposing recipients.
  • What happens when a journalist, researcher, influencer, or political organization requests access.
  • How the group responds to doxxing, impersonation, harassment, or a hostile information request.

These are political decisions as much as communications decisions. A movement that treats every audience as an opportunity for growth may end up making its most vulnerable members carry the cost of expansion.

Building a safety culture that can survive the crisis

Security work is often framed as a set of tools: an encrypted messenger, a password manager, a locked folder, a private account. Tools matter, but they cannot compensate for unclear responsibility or a culture that rewards speed at any cost.

A sustainable safety practice distributes knowledge. At least more than one person should understand critical accounts, payment procedures, emergency contacts, and the process for changing access. At the same time, distributing knowledge does not mean distributing every secret to everyone. The group needs continuity without creating a large pool of unnecessary access.

Training should be practical and recurring. New volunteers need to know what information they will receive, what they should not record, how to report a concern, and how to contact someone safely. Existing volunteers need opportunities to revisit the rules when the network changes its services, tools, or physical locations.

The group should review its procedures after incidents and near misses, not only after a major breach. A near miss can reveal that a form collects too much, that a public channel is being used for casework, or that volunteers are unclear about who can approve a payment. Treating those moments as learning opportunities is more useful than treating them as individual failures.

Safety also needs to remain connected to the politics of mutual aid. Surveillance is not distributed equally. A public post that creates little risk for one volunteer may expose another person to detention, eviction, family violence, workplace retaliation, or targeted harassment. A policy that looks “neutral” on paper can reproduce those differences if it assumes everyone has the same ability to secure a device, refuse disclosure, travel to a meeting, or challenge a coordinator.

That is why the best community mutual aid guidelines do more than protect systems. They protect people’s ability to participate without surrendering control over their identity and circumstances.

Mutual aid cannot remove every danger produced by poverty, state violence, housing insecurity, ableism, racism, or criminalization. It can refuse to add avoidable danger through careless administration. It can collect less, share less, retain less, and make fewer people responsible for information they never needed. It can build procedures that respect both urgency and consent.

The work will never be perfectly secure. That is not an argument for abandoning security. It is an argument for making honest, proportionate choices: identify the people and information at risk, reduce exposure where possible, prepare for mistakes, and keep the system accountable to those it exists to support.

A mutual aid network becomes safer not when it looks professional, but when its infrastructure reflects its politics. Care should extend to databases, group chats, delivery routes, payment accounts, public photographs, and the quiet decisions about who gets to know what. Solidarity is not only the promise to show up. It is the discipline of showing up without making people more vulnerable in the process.

FAQ

Why is data minimization considered the most important security measure?
Data minimization is the most reliable protection because information that is never collected cannot be leaked, subpoenaed, or misused. Every additional data field creates a new point of vulnerability for participants.
Should mutual aid groups stop using commercial platforms for coordination?
Not necessarily, but organizers should classify information before choosing a platform. Sensitive communications should be moved to end-to-end encrypted services, while public-facing work can remain on more accessible tools.
How can a network vet volunteers without creating exclusionary barriers?
Instead of demanding extensive documentation, networks should use graduated access. New volunteers can start with low-risk, supervised tasks, while more sensitive roles are reserved for those with established trust and additional training.
What should be included in a basic threat model for a community group?
A basic threat model should identify the assets being protected, potential adversaries, specific points of exposure, the potential consequences of a breach, and the available protections the group can realistically implement.
How should mutual aid groups handle participant stories in public communications?
Groups should prioritize publicizing the work rather than the people involved. Consent must be specific and informed, and organizers should avoid revealing names, faces, addresses, or personal histories that could expose participants to retaliation.