Building Security Policies That Reflect How Organizations Work: Lessons from Instituto Lamparina

Lesedi Bewlay

What makes a security policy one that a team still uses  after a partnership ends? That question sat underneath our six-month Matchbox partnership with Instituto Lamparina in Brazil, and it shaped many of the decisions we made together.

The partnership produced an organizational security policy, a responsible data policy covering how data are retained, archived and deleted, and an AI usage policy, each in Brazilian Portuguese and English. The more interesting result, and the one worth writing about, is what the process taught us about what makes a policy hold. Each of the lessons below responds to this opening question.

Instituto Lamparina builds narrative power in Brazil

Instituto Lamparina is a women-led organization that builds narrative power to strengthen democracy in Brazil through a gender, racial and climate justice lens. They weave narrative ecosystems, carry out narrative research and run collective campaigns with partners across the country.

That work involves sensitive information:contact networks built up over years, and material shared in confidence by partners. It also takes place in an environment that includes targeted harassment, doxxing and surveillance. The team arrived at Matchbox with three clear priorities: a data and AI usage policy they could adopt in daily practice, stronger security in the tools they use every day, and a more organized contact database. That clarity shaped the partnership from the first call.

Policies hold when they begin from existing practice

We designed the assessment to describe how the team already works. Interviews, a documentation review, research on the Brazilian legal and political context and a group process mapping session together produced a portrait rather than a score.

The portrait showed an organization that experiments readily with new tools, has consolidated its internal communications deliberately, approaches AI with curiosity rather than either uncritical adoption or blanket refusal, and already tells people what it collects and why. Working from that starting point let us calibrate our recommendations to the risks the team actually faces, and say plainly which practices should stay exactly as they are.

Proportionality became one of the core values written into the policy itself: measures matched to the level of risk, with baseline expectations that apply to everyone and heightened practices reserved for high-risk activities. The same principle guided how we handled the most sensitive material. We examined self-hosted options and offered them as something to pilot narrowly, on the team’s own timeline. One member of the Lamparina team described the resulting analysis as “possible to implement,” which is the response we were designing for.

The broader lesson for other organizations is that a policy holds when it is tailored to how a team already works. A policy written from existing practice asks people to keep doing what they do, but a little more deliberately.

An AI policy works when it meets practice where it already is

By the time we reached the AI usage policy, the team had run their own AI training and were using AI assistants in research work every week. That sequence turned out to be instructive.

It meant the useful questions were specific ones: Which data can go into which tool? What needs verifying before anyone relies on it? What should be recorded? And what does the organization expect of the consultants it works with? Writing a policy at that level of detail gives structure to something already underway, which is the situation most civil society organizations are in by the time anyone sits down to draft one. Recognizing that changes what the document looks like, and changes who reads it.

Very few resources of this kind exist in Brazilian Portuguese. This is the part of the partnership we expect to adapt most often for other partners.

Data governance reaches past an organization’s own boundaries

Partway through, the team raised a question our assessment had not anticipated. Much of their work happens inside partners’ drives, as guests, and ownership of those files sits with whoever owns the drive.

The principle we settled on is that the right of access belongs to the organization rather than to an individual. The responsible data policy now includes a protocol for working in someone else’s environment, along with a short agreement to raise with partners at the start of shared work.

The wider lesson travels well beyond Lamparina. For any organization whose work depends on coalition and collaboration, a data policy that covers only its own systems accounts for part of the picture. The files that matter most may live in someone else’s environment, under someone else’s ownership rules. It is worth asking, at the start of any shared work, where the work will actually live and who will hold access when the collaboration ends.

Handing findings back is itself an intervention

An assessment changes an organization before a single recommendation is implemented. Mapping a team’s practices shows them where their attention goes and what they treat as valuable, and teams understandably approach that process expecting a verdict.

We found the work goes better when we treat the handover as carefully as the analysis. Sharing the framing and core values before drafting the full policy text, naming early which practices need no change at all and returning the synthesis quickly, all shift the conversation from a general sense that everything requires attention toward a clear sense that specific things need care. That shift is what makes implementation possible, and it belongs in the design of the process rather than being left to chance.

Language access shapes what a project can see

This was the first project our project lead had led in a language he does not speak. Interpretation in check-ins, translation of transcripts and documents and colleagues with regional expertise were built into the project from the start.

The value of that went beyond comprehension. Our language colleague asked early on how the organization prefers to be named, which is how we learned to write Instituto Lamparina in formal communications and documentation. Questions of that kind surface assumptions that stay invisible when everyone works in one language. Language support belongs to the method, not to the logistics.

What we carry forward

Lamparina now holds three policies in both working languages, a set of security configuration recommendations and a clear pathway to an organized contact database. The team is working through adoption at its own pace, and our light-touch support remains open to them.

We take forward an approach to AI policy we can adapt for other partners, a stronger read on the Brazilian legal and threat environment, and Portuguese-language material in an area where there is little to draw on. The clearest result, though, is a team with the confidence to keep doing ambitious public work safely, working from documents they helped write and can therefore maintain.

So, what have we learned about designing policies that hold after a partnership ends? They begin from existing practice. They answer the specific questions a team is already asking. They account for work that lives beyond an organization’s own walls. And how findings are handed back matters nearly as much as what they say. None of this guarantees adoption, but it moves a policy from being a document a partnership produced to being a document a team owns.

Want to collaborate?

If you have questions about integrating tech and data more efficiently and securely into your social justice work, get in touch. We are always eager to collaborate with passionate groups committed to social change. You can also schedule a light-touch support call with us.

Read more about our Matchbox program, or read the announcement post from the start of this partnership.

MORE