Nonprofits
High-Impact Support for a High-Stakes Small Team
Ten years of executive-level IT partnership with the Jerome L. Greene Foundation
Background
A small team, a big mission, and no room for error
The Jerome L. Greene Foundation invests in the arts, education, medicine, and social justice across New York City — funding institutions from Columbia and Juilliard to reproductive healthcare and community organizations. It does that work with a deliberately small staff and a very large endowment.
That combination — a lean, non-technical team responsible for stewarding hundreds of millions of dollars — defines everything about how the Foundation's technology has to work. There is no internal IT department. There is no room for a security lapse. And there is very little tolerance for technology that demands attention rather than quietly enabling the mission.
Macktez has been the Foundation's technology partner for roughly ten years. What began with periodic onsite visits has grown into a complete, modern IT operation — full device management, single sign-on, cloud-native infrastructure, a comprehensive security suite, and a support relationship that reaches all the way up to personal, direct support for the Foundation's leadership.
The Challenge
High stakes, low tolerance for friction
Small foundations occupy a genuinely difficult position. They control significant assets, which makes them attractive targets, but they rarely have the in-house technical staff that a bank or a large enterprise would bring to bear on the same risk. Every dollar spent on overhead is a dollar not spent on the mission, so the technology has to be lean. And when the people using it aren't especially technical, the security can't depend on users making sophisticated judgment calls under pressure.
For the Jerome L. Greene Foundation, that meant the infrastructure had to be essentially bulletproof by design — secure by default, simple to use, and backed by a partner who could act as the Foundation's IT department, security team, and technology advisor all at once, without ever asking the staff to become any of those things themselves.
The Solution
A complete, modern IT operation — run for them, not by them
Over ten years, Macktez has built and now runs the Foundation's entire technology stack, evolving it from onsite, hands-on support into a fully modern, cloud-native operation:
- Full device management across the Foundation's Mac and iPad fleet via JumpCloud and Addigy MDM, so every device is enrolled, encrypted, patched, and manageable remotely
- Single sign-on and centralized identity through JumpCloud, unifying Google Workspace, Microsoft 365, 1Password, Zoom, DocuSign, Salesforce, and AWS under one governed login
- A comprehensive security suite — centralized password management, DMARC email protection, managed backups for cloud data, and ongoing cybersecurity awareness training for staff
- Cloud-native file infrastructure replacing on-premises servers, with third-party backup protecting against data loss even when a platform provider fails
- Personal, executive-level support — including direct support for Foundation leadership. When an executive has a security concern over a holiday weekend, someone answers the call
Knowing When Not to Be the Vendor
The best recommendation is sometimes someone else
Years ago, Macktez built the Foundation a custom FileMaker database to manage grant and grantee information. It served the Foundation well for a long time. But as the Foundation's needs grew more specialized, Macktez recommended something that not every technology partner would: that the Foundation leave the custom system behind and move to Foundation Source, a platform purpose-built for philanthropic grant management. Macktez helped manage that transition and fully decommissioned the old FileMaker system once the move was complete.
That willingness to recommend a better-fit specialist — even when it means handing work to someone else — has become a defining feature of the relationship. When the Foundation needed specialized web development, Macktez advised on selecting an outside developer with the right expertise rather than forcing a fit. The guiding principle is simple: the Foundation should always have the best tool and the best specialist for the job, whether or not that's Macktez.
AI, Adopted With Intention
New capability, on the Foundation’s terms
Most recently, Macktez guided the Foundation through a structured assessment of how AI could strengthen its work without compromising the trust, privacy, and confidentiality at its core. The approach was governance-first: keeping all data internal and out of external training models, treating every AI output as a first draft requiring human review, and respecting existing permission structures.
Just as important was matching the ambition to the Foundation's real capacity. The team wasn't positioned to take on advanced, autonomous AI agents — and Macktez didn't push them there. Instead, the work focused on what the Foundation could genuinely absorb and benefit from: AI-assisted meeting notes, drafting help for routine correspondence, and querying internal document collections. Practical capability, matched to the organization, rather than capability for its own sake.
Outcomes
What we delivered.
- A complete modern IT operation — MDM, SSO, cloud-native infrastructure, and a full security suite — run on the Foundation's behalf, with no internal IT staff required
- Enterprise-grade security posture protecting a small team responsible for a very large endowment
- A decade-long partnership that scaled from onsite visits to executive-level, always-available support
- Technology decisions consistently made in the Foundation's interest — including recommending outside specialists when they were the better fit
- AI capability adopted deliberately and safely, matched to the organization's real capacity
Punch Above Your Weight
Small team, big responsibility?
We give lean organizations the security posture, modern infrastructure, and senior-level support usually reserved for companies many times their size — without the internal IT department. Let's talk about what your team actually needs.
Let's TalkRelated
To give a lean team enterprise-grade identity, security, and support, these are where to begin:
For the concepts behind this security posture, see our University guides on MFA, least privilege, and directory services:
More identity and security work in action: