One platform, two boundaries
Anonymous visitors and authenticated members have different needs. Public leadership, meetings and documents should be intentionally published. Member profiles, cases, finance and other protected experiences begin with identity and scoped authorization.
Connecting those surfaces to maintained records can reduce duplicate publishing without making internal information public by default.
Test as the audience
Review the site in a signed-out session, then use representative member accounts with ordinary, missing and ineligible records.
- Confirm expired or replaced items disappear as intended.
- Check document and image alternatives.
- Verify record matching and support paths.
- Inspect every enabled member module for unintended visibility.
Treat domains and providers as operational dependencies
A branded site still needs domain ownership, DNS, proxy configuration and renewal responsibilities. Managed automation can help, but the organization must know who owns each external step.
Digital wallet cards similarly depend on tenant configuration and provider approval; they should not be treated as universally active because the member portal exists.