A local nonprofit runs a low-risk community fundraiser with an expected-name list and three trusted helpers at the welcome desk. Donations are handled elsewhere. ArriveList is used only to find expected display names and mark rows through the shared staff link; it does not process payment, validate tickets, or decide who may enter.

Import only the display-name list

The organizer pastes 186 names already expected by the nonprofit. Two guests share the same display name, so both rows remain in their original order. Email addresses, donation amounts, membership status, accessibility needs, and notes stay outside ArriveList.

Use one staff link across the welcome desk

The manager keeps management access private and shares the adjacent staff QR and copy action with the three helpers. Each phone defaults to Not arrived and uses search before marking a row. The shared count helps the team coordinate, but it is not a unique-person count because duplicate names remain separate.

Rotate a staff link that was shared too widely

One helper posts the staff link in a broader volunteer chat by mistake. The manager rotates staff access, sends the replacement only to the desk team, and confirms the old link no longer reveals the event. The private manager link remains valid.

Close and delete after the operational need ends

At the end of check-in, the manager closes the event and confirms that staff mutations stop. The nonprofit uses its own appropriate systems for financial or reporting obligations. When the welcome-desk list is no longer needed, the manager deletes it rather than keeping guest names indefinitely.