| 1 | Map current feedback channels and failures, define the service purpose, accepted categories, urgent exclusions, non-digital alternatives, service times and decision owners. | Portal service owner and secretary | Weeks one and two | A feedback service charter and channel map |
| 2 | Complete a data and risk design covering fields, optional identity, notices, access, platform metadata, data location, retention, deletion, complaints, safeguarding and cyber incident response. | Privacy, governance and cyber reviewers | Before platform selection | A data map, risk register and collection notice |
| 3 | Select or configure the smallest suitable platform, establish club-controlled ownership, multi-factor authentication, least-privilege roles, backups, export and exit, and build accessible form and status pages. | Platform administrator and accessibility lead | Weeks three and four | A controlled portal configuration |
| 4 | Test with keyboard, screen reader, mobile, low bandwidth, plain language and real non-digital users; run privacy, security, acknowledgement, referral, outage and recovery scenarios before launch. | Independent testers and service owner | Before launch | A passed service-readiness checklist |
| 5 | Operate a 90-day pilot, acknowledge submissions, triage by risk and authority, transfer protected matters safely, record decisions and respond through the contributor's chosen channel. | Triage team and decision owners | At least twice weekly | A controlled submission and response register |
| 6 | Review reach, service times, unresolved matters, access barriers, security events, data holdings and delivered improvements; then continue, revise, replace or close the portal and verify export and deletion. | Board sponsor and independent checker | Day 90 | A service review and data close-out decision |