Everybody's details are publically accessible anyway, I don't see how this database would actually be remotely useful to anyone. It seems like a bunch of paranoia over no real danger.

Why not use existing tried and tested security for accounts from google, etc. Then it is simply a matter of the right levels of compartmentalised access to known members of the organisation. This shouldn't take years to do, it is not rocket surgery.

