SanctuaryDOCS
Open App
Role Matrix

Role-Permission Matrix

Access:Super AdminLead Pastor

This page documents the complete permission matrix for every role in SanctuaryOS across every module. Use this reference when deciding which role to assign to a user. Permissions are derived from the @Roles decorators in the API controllers.

Flock Module (Members & Households)

Color: #2563EB Blue

RoleAccess LevelDetails
Super AdminFullAll members, households, profiles, engagement, children, onboarding, import/export
Lead PastorFullAll member data, campus-scoped
PastorFullAll member data, campus-scoped
ElderFullAll member data, campus-scoped. No financial data.
Finance AdminRead-onlyMember/donor lookup for giving entry. Cannot edit member profiles.
Finance UserRead-onlyDonor lookup during session entry only
Reporting OnlyNoneNo direct Flock access (sees member names in reports only)
Flock LeaderScopedOnly assigned members. Configured in Flock Leader Scopes settings.
Worship LeaderNoneNo Flock access
Team LeaderNoneNo Flock access
VolunteerNoneNo Flock access
Small Group LeaderNoneNo direct Flock access (sees group members in Circles)
Care MinisterNoneNo direct Flock access (sees care recipients in Care)
Care Read OnlyNoneNo Flock access
Campus AdminNoneSettings management only, no module data

Steward Module (Giving & Finance)

Color: #059669 Green

RoleAccess LevelDetails
Super AdminFullAll sessions, transactions, deposits, statements, reports, corrections, import, merge, bulk actions, accounting sync
Lead PastorRead-onlyCan view sessions, transactions, reports. Cannot enter or modify financial data.
PastorRead-onlySame as Lead Pastor. View-only access to financial data.
ElderNoneNo financial data access of any kind
Finance AdminFullAll Steward operations: session entry, posting, deposits, corrections, reports, statements, import, merge, bulk actions, accounting sync. Mandatory MFA.
Finance UserLimitedSession entry and posting only. Cannot access deposits, statements, corrections, import, merge, or accounting sync.
Reporting OnlyRead-onlySteward reports and dashboards only. No data entry.
Worship LeaderNoneNo Steward access
Team LeaderNoneNo Steward access
VolunteerNoneNo Steward access
Flock LeaderNoneNo Steward access
Small Group LeaderNoneNo Steward access
Care MinisterNoneNo Steward access
Care Read OnlyNoneNo Steward access
Campus AdminNoneNo Steward access

Gather Module (Attendance & Check-In)

Color: #D97706 Amber

RoleAccess LevelDetails
Super AdminFullDashboard, calendar, check-in, attendance records, Order of Service, alerts, reports, children's check-in, lifecycle management
Lead PastorFullAll Gather operations including service lifecycle (start/complete/cancel)
PastorFullAll Gather operations including service lifecycle
ElderEditDashboard, calendar, check-in, attendance records, reports. Cannot manage service lifecycle (start/complete/cancel).
Check-In OperatorCheck-in onlyCheck-in console operations: check in members, undo check-ins, manage children's check-in. No access to records, reports, or lifecycle.
Reporting OnlyRead-onlyDashboard and reports only. No check-in or editing.
Worship LeaderNoneNo Gather access (Order of Service read access is via Serve)
Finance AdminNoneNo Gather access
Finance UserNoneNo Gather access
Team LeaderNoneNo Gather access
VolunteerNoneNo Gather access
Flock LeaderNoneNo Gather access
Small Group LeaderNoneNo Gather access
Care MinisterNoneNo Gather access
Care Read OnlyNoneNo Gather access
Campus AdminNoneNo Gather access

Serve Module (Volunteers & Scheduling)

Color: #9333EA Purple

RoleAccess LevelDetails
Super AdminFullAll teams, scheduling, CCLI reporting, blackout management, arrangements, confirmations, requests
Lead PastorFullAll Serve operations, scheduling, blackouts, confirmations, requests
PastorFullAll Serve operations, scheduling, blackouts, CCLI read
Worship LeaderFullFull Serve module: setlists, service plans, arrangements, CCLI, scheduling
Team LeaderScopedFull schedule and roster access for assigned team(s). Can manage blackouts, CCLI, arrangements, confirmations, and requests for their teams.
VolunteerOwn onlyView own schedule, confirm/decline availability. Can respond to confirmations.
ElderNoneNo Serve access
Finance AdminNoneNo Serve access
Finance UserNoneNo Serve access
Reporting OnlyNoneNo Serve access
Flock LeaderNoneNo Serve access
Small Group LeaderNoneNo Serve access
Care MinisterNoneNo Serve access
Care Read OnlyNoneNo Serve access
Campus AdminNoneNo Serve access

Circles Module (Small Groups)

Color: #E11D48 Rose

RoleAccess LevelDetails
Super AdminFullAll groups, members, health scores, attendance, join requests, leader assignments, categories, archiving
Lead PastorFullAll Circles operations
PastorFullAll Circles operations
Flock LeaderEditCan edit groups and members (elevated from base role)
Small Group LeaderScoped editCan edit their assigned group(s): manage members, record attendance, handle join requests
ElderViewCan view all groups, members, and reports. Cannot edit.
Reporting OnlyViewCan view groups and reports. Cannot edit.
Finance AdminNoneNo Circles access
Finance UserNoneNo Circles access
Worship LeaderNoneNo Circles access
Team LeaderNoneNo Circles access
VolunteerNoneNo Circles access
Care MinisterNoneNo Circles access
Care Read OnlyNoneNo Circles access
Campus AdminNoneNo Circles access

Care Module (Pastoral Care)

Color: #16A34A Green

RoleAccess LevelDetails
Super AdminFullAll care cases, interactions, milestones, prayer requests, visitation, ministry areas, settings
Lead PastorFullAll Care operations
PastorFullAll Care operations
Care MinisterScoped editCan create and edit care cases, record interactions, manage prayer requests within assigned ministry area
Flock LeaderEditCan create and edit care cases (elevated from base role)
ElderViewCan view care cases and reports. Cannot create or edit.
Reporting OnlyViewCan view care reports. Cannot create or edit.
Care Read OnlyViewRead-only access to all Care data. Cannot create or modify records.
Finance AdminNoneNo Care access
Finance UserNoneNo Care access
Worship LeaderNoneNo Care access
Team LeaderNoneNo Care access
VolunteerNoneNo Care access
Small Group LeaderNoneNo Care access
Campus AdminNoneNo Care access

Services (Cross-Module View)

Color: #4F46E5 Indigo

RoleAccess LevelDetails
Super AdminFullSees all three data types: giving, attendance, volunteers
Lead PastorFull (read)Sees giving (read-only), attendance, and volunteers
PastorFull (read)Sees giving (read-only), attendance, and volunteers
ElderPartialSees attendance and volunteers only. No giving data.
Finance AdminPartialSees giving data only. No attendance or volunteer data.
Finance UserPartialSees giving data only. No attendance or volunteer data.
Reporting OnlyPartialSees giving data only. No attendance or volunteer data.
Worship LeaderPartialSees volunteer data only. No giving or attendance.
Team LeaderPartialSees volunteer data only. No giving or attendance.
VolunteerNoneNo Services page access
Flock LeaderNoneNo Services page access
Small Group LeaderNoneNo Services page access
Care MinisterNoneNo Services page access
Care Read OnlyNoneNo Services page access
Campus AdminNoneNo Services page access

Settings

RoleAccess LevelDetails
Super AdminFullAll settings: church profile, campuses, branding, users, custom fields, service patterns, rooms, plan templates, lookup tables, communication
Lead PastorFullAll settings except system-level configuration
Campus AdminCampus-scopedCampus management, user assignment at their campus. Cannot modify church-wide settings.
Finance AdminPartialChurch profile (for receipt settings), lookup tables (payment methods), fund accounts
All other rolesNoneNo settings access

Quick Reference: Role Summary

RoleFlockStewardGatherServeCirclesCareSettings
Super AdminFullFullFullFullFullFullFull
Campus AdminScoped
Lead PastorFullReadFullFullFullFullFull
PastorFullReadFullFullFullFull
ElderFullEditViewView
Finance AdminReadFullPartial
Finance UserReadLimited
Reporting OnlyReadReadViewView
Flock LeaderScopedEditEdit
Small Group LeaderScoped
Team LeaderScoped
Worship LeaderFull
VolunteerOwn
Care MinisterScoped
Care Read OnlyView
Check-In OperatorCheck-in

Related Pages

PreviousCreating Users
NextCustom Fields