Skip to content
Documentation

Administration

Roles & Access

Ecclora separates what someone does in your church from what they can access in the system. The first is a Position. The second is one or more Roles. Keeping them apart means giving someone a title never accidentally grants them access, and giving someone access doesn't require inventing a job title for them.

Positions

A Position is a label, Senior Pastor, Media Director, Usher, and so on. Ecclora comes with a large seeded list across categories like Leadership, Administration, Finance, Ministry, Worship & Production, Member Care, and Children & Youth, and you can add your own if your church uses a title that isn't in the list. A position never grants access on its own.

Roles

A Role is what actually grants access, built from a specific set of permissions. Ecclora ships with twelve standard roles:

RoleCovers
Church AdministratorMembers, ministries, groups, events, content, communications, and user management. Deliberately excludes finance and Pastoral Care.
Member ManagerMember and household records.
Ministry ManagerMinistries, departments, and group leadership.
Content EditorAnnouncements, sermons, media, and pages.
Communications ManagerAnnouncements and communications history.
Finance ManagerFinancial records, giving, and budgets.
Finance ViewerRead-only financial access.
Events ManagerEvent creation, scheduling, and attendance.
Attendance / Check-inRecording attendance at the door.
Pastoral Care CoordinatorPrayer requests, visits, and follow-ups. Standalone access, not bundled with member or ministry access.
AuditorRead-only oversight across members, attendance, finance, and the audit log.
ViewerGeneral read-only access.
Church Administrator is broad, not unlimited. It covers almost everything a day-to-day administrator needs, but it deliberately excludes finance and Pastoral Care. A church administrator who also needs either is assigned Finance Manager, Finance Viewer, or Pastoral Care Coordinator alongside their administrator role, on purpose, not by accident.

If none of the standard roles fit exactly, build a custom role from the same underlying permissions rather than stretching a standard one to cover something it wasn't meant to.

Assigning access

Invite someone under Settings → Users & Roles with their email, a position for reference, and one or more roles. A person isn't limited to a single role, someone can hold Ministry Manager and Finance Viewer at the same time if that's genuinely their job.

Scoped access

Some roles don't have to apply to the whole organization. How far a role can be narrowed depends on what it's for:

AreaCan be scoped to
MembersA campus, a group, or a department.
AttendanceA campus.
GivingA campus.
CommunicationsA campus.
Everything elseOrganization-wide only, for now.

A group- or department-scoped grant works by roster, a Ministry Manager scoped to the Youth Group sees and manages that group's roster, not every group in the organization. The same role can also be granted more than once to the same person across different campuses, groups, or departments, and the picker only ever offers the ones that role is actually allowed to touch.

Events and Content aren't scopable yet, events don't have the underlying structure for it, and Content is a single shared site per organization rather than individual records.

Effective Access

Open any staff member's record to see their Effective Access: every permission they currently hold, and which role granted it, scoped grants included, shown as, for example, “Member Manager (Lekki Campus).” This is the place to check when you need to know exactly what someone can and can't do, rather than reconstructing it from their list of roles.