Roles & Permissions
Audience: This article is for church administrators.
Roles in TimelyChurch control what each team member can see and do within your church's admin panel. Every team member is assigned exactly one role, and that role determines which modules they can access, which actions they can perform, and whose records they can view.
Accessing Roles & Permissions
- Navigate to Team in the left sidebar.
- Click the Manage Roles button on the Team page.
The Roles page opens at Dashboard / Settings / Team / Roles (you can see this trail in the breadcrumb at the top of the page).
Understanding the Role System
Each role in TimelyChurch is defined by three components:
1. Modules
Modules are the features a role can access. Each module has its own set of actions that can be individually granted. The table below lists the available modules and their actions:
| Category | Module | Actions |
|---|---|---|
| People & Families | People & Families | view, create, edit, delete, import, export |
| Follow-Ups | view, create, edit, delete, assign | |
| Families | view, create, edit, delete | |
| Groups | view, create, edit, delete, lead | |
| Classes & Education | Classes | view, create, edit, delete |
| Schedules | view, create, edit, delete | |
| Lessons | view, create, edit, delete, approve | |
| Attendance | view, record, reports | |
| Events & Calendar | Events | view, create, edit, delete |
| Calendar | view, export, create, edit, delete | |
| Rooms & Facilities | view, create, edit, delete | |
| Resources & Equipment | view, create, edit, delete | |
| Volunteers & Teams | Serving Teams | view, create, edit, delete, lead |
| Volunteers | view, create, edit, delete | |
| Tasks | view, create, edit, delete, assign | |
| Check-In | Check-In | view, use, manage |
| Communication | Messaging | view, send, manage |
| Announcements | view, create, edit, delete, publish | |
| Email Templates | view, create, edit, delete | |
| Email Campaigns | view, create, edit, delete, send | |
| Q&A Sessions | view, create, edit, delete, moderate | |
| Forms | Forms | view, create, edit, delete |
| Finances | Giving & Donations | view, create, edit, delete, reports |
| Funds | view, create, edit, delete | |
| Pledges | view, create, edit, delete | |
| Budgets | view, create, edit, delete | |
| Accounting | view, create, edit, delete, reconcile | |
| Giving Statements | view, generate, send | |
| Worship | Songs & Music | view, create, edit, delete |
| Service Plans | view, create, edit, delete | |
| Sermons | view, create, edit, delete, publish | |
| Website CMS | Website CMS | view, create, edit, delete, publish |
| AI Assistant | AI Assistant | view, use, manage |
| Reports & Data | Reports | view, export |
| Import & Export | import, export | |
| Administration | Team Management | view, invite, manage |
| Settings | view, edit | |
| Custom Fields | view, create, edit, delete |
Source of truth: If you see a discrepancy between this table and the Roles page, the in-app Roles page is correct. Some modules only appear if your subscription plan includes that feature.
2. Scope
The scope determines whose records a team member can see:
| Scope | Description |
|---|---|
| Own Records Only | The team member can only see and manage their own records (schedules they are assigned to, attendance they recorded, etc.) |
| Team Members | The team member can see records for people on their team or in their group |
| All Records | Full access to all records across the entire church |
Note: These are the scope names used inside the role editor. When you invite someone, the role dropdown shows the same scope in shorter form -- Themselves (Own Records Only), Their team (Team Members), or Org-wide (All Records).
3. Color
Each role has a color label for quick visual identification in the team list. Available colors include Gray, Red, Orange, Amber, Green, Emerald, Blue, Indigo, Purple, and Pink.
Built-In System Roles
TimelyChurch comes with a set of system roles that cover the most common use cases. These roles are automatically created for every church and serve as templates. A role that came from a system template shows a small Default badge on its card, and can be reset back to its original settings.
Administrator (Purple)
- Scope: All Records
- Permissions: Full access to every module and every action
- Best for: Senior pastors, executive staff, office administrators
Finance Admin (Green)
- Scope: All Records
- Permissions: Full access to the finance modules -- Giving & Donations, Funds, Pledges, Budgets, Accounting, and Giving Statements -- plus Reports (view/export). No access to people/events admin.
- Best for: Treasurers, finance team members who handle money but not general church admin
Team Leader (Emerald)
- Scope: Team Members
- Permissions: People (view/edit), Follow-Ups, Schedules (view/create/edit), Lessons (view), Classes (view), Attendance (view/record), Events (view), Calendar (view), Tasks, Serving Teams (view/edit/lead), Volunteers (view/edit), Check-In (view/use), Messaging (view/send), Announcements (view), Reports (view)
- Best for: Ministry directors, department heads, team captains
Team Member (Blue)
- Scope: Own Records Only
- Permissions: Schedules (view), Lessons (view), Attendance (view), Events (view), Calendar (view), Tasks (view/create/edit), Serving Teams (view), Volunteers (view), Check-In (view/use), Messaging (view), Announcements (view)
- Best for: Teachers, regular volunteers, worship team members
Member (Gray)
- Scope: Own Records Only
- Permissions: Events (view), Calendar (view), Announcements (view), Check-In (use)
- Best for: General congregation members who need basic portal access
Accountant (Read-Only) (Blue)
- Scope: All Records
- Permissions: Read-only access to all finance modules (Accounting, Giving & Donations, Funds, Pledges, Budgets, Giving Statements) plus Reports (view/export). No access to people, events, or communications.
- Best for: An external CPA or bookkeeper you bring in at tax time
Tip: System roles serve as starting points. You can customize most system roles' permissions to match your church's needs, and you can always reset them back to defaults. The Administrator role is the exception -- it always keeps full access and its permissions cannot be edited.
Creating a Custom Role
If the built-in roles do not match your needs, create a custom role:
- On the Roles page, click the New Role button in the top-right corner.
- (Optional) Start from a template. The top of the Create dialog offers quick-start templates -- such as Worship Director, Counter, Reviewer, and Bookkeeper -- that pre-fill the name, color, scope, and permissions. You can edit everything afterward. (Some templates may show an upgrade badge if your plan does not yet include their features.)
- Fill in the role details:
- Role Name -- A descriptive name (e.g., "Children's Ministry Volunteer," "Finance Team," "Worship Leader"). This field is required.
- Color -- Select a color for the role badge.
- Description -- A brief explanation of what this role is for (optional, up to 500 characters).
- Choose the Permission Scope -- Themselves (Own Records Only), Their team (Team Members), or Org-wide (All Records).
- Set the permissions for each module. For every module you turn on, use the None / View / Edit / Full level pills to set how much access the role gets:
- None -- the module is turned off for this role.
- View -- read-only access.
- Edit -- view, create, and edit.
- Full -- every action the module supports.
- If you fine-tune individual action checkboxes to a combination the pills don't cover, the role shows a Custom badge for that module. The per-action checkboxes appear beneath the pills so you can adjust exactly which actions are allowed.
- Click Create Role.
The new role will immediately be available for assignment when inviting or managing team members.
Editing a Role
- On the Roles page, find the role you want to edit.
- Click the pencil (Edit) icon on the role's card.
- Update the role name, color, description, scope, or module permissions using the same controls as the Create dialog (including the None/View/Edit/Full level pills).
- Click Save Changes.
Changes take effect immediately for all team members assigned to that role.
Note: System roles can be customized for your church -- each church gets its own copy that can be modified independently. The Administrator role is the exception: its permissions are locked to full access and cannot be changed.
Resetting a Role to Defaults
If you have modified a system role and want to restore it to its original configuration:
- Find the role on the Roles page. Roles that came from a system template show a Default badge.
- Click the reset (circular arrows) icon on the role's card.
- Confirm the reset.
This will restore the role's name, description, color, scope, and all permissions to the original system template values.
Deleting a Custom Role
Custom roles can be deleted if they are no longer needed:
- Find the role on the Roles page.
- Click the trash (Delete) icon on the role's card.
- Confirm the deletion.
You cannot delete a role that has team members assigned to it. If the role is in use, the Delete button is disabled and you must first reassign those team members to a different role.
Practical Examples
Example 1: Sunday School Coordinator
Create a role for someone who manages Sunday School classes but should not access finances:
- Scope: Their team (Team Members)
- Modules: People (View), Classes (Edit), Schedules (Edit), Lessons (Edit), Attendance (set the level so they can view and record), Check-In (set to View)
Example 2: Finance Administrator
Your church treasurer can use the built-in Finance Admin role, or you can create a custom role:
- Scope: Org-wide (All Records)
- Modules: Giving & Donations (Full), Funds (Full), Pledges (Full), Budgets (Full), Accounting (Full), Giving Statements (Full), Reports (View)
Example 3: Worship Team Member
Create a role for musicians and vocalists -- or start from the Worship Director template:
- Scope: Themselves (Own Records Only)
- Modules: Songs & Music (View), Service Plans (View), Schedules (View), Calendar (View)
Frequently Asked Questions
Q: What happens if I change a role's permissions while people are using the system? A: Permission changes take effect immediately. The next time a team member loads a page, they will see the updated access level.
Q: Can a team member have more than one role? A: No. Each team member is assigned exactly one role per church. If someone needs a unique combination of permissions, create a custom role for them.
Q: How many custom roles can I create? A: There is no hard limit on the number of custom roles. Create as many as you need to match your church's organizational structure.
Q: The number of team members shown on a role card -- what does that mean? A: This count tells you how many people are currently assigned to that role. It helps you understand the impact before making changes.
Q: What does the "Custom" badge on a module mean? A: It means the actions you've selected for that module don't match any of the simple None/View/Edit/Full presets. That's perfectly fine -- it just signals you've fine-tuned the individual actions for that module.