Setup
Review Role Permissions
Review every role and all 35 RBAC permissions before inviting your full security team.
Role permissions control what each type of team member can view or change. Review them before broad rollout so sensitive administration stays with trusted leaders.

Review a role
- Open Church Admin and find Role Permissions under Configurations & Tools.
- Select Manage RBAC.
- Under Select Role to Configure, choose the role you want to review. Start with Security Team Member, then review Security Shift Team Lead, Campus Security Lead, Director of Safety & Security, Support Staff, and Admin.
- Review every permission category listed below. The RBAC page currently includes 35 permissions across 11 categories.
- For each permission, keep Default or explicitly choose Enabled or Disabled. Only override a default when your church has a clear operational reason.
- Select Save Changes, then repeat the review for every role your church assigns.
What each permission state means
- Default — Use the standard access configured for the selected role.
- Enabled — Explicitly allow the selected role to use this permission.
- Disabled — Explicitly prevent the selected role from using this permission.
The state can differ by role. The list below describes every permission you can configure; it does not mean each permission should be enabled for every role.
Complete permission inventory
These names and descriptions match the permissions currently shown on the Role-Based Access Control page.
Incidents
- Create Incidents — Report new incidents
- Edit Incidents — Modify existing incidents
- Delete Incidents — Remove incidents
- Archive Incidents — Archive and unarchive incidents
- View All Incidents — See all incidents in org
- View Sensitive Incidents — Access incidents marked sensitive
BOLO Alerts
- Manage BOLO Alerts — Create, edit, resolve, and delete BOLO alerts
Team
- View Team — View team directory
- Add Team Members — Invite new members
- Edit Team Members — Modify member details
- Remove Team Members — Remove from team
Campus
- View Campuses — See campus information
- Edit Campuses — Modify campus details
- Manage Areas — Manage campus areas
- Manage Campus Users — Assign users to campus
Equipment
- View Equipment — See equipment list
- Add Equipment — Create new equipment
- Edit Equipment — Modify equipment
- Delete Equipment — Remove equipment
- Checkout Equipment — Check out equipment
Schedules
- View Schedules — See shift schedules
- Create Schedules — Create shifts
- Edit Schedules — Modify shifts
- Volunteer For Schedules — Request open schedule slots
Procedures
- View Procedures — View documents
- Upload Procedures — Add new documents
Communications
- Manage Messages — Author and send team messages
- Delete Any Chat Message — Remove any team chat message
Settings
- Manage Settings — System settings
- Church Settings — Organization settings
Checklists
- View Checklists — See checklists
- Manage Checklists — Edit templates
- Delete Checklists — Delete draft and completed checklist runs
Users
- Manage Users — Full user management
- Reset Passwords — Password reset access
Permission guidance
- Give volunteers only the access they need for their assigned work.
- Reserve Admin for people responsible for organization-wide configuration, billing, and access control.
- Review sensitive incident, user-management, deletion, settings, and password-reset permissions carefully.
- After a change, test the expected workflow with a non-admin account assigned to that role.
A saved change applies to every user with that role. Use Reset to Defaults if you need to remove the church-specific overrides for the selected role.