Skip to Content
Getting StartedInvite the team and assign roles

Invite the team and assign roles

Ministrium operates with role-based access control (RBAC): each user has one or more roles that define what they can do and a scope that limits the data they can see. This page describes how to invite new collaborators and assign the right role. For the full catalogue of the 12 roles, see Roles and permissions.

Steps

Open the Team module

In the side menu, open Church → Team. You’ll see the list of current users and the Invite staff button.

Fill in the staff member’s data

  • Full name: the collaborator’s name as it should appear in the internal list.
  • Email: the invitation is sent to this email. It will also be their username for sign-in.

Use the institutional email when one exists (for example pastor@yourchurch.org). Personal email works but creates dependencies: if the person resigns, their personal email remains the only access to church information until the admin deactivates it.

Assign a role

Choose one of the 12 functional roles:

RoleFor whom
PastorPastoral leadership with full access to every module.
Associate PastorAssociate pastoral leadership with full access.
Campus AdministratorAdministrative operations for an assigned campus.
SecretaryPeople management and read access to groups and cell reports.
Finance LeaderFull Finance access and read access to People.
AccountantRead access to Finance and People.
Zone SupervisorGroups, agenda, interactions, and analytics for an assigned zone.
District SuperintendentGroup and report management within an assigned district.
Cell LeaderMembers, attendance, and weekly reports for an assigned cell.
Service Team LeaderTeams, agenda, and service planning.
Legal Kids LeaderMinor supervision and consents.
Formation Leader / TeacherAssigned cohorts, curriculum, and grading.

For the full detail of what each role can do, see Roles and permissions.

Limit campus scope (optional)

If your church has multiple campuses, you can restrict the user to one or several:

  • No restriction → sees all campuses.
  • Restricted to one campus → only that campus.
  • Restricted to several → the campuses you choose (typical for zone supervisors).

The scope is applied structurally at the database level: the user cannot see data from a campus outside their scope, not even by accident. See Isolation between churches.

Cell-, zone-, district-, and campus-scoped roles can only see data within their area. Confirm the scope before sending the invitation.

Send the invitation

Click Send invitation. The collaborator receives an email with:

  • Who is inviting them and to which church.
  • The assigned role and campus scope.
  • A single-use link to create their password.

The link expires in 7 days. If the person doesn’t respond in time, go to Church → Team → Pending and click Resend invitation.

MFA activation

For pastoral, administrative, and financial roles, Ministrium requires MFA (two-factor authentication) from the first login. The interface guides the user to set up a TOTP app (Google Authenticator, Authy, 1Password) in less than a minute.

For all other roles, MFA is optional but recommended. See MFA and password policy.

Composite roles

A user can have composite roles combining responsibilities. Common examples:

  • Pastor + Cell Leader — a pastor who also leads a cell.
  • Accountant + Service Team Leader — an accountant who also coordinates a team.

To assign multiple roles, go to Church → Team → Edit user and add each role. Permissions accumulate: the user has everything each role allows, and the interface adapts to show the modules relevant to the combination.

Change or remove a role

Go to Church → Team → Edit user and modify the role or scope. If the user leaves the church:

  1. Remove administrative or leadership roles and retain only member access when appropriate; otherwise, deactivate the account.
  2. Do not delete the account: deletion would break the audit trail. The correct action is to deactivate.

Every change is logged in the audit with who did it, when, and from which IP.

Next steps

Last updated on