Help/Roles & permissions
How roles work
The roles Scout starts you with, and which of them you can change.
Every person with a Scout login holds exactly one role, and that role carries a set of permissions. Scout seeds six roles when your church is created. Some you can change, some you cannot, and one of them is not a role at all.
The six you start with
| Role | Can you edit it? | Can you delete it? | What it is for | |---|---|---|---| | Admin | No | No | Full access to everything, including settings | | Pastor | Yes | Yes | Full access to people, groups, notes, and giving. Editable under Permissions | | Staff | Yes | No | People, groups, serving, and check-in. No giving data | | Finance | Yes | Yes | Giving and reports only | | Volunteer | Yes | No | Runs check-in and sees teams, groups, and events | | Member | Yes | No | Uses the church app only. No dashboard access |
Admin is the locked one. It holds every permission by definition rather than by a stored list, so its grid is replaced on screen with "Admin has all permissions and can't be changed." You cannot rename it, delete it, or take anything away from it.
Pastor and Finance are seeded conveniences rather than fixtures. Delete either if it does not match a job your church actually has.
Volunteer is the fallback. Delete a custom role and everyone holding it moves to Volunteer rather than losing their login.
Member is the role every congregant with a churchHQ account holds. It has no dashboard permissions at all, it is filtered out of both role pickers, and members do not appear on the Users tab. You will never assign it by hand.
Owner is not a role
There is no Owner role in the picker, and looking for one is the most common confusion here. Ownership is a separate flag on one person's account, set on whoever created the church.
Two things follow from that:
- The owner is also holding a normal role. Usually Admin, and the Users tab shows it as a chip reading the role name followed by · Owner.
- Ownership carries what a permission cannot: the Billing link, deleting a post someone else wrote, and being the one account nobody can remove.
To move it, open Settings → Users, click Edit on the person, and use Transfer ownership. It only appears when you are the owner and the other person is an Admin. The confirm reads "Transfer ownership to {name}? You'll become an Admin and they'll gain billing access." See Inviting your team.
What each role can actually reach
Scout has 34 permissions, grouped as People, Giving, Insights, Community, Serving, Check-In, Outreach, and Admin. Rather than list all of them here, the differences that decide a role are:
- Admin and Pastor hold effectively everything. The only default difference is Release children at pickup, which Pastor does not have.
- Staff holds the operational set: people, notes, groups, teams, services, scheduling, check-in, forms, events, workflows, reports, and Scout's insights. It holds no giving permission at all, which is deliberate, so the whole Giving area is closed to it.
- Finance holds six permissions and nothing else: view giving, view reports, record donations, refund donations, manage funds, export data. No people, no notes, no insights.
- Volunteer holds seven: view participation data, groups, teams, the serving schedule, check-in, events, and manage rooms and sessions.
For a permission-by-permission account of what turning something off actually hides, see What each permission controls.
Where you change a role
Settings → Users, then Edit on the row, then pick a role under Role — each option lists what it can reach — then Save role. The button stays disabled until you pick something different.
Two rules the form enforces: you cannot change your own role, and you cannot change the owner's role. Move ownership first if that is what you are trying to do.
When a change takes effect
On that person's very next request. Scout re-reads the user's role and permissions from the database on every authenticated request rather than only at sign-in, so there is no cache to wait out and nobody needs to sign out and back in.
What you cannot do
- No per-person overrides. Permissions attach to roles, and a person holds one role. If one person needs a different mix, they need their own role. See Creating a custom role.
- No renaming a role. There is no rename control on any role, including the ones you created.
- No suspending someone. The options are changing their role or removing them.
- No list of who holds a role. The Permissions tab shows a count only when you go to delete a role. To see who has what, read the role chips on the Users tab.
Getting to Settings at all
The Settings page needs the Edit church settings permission (manage_settings). Admin and Pastor hold it. Staff, Finance, and Volunteer do not, so those roles land on an access-denied page.
Inside Settings, each tab has its own gate: Church Info needs manage_settings, Users needs invite_team, Audit Log needs view_audit_log, and Permissions is Admin only. Not a permission, the Admin role itself, so a Pastor can invite people and set roles but cannot change what a role means.
Still need help?
Email support@scout.church and we'll get back within one business day.