> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kehillahq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> What each role can see and do, including who can see contact details and finances.

Every person with a sign-in has exactly one role. The role decides what they see. This page is the reference: pick the narrowest role that lets someone do their job.

## The roles at a glance

| Role                | Directory     | Contact details | Finances           | Manage users | Notes                           |
| ------------------- | ------------- | --------------- | ------------------ | ------------ | ------------------------------- |
| **Admin**           | View and edit | Full            | View, edit, export | Yes          | Runs the congregation's account |
| **Clergy**          | View and edit | Full            | No access          | No           | Also sees pastoral notes        |
| **Financial Admin** | View only     | Full            | View, edit, export | No           | Your treasurer or bookkeeper    |
| **Staff**           | View and edit | Full            | No access          | No           | Office administrator            |
| **Board Member**    | View only     | Limited         | View only          | No           | Sees totals, not payment entry  |
| **Volunteer**       | View only     | Limited         | No access          | No           | The narrowest role              |

<Note>
  There is also a Super Admin role. It belongs to KehillaHQ support staff, not to your congregation, and it does not appear when you invite someone.
</Note>

## What "limited" contact details means

This is the part worth understanding properly, because it is how you give someone useful access without handing over your members' personal information.

**Board Member** and **Volunteer** see who your members are: names, which household they belong to, membership type, and status. They do not see:

* Email addresses and phone numbers
* Birth dates
* Hebrew names and Hebrew birth dates
* Gender
* Household addresses and household phone numbers

Those fields appear empty for them, exactly as if they had never been filled in. A volunteer building a Sukkot sign-up list can see that the Rosen household exists and who is in it, without collecting everyone's phone number along the way.

Every other role sees contact details in full.

## Who can see money

**Admin** and **Financial Admin** have full financial access. They see dues, donations, and the To file inbox, they can record payments, change commitments, and export financial data. Both can also connect a payment processor such as PayPal.

**Board Member** can view finances but not change them. This suits a board that needs to see where the year stands without anyone accidentally editing the ledger.

**Clergy**, **Staff**, and **Volunteer** have no financial access at all. For them the Finances section is simply not in the sidebar.

## Pastoral notes

**Clergy** is the only role that can see pastoral notes. Notes stay private to clergy even from an Admin. This is deliberate, so a rabbi can record a sensitive note about a family without it becoming visible to office staff or the board.

## Choosing a role

A few situations that come up often:

**Your treasurer or bookkeeper.** Financial Admin. They get everything they need for money, and can view the directory for context, but cannot edit member records or invite users.

**Your office administrator.** Staff. Full directory access including contact details, no financial access.

**A board member who wants to see how the year is going.** Board Member. Read-only finances, limited contact details.

**A volunteer helping with an event.** Volunteer.

**Someone who needs to do everything.** Admin. Keep this list short. Two or three people is usually right for a congregation of this size.

<Tip>
  If you are unsure between two roles, pick the narrower one. Widening someone's access later takes a few seconds. Discovering that a volunteer has been able to export the full membership list does not have an undo.
</Tip>

## A note on how this is enforced

Hiding a section from the sidebar is not the whole of it. Permissions are checked again on the server every time a page loads or a change is saved, so someone cannot reach a restricted page by typing its address directly.
