CCSecurity & Access
Foundation contract
Permissions & audit · P0
Trust must be built into every request.
Church Commons can replace multiple systems only if organizations can trust one shared platform with their public, private and sensitive records.
Private by defaultPublication requires an intentional field-level decision.
Least privilegeAssignments grant only the capability and context needed.
No silent accessSensitive activity and all changes become reviewable history.
| Role bundle | Tenant settings | People & roles | Private contacts | Publish directory | Program operations | Approved AI tools | Audit history |
|---|---|---|---|---|---|---|---|
| Platform stewardChurch Commons Operates the shared platform without becoming the day-to-day administrator of every tenant. | Allowed | Scoped | Scoped | Not allowed | Not allowed | Scoped | Allowed |
| Organization administratorOne organization Owns membership, organization settings, role assignments and app availability for one organization. | Scoped | Allowed | Allowed | Allowed | Scoped | Scoped | Allowed |
| Records managerAssigned record sets Maintains operational records and imports without receiving platform-development authority. | Not allowed | Allowed | Allowed | Scoped | Not allowed | Scoped | Allowed |
| Program directorAssigned app or program Runs Formation or another ministry program without inheriting organization-wide administration. | Not allowed | Scoped | Scoped | Not allowed | Allowed | Scoped | Scoped |
| ContributorAssigned task or offering Supports a course, committee, form review or another bounded task with minimum necessary access. | Not allowed | Not allowed | Not allowed | Not allowed | Scoped | Scoped | Not allowed |
| ParticipantSelf and enrolled experiences Accesses personal records, registrations, courses and invitations without administrative authority. | Not allowed | Not allowed | Not allowed | Not allowed | Scoped | Not allowed | Not allowed |
Teaching authority, AI access, private-record access and organization administration remain separate. Governance bodies are organizations or teams—not permission labels.