Platform map
CCSecurity & Access
Foundation contract

Permissions & audit · P0

Trust must be built into every request.

Church Commons can replace multiple systems only if organizations can trust one shared platform with their public, private and sensitive records.

Private by defaultPublication requires an intentional field-level decision.
Least privilegeAssignments grant only the capability and context needed.
No silent accessSensitive activity and all changes become reviewable history.

Simple roles · precise authority

Capability bundles

A role is an understandable starting bundle. Contextual capabilities—not the label alone—decide what a person may do.

Role bundleTenant settingsPeople & rolesPrivate contactsPublish directoryProgram operationsApproved AI toolsAudit history
Platform stewardChurch Commons

Operates the shared platform without becoming the day-to-day administrator of every tenant.

AllowedScopedScopedNot allowedNot allowedScopedAllowed
Organization administratorOne organization

Owns membership, organization settings, role assignments and app availability for one organization.

ScopedAllowedAllowedAllowedScopedScopedAllowed
Records managerAssigned record sets

Maintains operational records and imports without receiving platform-development authority.

Not allowedAllowedAllowedScopedNot allowedScopedAllowed
Program directorAssigned app or program

Runs Formation or another ministry program without inheriting organization-wide administration.

Not allowedScopedScopedNot allowedAllowedScopedScoped
ContributorAssigned task or offering

Supports a course, committee, form review or another bounded task with minimum necessary access.

Not allowedNot allowedNot allowedNot allowedScopedScopedNot allowed
ParticipantSelf and enrolled experiences

Accesses personal records, registrations, courses and invitations without administrative authority.

Not allowedNot allowedNot allowedNot allowedScopedNot allowedNot allowed
Teaching authority, AI access, private-record access and organization administration remain separate. Governance bodies are organizations or teams—not permission labels.