> ## Documentation Index
> Fetch the complete documentation index at: https://guide.worshipbuddy.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding Permissions

> User roles and permission levels in ChurchBuddy

# User Permissions and Roles

ChurchBuddy uses a role-based permission system to control who can do what in your organization. Understanding these roles helps you assign appropriate access levels to team members.

## Permission Levels

There are several permission levels, from highest to lowest:

1. **Owner**
2. **Organization Admin**
3. **Team Admin**
4. **Scheduler**
5. **Viewer**
6. **Member** (default, no special permissions)

## Owner

The Owner is the person who created the organization. There is only one Owner per organization.

**Can:**

* Everything an Organization Admin can do, PLUS:
* Transfer ownership to another member
* Delete the organization (if applicable)

**Cannot:**

* Remove themselves as Owner (must transfer ownership first)

<Info>
  **Tip**: The Owner role should typically stay with the organization's primary administrator or leader.
</Info>

## Organization Admin

Organization Admins have almost complete access to the organization.

**Can:**

* View and edit all teams, users, services, and assignments
* Create, edit, and delete services
* Schedule anyone to any service
* Manage all teams (create, edit, delete)
* Add/remove users from the organization
* Assign team and org-level roles
* View and edit anyone's availability
* Access all settings (except ownership transfer)
* Access calendar exports
* Manage WorshipBuddy and BibleBuddy integrations (if applicable)

**Cannot:**

* Transfer organization ownership
* Delete the organization (Owner only)

<Info>
  **Tip**: Organization Admins are great for trusted leaders who need broad access but shouldn't have ownership control.
</Info>

## Team Admin

Team Admins have administrative control over specific teams they're assigned to.

**Can:**

* Edit team details for their assigned teams (name, description, positions)
* Assign people to positions in their teams
* View and edit availability for their team members
* View calendar (Calendar + Services sub-tabs — all org services, not filtered by team)
* Schedule people for their teams
* Access the **People** section — **People sub-tab only** (not Groups, Workflows, or Forms sub-tabs)
* Access top-nav **Groups** when one of their teams belongs to a group (read/edit that group; cannot create groups)
* Access **Organization** nav → redirected to Teams page

**Cannot:**

* Create or delete services
* Edit teams they're not assigned to
* Add/remove users from the organization
* Open individual person detail pages from the People list
* See or modify other teams
* Integrations and Giving sub-tabs may still appear but show an access-denied alert if clicked (Teams redirect only)
* Create new teams

<Info>
  **Tip**: Team Admins are perfect for ministry leaders who manage specific teams but don't need organization-wide access.
</Info>

## Scheduler

Schedulers can assign people to services but have limited editing capabilities.

**Can:**

* Assign people to positions in their teams for existing services
* View their team's availability
* See services where their team is assigned
* Use **Schedule Team Members** and **Auto Schedule** on Calendar/Services

**Cannot:**

* Create, edit, or delete services
* Change team names or permissions
* Add/remove users
* Edit team details
* Access the People page
* Access settings

<Info>
  **Tip**: Schedulers are great for volunteers who help with scheduling but don't need to manage team structure.
</Info>

## Viewer

Viewers have read-only access to specific teams.

**Can:**

* View the Dashboard
* View the **Calendar** sub-tab only (Services sub-tab is hidden)
* See all org services on the calendar (not filtered to assigned teams)

**Cannot:**

* Access the Services card grid sub-tab
* Access the Teams page
* Access the People page
* Make any changes or schedule people
* Edit services or teams
* Export schedules
* Use auto-scheduling

<Info>
  **Note**: Viewer permissions are useful for people who need to see information but shouldn't make changes.
</Info>

## Member (Default)

Members have basic access with no special permissions.

**Can:**

* View their personal schedule
* Set their availability
* View services they're scheduled for

**Cannot:**

* Access team management
* Schedule others
* Edit services
* Access settings

<Info>
  **Note**: All users can view services they're personally scheduled for, regardless of permissions.
</Info>

## Assigning Permissions

### Organization-Level Permissions

Only Owners and Organization Admins can assign organization-level roles:

1. Go to **People** and open the person's detail page (`/org-person-detail/`)
2. Click **Edit Person** (or **Edit Positions & Teams** for positions/permissions)
3. Make changes and click **Save Changes**

### Team-Level Permissions

Owners and Organization Admins can assign team permissions:

1. Go to **People** and open the person's detail page
2. Click **Edit Person** or **Edit Positions & Teams**
3. In **Team Permissions**, select teams and assign levels (Admin, Scheduler, Viewer)
4. Click **Save Changes**

## Permission Best Practices

1. **Principle of least privilege** - Give people only the permissions they need
2. **Start with lower permissions** - You can always increase permissions later
3. **Review regularly** - Periodically review who has what permissions
4. **Use Team Admins** - Delegate team management to Team Admins rather than making everyone Organization Admins
5. **Document permissions** - Keep track of who has what access for your records

## Permission Visibility

Navigation and features are automatically hidden or shown based on permissions:

* **Settings** - **Organization** nav visible to Owners, Admins, and Team Admins
* **Teams** - Via **Organization → Teams** sub-tab
* **People** - Via **People → People** sub-tab (top nav hidden for Schedulers and Members)
* **Groups** — Owners/Org Admins: **People → Groups** or top nav. Team Admins: top-nav **Groups** only (when their team is in a group), not People → Groups
* **WorshipBuddy** - Top nav when access granted
* **BibleBuddy** - Direct URL `/org-biblebuddy/` (top nav link hidden)
* **Streaming** - Top nav when any integration is connected (YouTube or Zoom)

Users will only see features they have permission to use.
