Who can do what: the role access matrix
Every staff member has a role, and the role decides what they can see and do across Vianney. You set this in one place — the role access matrix — and each switch you flip is real: it changes both what appears on the screen and what the person is actually allowed to do behind the scenes.
The seven roles
- Priest — full access, including Settings and Messages.
- Administration — broad office access including Messages; not annulments by default.
- Parish Office — front desk: directory, Messages, intentions, scheduling, calendar.
- Deacon — pastoral access including Messages, without certain private and confidential areas.
- Faith Formation, Sacred Music, Maintenance — focused access to just the areas they need (Messages not included by default; Faith Formation, like the office, sees public Insights on a person's profile and never private ones).
Reading the matrix
Go to Settings → Staff & Teams → Role access (priest or Administration). It is a grid:
- Down the side are the seven roles.
- Across the top are the modules and, within each, the specific actions — things like create, edit, record, issue certificates, send, publish, and configure.
- The first column of each module is "Whole module." Turning that on (or off) cascades to every action beneath it, so you can grant a whole area with one switch, then fine-tune the individual actions from there.
- Fine-tuning after a cascade now sticks. Grant a role the whole module and then untick one action beneath it, press Save, and the untick is what you get. (There was a spell when that particular combination quietly snapped back to fully-on when the grid redrew — it does not any more.)
Every switch is real
There are no decorative switches. If you turn an action off for a role, the person's screen hides it and the system refuses that action if it is somehow attempted anyway — the two always agree. That is checked automatically on every release, so what the matrix says is what the parish actually enforces. Changes take effect within seconds; no one has to sign out and back in.
The one locked switch
Almost everything is yours to adjust. The single exception is "Remove a funeral case," which is locked to the pastor 🔒 — because permanently removing a sacramental case is a decision canon law reserves to him, no matter how the matrix is set. You will see it marked as locked and cannot hand it to another role.
Note that recording a death is *not* locked: it is part of the ordinary Funerals module, so anyone with Funerals access can enter it — only *removing* a case is the pastor's alone.
One switch retired, two arrived (20 August 2026)
Pastoral notes (the switch that opened the old middle note tier) is gone from the matrix, along with the tier it controlled. Reading someone else's private Insight is no longer a switch at all — it is the pastor, and only the pastor. If you had granted that permission to somebody, there is nothing to undo: the stored grant is simply ignored.
Two new switches took its place, and both are granted with their parent module by default and can be withheld from a role:
- People setup — define the person-detail fields your parish keeps: marital status, profession, languages, talents, accessibility needs, and any field you add. It appears as a Setup tab inside People.
- Engagement setup — curate the parish's volunteer opportunities and service bodies (Finance Council, Parish Council, and whatever else you keep). Ministry positions are not edited here; they come from Ministry Scheduling.
Events: seeing, adding, and running
Events is its own group in the matrix — public event pages, RSVPs, and rosters. It has the bare Events key to enter the module (which is also what lets someone read rosters and download the roster CSV) and two actions:
- Add new events — create a new event page, as a draft. Nothing is public until somebody publishes it.
- Manage events & RSVPs — edit, publish, cancel and re-link an event, hand-edit a single date, add a walk-in at the desk, cancel an RSVP, link an RSVP to a person record, and edit the events policy.
The two used to be one switch; they were split so a role can be trusted to *draft* an event without also holding the run of everything else. The default worth knowing: Faith Formation keeps Events, and may add one, but not Manage events & RSVPs — the DRE can set up the VBS nights and read the roster, while publishing a page the whole world can reach, taking walk-ins and linking identities stay with clergy and the office. Sacred Music and Maintenance have no Events access at all. See Events and RSVPs.
Tasks is its own group now
Tasks used to ride along with Liturgy. It is its own module in the matrix, with a single action beneath it: Assign tasks to others.
The split matters. Everyone who has the Tasks module keeps their own My Tasks list — their personal work, and the one that syncs with Google Tasks. The action controls only whether they may route work to *somebody else*: a visit, a call, a baptism, a funeral, or a free-form task. Turn it off for a role and that role still has its own list; it simply cannot hand work out.
Sacred Music has Tasks by default. That is deliberate rather than generous: Tasks used to ride the Liturgy permission, which Sacred Music already had, so leaving it out would have quietly taken a screen away in a rename. Untick it if a music director never routes work. Maintenance is the one role without it.
One rule is not in the matrix and cannot be switched: a Parochial Vicar may only assign work to himself. The Pastor, or the office, routes work to another priest. That is canonical, not an oversight, and no permission grants around it.
Chat has three switches, two of them explicit
The Chat group has the bare Chat key and two management actions: Create & manage chat channels and Manage built-in chat channel membership.
Two things about it are unusual and worth reading. First, every role has Chat — Sacred Music and Maintenance included. A parish where the maintenance director cannot be messaged is a parish that goes back to texting, which is the opposite of the point. Second, neither management key is inherited: granting a role the whole Chat module does not hand it either of them. They have to be ticked on their own, deliberately.
Built-in channel membership also carries a rule the matrix cannot express: among priests it is the pastor's, not every priest's. A Parochial Vicar with the switch on still cannot change who is in a built-in channel.
You may see this group in the matrix before Chat itself appears anywhere in the parish. That is expected — the permissions are set up ahead of the module being switched on, and what you tick here is what will be enforced the moment it is.
Connect has an approval switch
Alongside Compose & manage and Send & schedule, the Connect group carries Approve library content — approving, archiving and restoring the shared group- and parish-scope templates in the Template Library. It gates *visibility* only: approval is what makes an item selectable by everyone else in its scope; it never sends anything. By default it sits with the priest and Administration — the front office keeps Connect but not library approval, so the desk can write and send freely while what becomes the parish's standing wording stays a deliberate decision. Deacon and Faith Formation have no Connect access at all by default. See The Connect Template Library.
When one person needs a little more (or less)
Roles cover the common cases; individuals sometimes need an exception — "Mary at the front desk may also record baptisms." You do not have to invent a new role for that. Open her staff card and use the Access panel to grant or deny a single permission just for her, on top of her role. See Exceptions for one person.
Safe Environment is separate
Access to the Safe Environment module is not set from this matrix. The pastor has implicit coordinator access; every other priest (a Parochial Vicar, for instance) and every other role needs an explicit Safe Environment access grant in Settings → Staff & Teams before the module appears. This keeps sensitive clearance records with the people who genuinely need them.
Faith Formation has its own permission group
The Formation module carries its own permission group in the matrix, like every other module: the bare Formation key to enter the module, then Manage programs & classes, Enroll & approve, Attendance, School roster import, Sacrament prep, and Module settings. By default, Priest, Administration, and Parish Office have the whole group; Faith Formation (the DRE role) has it all too; Deacon keeps the module and day-to-day work but not roster import or module settings.
Confirming a proposed sacramental-register entry is deliberately a *different* permission — Record register entries (grouped under People, not Formation). Formation staff can propose an entry from a prep track or an OCIA case, but turning that proposal into an actual register row needs this separate permission, which floors to Priest, Administration, and Parish Office; Deacon and Faith Formation propose but do not confirm by default.
Ministries includes a separate override switch
The Ministries group is the bare Ministries key to enter the module, then Manage members, Ministry settings, Build schedules, Publish schedules, and Override schedule rules.
Override schedule rules is the one worth pausing over. Building and publishing a schedule is one thing; approving something the rules push back on is another. When the office approves a sign-up or a substitute and Vianney flags a soft restriction — one of the person's own away dates, their monthly limit, a limit on serving twice in a weekend, not enough rest since they last served, they are not on that roster, they are already serving that Mass, a lapsed qualification, or a Safe Environment hold your parish set — the approval only goes through for someone who holds this switch, and only with a reason recorded alongside it. Everyone else sees the finding plainly and cannot approve past it.
Two things it never does. It is not a way around a diocese-level Safe Environment block — nothing overrides that. And it does not bend the structural facts: a cancelled Mass, a spot someone else has already taken, or a stale screen is refused for everyone, override or not.
By default every role except Maintenance has the whole Ministries group, this switch included. If you would rather that approving over a restriction stayed with the office lead, turn Override schedule rules off for the other roles here, or withhold it from one person with an exception — the rest of their scheduling work is untouched.
A few permissions stand alone
Most access follows the matrix's module grants, but a handful of sensitive permissions are deliberately not bundled into a module's "whole module" switch and must be granted on their own:
- Capacity & asks — giving-capacity and ask-tracking data is not part of the ordinary Stewardship grant; it has its own switch, and by default no lay role has it.
- Engagement stages — seeing and overriding lifecycle stages has its own entry in the matrix, alongside the rest of Engagement.
- School — the School module has its own permission group in the matrix, and it floors to the pastor and parish office by default.
- Export people — downloading the directory as a CSV from the People bulk-action bar is its own switch, separate from ordinary directory access. It floors to the pastor and the parish office by default; Deacon and Faith Formation do not have it.
Vianney Connect group roles
Connect groups also support per-group roles behind the scenes for who may post to or manage a specific group's roster — but there is no staff-facing screen to assign or view them yet, so there is nothing to walk through here today. If you need group-level sending or roster management set up, raise it with support directly rather than looking for it in this matrix.
Tips
- Start from a role, then use per-person exceptions for the odd case — it is far simpler than making bespoke roles.
- The menu hides what a role cannot use, and the same limit is enforced underneath, so hiding is real, not cosmetic.
- Private things — annulment detail, Stewardship amounts — are withheld from broad roles by default; grant them deliberately. Private Insights are not on that list, because they are not a grant: only their author and the pastor ever see them.
- Roles are why two colleagues can see different tabs; that is by design.
- On a cluster home, Google sign-in is just a second door in — once you're in, your role and access are exactly the same as if you had signed in with a password.