A church of 90 people usually has one login for its records software and two or three volunteers who know the password. That is not a temporary arrangement waiting for a budget to catch up — for a lot of small churches, it is the permanent shape of the staff. Which means giving confidentiality cannot depend on a permissions panel that restricts what a volunteer can see. It has to depend on the volunteers themselves, and on habits that hold even when nobody is watching.
That is a harder problem than a software setting, but it is also a more honest one. Most confidentiality failures at small churches are not hacking or malice. They are a treasurer mentioning a number in passing, a shared screen at the wrong moment, or a printed report left on a desk in the church office. Here is how to close those gaps without pretending you have access controls you do not have.
Start from the real constraint: one login, everyone who has it can see everything
Church management tools built for congregations this size — including SundayBridge — are typically built around a single login per church rather than staff roles with different levels of access. There is no way to give the bulletin volunteer access to the directory but not to giving totals. If someone has the password, they can see contributions, pastoral care notes, and everything else in the system.
Accepting this up front changes the whole conversation. Instead of asking “how do we configure the software to protect this,” you ask “who actually needs the password, and what do we agree to do with what we see.” That second question has a real answer, even without a permissions system.
Shrink the list of people who have the login
The single biggest lever you have is the smallest one: fewer logins. Every person who can sign in is a person who could, deliberately or by accident, see a giving record while doing something unrelated. For most churches this size, that list should be short on purpose:
- The treasurer or bookkeeper who enters and reconciles gifts.
- One backup, in case the treasurer is sick or travels — not three backups “just in case.”
- The pastor, if your church has decided that is the right policy (see below), or specifically not the pastor if it has decided otherwise.
A volunteer who only needs the directory for a phone tree, or the events calendar for scheduling, does not need the login that also holds giving. If that means printing a contact list for them once a quarter instead of giving them standing access, print the list. The inconvenience is the point — it keeps the door narrow.
Decide, on purpose, whether the pastor sees individual amounts
This is the decision small churches most often make by accident instead of on purpose. Some pastors have full visibility into who gives what because nobody ever discussed doing it differently. Others are walled off entirely because a previous treasurer decided that was safer and never told anyone why.
Either approach can be defensible. What cannot be defended is not having made the decision at all. Sit down as a board or elder team, decide the policy, write two sentences about it, and apply those two sentences the same way for every pastor and every treasurer who ever holds the role. When the policy changes hands with the people instead of living in someone’s head, it survives turnover.
Treat the login like a shared house key, not a shared secret
Passwords at small churches tend to travel by word of mouth: written on a sticky note in the office, texted to a new volunteer, remembered by three people who have all since moved on. Treat the login the way you would treat the key to the building — something you know exactly who holds, and something you can change when someone stops needing it.
- Change the password when a treasurer or key volunteer steps down, every time, without exception.
- Never text or email the password in plain text if you can help it — hand it over verbally or on paper.
- Keep one written note of who currently has it, reviewed at the same time each year, maybe alongside your year-end giving statements work.
Separate the moment of entering data from the moment of discussing it
A lot of accidental disclosure happens not while someone is looking at giving records but while they are talking about something else nearby. The treasurer has the giving screen open to enter Sunday’s contributions, a board member walks by to ask about the coffee budget, and a name and number are visible on the monitor for the three seconds it takes to glance over.
The fix is not a technical one. It is a habit: close the giving screen, or turn the monitor, before anyone else is in the room, even for a thirty-second conversation. If entering contributions is part of your weekly admin rhythm, do that piece of the rhythm at a time when the office is actually quiet, not squeezed between two other conversations.
Handle printed reports like cash, because in a sense they are
A giving report on paper is arguably more exposed than one on a screen, because paper does not lock itself and it does not go away when you walk off. If you print anything with individual amounts on it — for a board meeting, for reconciliation, for an audit — treat it with the same care you would treat a stack of checks: know who has it, know when it gets shredded, and never leave it on a desk overnight in a building other people can enter.
If a board needs to review giving trends without seeing individual names, ask whoever runs the reports to pull totals and patterns rather than a name-by-name list. Most of what a board actually needs — is giving trending up or down, are pledges being met, is one fund under-supported — can be answered in aggregate. Save the individual detail for the one or two people who genuinely need it.
Plan for the moments confidentiality usually breaks
Most churches do not lose confidentiality on an ordinary Tuesday. They lose it during a specific, predictable moment: a finance committee meeting, a budget season, a capital campaign, or a conversation about whether a family can afford to keep serving on a ministry team. Those are the moments worth planning for in advance, because they are also the moments where someone with good intentions is most tempted to peek at an individual number to answer a question that could have been answered with a total instead.
Before a finance meeting, decide what will actually be shown — usually fund totals, pledge progress, and trend lines rather than a name-by-name printout — and prepare exactly that, nothing more. Before a capital campaign, agree in writing whether the campaign committee will see individual pledges or only aggregate progress toward the goal. Deciding this ahead of the meeting, when nobody has a specific person in mind, produces a calmer and fairer answer than deciding it in the room when someone is asking about a specific family.
Keep the habit alive after the people change
Volunteer treasurers rotate. A church that goes through three treasurers in five years, which is common, needs the confidentiality habit to survive each handoff rather than reset with every new person who learns the system from scratch. Build the handoff itself into the habit: when a new treasurer takes over, the outgoing one walks them through not just how to enter a gift, but who currently has the login, what the pastor does and does not see, and where the written policy lives. That fifteen-minute conversation, repeated every time the role changes hands, does more for long-term confidentiality than any single rule on its own.
Write the rules down where the next person will find them
None of this holds up if it only lives in the current treasurer’s head. Write a short, plain page: who has the login, what happens to individual amounts, what the pastor does and does not see, how printed reports get destroyed. Keep it with your other governance documents, not buried in an email thread. The next treasurer, the next pastor, the next board chair should be able to read it in five minutes and know exactly what they are agreeing to when they take the role.
What this cannot fix
Be honest with your board about the limits here. A single shared login means anyone who has it technically can browse giving records out of curiosity, and no habit or written policy stops that with certainty. What these practices do is remove the accidental exposure — the glanced screen, the sticky-note password, the printed report on the wrong desk — and make the deliberate kind of snooping a clear, nameable breach of an agreement rather than an ambiguous gray area. That is the honest ceiling of what a small volunteer staff can guarantee, and it is worth telling people that plainly rather than promising more than any system, software or otherwise, can deliver.