Admin

Who should actually have access to your church's records?

A policy conversation for the season before you need a policy — while one login still covers the whole church.

7 min read

Ask AI · in the $19/mo plan

Ask your own records a question. What follow-up has nobody picked up yet?” — answered from the records you already keep. It reads your church and no other, and it can't invent a number.

10 questions a month included · no AI add-on to buy

Most small churches run their records on one shared login. Not because anyone decided that was the right approach, but because nobody decided anything at all. The part-time secretary set up an account years ago, the password lives in a sticky note or a group text, and whoever needs to look something up asks whoever has it open. It works, mostly, until the week it does not.

This is not an article about buying software that solves the problem for you. It is a conversation your church can have this month, for free, with the tools you already have — about who actually needs to see what, who currently can, and why the gap between those two lists is worth closing on purpose rather than by accident.

The shared login is not a scandal — it is a default

It is worth saying plainly: a church of sixty to two hundred people running on one shared login is not doing anything unusual or negligent. It is the default almost everyone starts with, because for a long time it is genuinely fine. One trusted person, or two, keep the records. Everyone else asks them. The system has no permissions to configure because it has no need for them yet.

The trouble is not the shared login itself. It is that most churches never revisit the arrangement, so it quietly stops fitting the church that grew around it. The secretary who set the password five years ago has moved. Two more volunteers now need to check things. Nobody remembers who has the login anymore, and nobody is quite sure they would notice if the wrong person did.

Start with what is actually sensitive, not what feels sensitive

Not every record carries the same weight, and treating them as if they do makes the real conversation harder, not easier. Roughly three tiers show up in most churches:

  • Contact information and household structure — useful to a wide circle of volunteers, low risk if seen by the wrong person, high cost if it is wrong or out of date.
  • Giving records — legally and pastorally sensitive. Most congregations expect only one or two people to ever see who gave what, and that expectation deserves to be honored on purpose.
  • Pastoral care notes — the most sensitive category by far, and the one where a breach of trust does real, lasting damage to a person who was vulnerable enough to ask for help.

A useful exercise: list every person who currently has any access to your records, then write next to their name which of the three tiers they actually need for their role. The gaps between what they have and what they need are your policy, waiting to be written down.

Write down who owns the decision, not just who has the password

Ownership and access are different questions, and conflating them is where most informal policies fail. Access is the technical question: who can currently open the record. Ownership is the governance question: who is allowed to decide who gets access, and who is accountable if that decision goes badly. A church can have three volunteers with access and still have exactly one owner — usually the senior pastor, an administrator, or a small board — who answers for the arrangement.

Naming that person out loud, even informally, changes the tenor of the whole conversation. It stops being “who is allowed to see this” and becomes “who has agreed to be responsible for this,” which is a question most people answer more carefully. If your directory is the thing every volunteer touches, someone still has to be the one who decides who gets to touch it.

Separate roles from relationships

The hardest access conversations in a small church are rarely about strangers. They are about people who are both trusted friends and the wrong audience for a particular record — the volunteer treasurer who is also everyone's favorite aunt, the deacon who sat with a grieving family last year and now wonders whether he should know what they gave this year. Trust in the relationship and trust in the role are not the same thing, and a healthy policy treats them separately.

One honest way to frame it to a volunteer: “You see this because of the role, not because we doubt you as a person.” That sentence, said once, out loud, does more to protect both the volunteer and the congregation than any technical safeguard would. It gives the volunteer a clean answer when someone asks what they know, and it gives the church language for the boundary before a moment of tension forces the conversation.

What “one login” actually costs you

It is worth being specific about the real risks of a single shared login rather than treating it as a vague discomfort. Three things tend to happen:

  • Nobody can answer “who looked at this?” When something is seen or changed and a question arises later, there is no way to say who did it. Everyone used the same credential.
  • Access outlives the role. A volunteer steps down from treasurer, but the password is unchanged. Nothing was ever technically revoked because nothing was ever technically granted.
  • The password itself becomes a liability. It gets texted, written on a whiteboard, or shared with a well-meaning new volunteer “just this once,” and now it is circulating further than anyone intended.

None of these are dramatic. They are quiet, and that is exactly why they are worth naming before one of them turns into an actual problem — a giving dispute, a care note surfacing in the wrong conversation, a departed staff member who still, technically, has the keys.

A policy you can write in one page

You do not need a legal document. A short, plain-language page that your board or elders sign off on covers most of what a church of this size actually needs:

  • Who currently has access to records, and to which tiers.
  • Who owns the decision to grant or remove access.
  • What happens when someone with access leaves a role or the church.
  • Who is told when access changes, and how.
  • When the policy gets reviewed — put a date on it.

Most software, including SundayBridge, runs a small church on one login rather than a full set of staff roles and permissions — which is exactly why the policy has to live in a conversation and a document, not a settings screen. That is not a gap to apologize for; it is the honest shape of the tool, and it means the discipline has to come from your church rather than from a checkbox.

Revisit it on a schedule, not a crisis

The churches that handle this well do not have better software. They have a habit: once a year, usually alongside an annual meeting or budget review, someone reads the access list out loud and asks whether it still matches reality. Most years, nothing changes. The value is not in catching a problem every year — it is in the review itself being the reason a problem never gets the chance to sit unnoticed for three years. A short weekly admin rhythm is where the small stuff gets caught; an annual access review is where the bigger, quieter risks get caught.

If your records have drifted — duplicate entries, an outdated directory, giving history nobody has reconciled in a while — a cleanup pass is a natural companion to an access review. You are already looking closely at the data; it costs little extra to also ask who should be looking at it. And if giving is part of what you are reviewing, it is worth reading how a giving record can respect the giver even when very few people ever see it.

The honest version is the sustainable one

None of this requires new software, a committee, or a consultant. It requires one meeting where your church says out loud who sees what, why, and who decided. Most churches this size are running on trust that has never actually been named — which usually works fine, until the day it does not, and by then the person who could explain the arrangement has moved on and nobody else remembers why it was set up that way.

Naming it costs an afternoon. Not naming it costs nothing, until the one time it costs a lot — a giving dispute nobody can trace, a care note that reached the wrong ears, a departing volunteer who still has the keys eighteen months later. Write the one page. Name the owner. Put a date on the next review. That is the whole policy, and it is enough.

Frequently asked questions

Isn't one shared login just easier for a small church?
It is easier right up until something goes wrong — a password gets texted to the wrong person, a departing volunteer never had their access removed because there was nothing to remove, or the pastor genuinely does not know who looked at a giving record. Easier and safer are not the same thing, and a small church can usually afford a little less easy.
Who should know we even have a records policy?
Everyone who touches the records, and ideally the whole staff and lay leadership too, even if they never open the software themselves. A policy nobody knows exists is not a policy; it is a memo in a drawer. Read it aloud at a staff meeting once a year and ask if anything has changed since.
Should the senior pastor see everything, including giving amounts?
Many churches say yes as a matter of course, but it is worth asking on purpose rather than by default. Some pastors want to know who gives what because it shapes how they shepherd; others deliberately stay unaware so no gift ever changes how they treat someone. Either is defensible. Drifting into one without discussing it is not.
What do we do about a volunteer treasurer who is also a member with pastoral needs?
Separate the two hats out loud. The treasurer sees giving records because the role requires it, not because they are also a trusted friend of the family. Naming that distinction protects the volunteer as much as the congregation — it gives them a clean answer when someone asks what they know.
How often should we revisit who has access?
Once a year at minimum, and immediately whenever a volunteer or staff member with access leaves a role. An annual review takes twenty minutes and mostly confirms nothing has changed. The times it turns something up are exactly why it is worth doing on a schedule rather than when you remember.