A woman in your congregation tells the pastor, quietly, after the second service, that her husband moved out three weeks ago. The pastor writes a case note that afternoon so the next conversation does not start from zero. Nothing about that note is meant for the greeter roster, the treasurer, or the volunteer who runs the check-in table — and yet if your church runs on one shared login, all three of them could open it if they happened to be signed in and curious.
Most small churches never sit down and decide who should see pastoral care notes. It just sort of happens by whoever has the password and whoever thinks to look. That is not a software problem you can fix with a setting, because a lot of church software runs on one login per church rather than separate staff roles. The boundary has to be built out of habits, not permissions. Here is how to think through it.
Start from what a shared login actually means
It is worth saying plainly, because it changes how you plan: if your church has one username and one password for the database, anyone who has been given that password can open anything in it. That includes the giving history, the follow-up board, and the pastoral care cases. There is no toggle that shows the volunteer coordinator the serving schedule and hides the care notes from her at the same time. If she is logged in, she can click through to anything you can.
That is not a flaw unique to one product. Most software built for a congregation of 60 to 250 people skips staff roles and permissions on purpose, because building and maintaining a permissions system is real engineering weight for a problem that size of church rarely has — usually one or two people manage the whole database anyway. The tradeoff is that access control becomes a people decision, not a technical one. Knowing that up front is more useful than being surprised by it later.
Decide who actually needs the password
The real question is not “who should see pastoral care notes” in the abstract. It is “who has the login,” because those are the same list. For most churches this size, that is a short roster: the pastor, maybe an associate pastor, and whoever keeps the database current day to day, often a part-time secretary. A volunteer coordinator who only needs the serving schedule and a background-check alert does not need the login at all — she needs a printed roster or a text message, not database access.
It is tempting to hand the login to more people because it is convenient — the treasurer wants to see who gave what without asking, a small-group leader wants to check attendance herself. Each of those requests is reasonable on its own. Add them up and you have quietly turned a one-person login into a five-person one, and pastoral care notes are sitting behind it the whole time.
Separate “needs to know something happened” from “needs to read the note”
Care almost never stays contained to one person. A family going through a hospitalization needs meals organized, which means the meal-train volunteer needs to know something is going on. That does not mean she needs to read the case file. The habit worth building is: information that helps someone serve well travels by conversation — a text, a hallway word, a line in a staff meeting — and the written case note stays with whoever is actually doing the pastoral follow-up.
- The person doing follow-up writes and reads the full note: what was said, what was promised, what is next.
- People helping practically — meals, rides, child care — get only what they need to act, passed along verbally.
- Everyone else gets nothing, not because they are not trusted, but because it is not theirs to carry.
This is the same discipline that applies to running a good church directory your team trusts — the value of the record depends on people believing it will not be casually browsed.
Write notes for the reader, not for yourself
Because a shared login means anyone with access could, in theory, open a case note, it is worth writing every note as though someone other than you might read it — even if in practice only two people ever do. That changes what goes in it. Facts that move the care forward belong in the note: what happened, what was offered, what the next step is. Detail that is only there because it was told to you in confidence, and does not change what anyone does next, usually does not need to be written down at all.
This is not about being vague or clinical. It is about discipline: a note that says “financial strain following job loss, following up on assistance fund, next check-in scheduled for the 14th” carries what the next conversation needs. A note that also repeats the specific number on a bank statement does not add anything useful and is one shared password away from being read by someone who had no reason to know it.
Build the human boundary you cannot build in software
Since the system will not stop a volunteer coordinator from opening a care case if she has the login, the boundary has to be a spoken agreement, kept the same way small churches keep most of their trust — because people said they would. That usually means a short, explicit conversation, not a written policy nobody reads: whoever has the password agrees that pastoral care is a section they do not open unless it is their job to be in it, the same way a volunteer with a key to the building does not go through the filing cabinet in the office just because the door happened to be open.
It helps to say this out loud when you hand someone the login, not assume it is obvious. “You have access to everything in here, including care notes. Please only open that part if you are the one following up.” That one sentence, said once, does more than any setting would.
Keep the circle small on purpose, not by accident
The number of people who hold the login tends to grow slowly and without anyone deciding it should. A new part-time hire gets it because it is easier than asking someone else for reports. A long-serving volunteer gets it because she has earned trust over fifteen years. Each addition is defensible. The compounding effect is that the list of people who could open a pastoral care case gets longer every year, while the number of people who actually should never grew at all.
A useful habit, worth folding into your weekly church admin rhythm, is to periodically ask out loud: who currently has this login, and does each of them still need it? It is a five-minute conversation, not an audit, but it is the only thing standing between a small, trusted circle and a login that quietly ended up in a dozen hands.
What this looks like day to day
In practice, most churches this size land somewhere sensible: the pastor and the person who manages the database day to day hold the login and the care notes that come with it. A volunteer coordinator, worried about running her serving team without burning people out, gets what she needs about who is available and who has a background-check flag — not access to pastoral cases she was never meant to read. SundayBridge keeps every case discreet by keeping it in its own section of the record, with comments and history attached to the person, not scattered across a spreadsheet tab someone forwarded once and never deleted. What SundayBridge cannot do is decide, on your behalf, who deserves to be trusted with the password. That part is still yours.
The boundary is a decision, not a default
Nobody at a church of 90 people wakes up intending to let pastoral care notes drift into the wrong hands. It happens the quiet way most access problems happen: a password shared for convenience, a login handed to a new volunteer because asking someone else felt like a hassle, nobody ever circling back to ask who still needs it. Deciding on purpose who holds the login, saying the boundary out loud, and revisiting it once in a while costs less than the conversation you would rather not have after someone reads something they should not have.