Roles & permissions
Built-in roles, custom roles, restore defaults, and the two access layers.
Roles answer two different questions. First: which sections can this user open, read, write, delete, or manage? Second: which specific people, requests, plans, tasks, and notes can this user see? Epimely keeps those separate so a church can share work without broadly exposing private details.
Every church starts with five built-in system roles. Admins can rename them, enable or disable non-admin roles, restore built-in defaults, and create custom roles with their own section permissions.
How to
Know the built-in roles
Admin manages the church account and can enter elevated admin mode. Pastoral Care Leader works care across people, requests, plans, forms, tasks, and reports. Pastoral Care documents care, starts forms, uses groups, and works assigned people. Queue Manager routes requests and monitors queues with identifying details redacted. Viewer sees only anonymous request queue rows.
Understand section permissions
Each role has View, Read, Write, Delete, and Manage controls per section. View makes the section visible in navigation and lets the route open. Read allows lists, detail pages, and records to load, still limited by church, assignment, access grants, and server-side redaction. Write creates or edits records. Delete allows destructive actions such as delete, archive, or removal. Manage controls section configuration such as roles, statuses, flags, templates, exports, or settings.
Use View and Read intentionally
View and Read are separate so a church can expose a section shell, workflow entry point, or navigation item without automatically returning record data. In most day-to-day roles they should be enabled together. A role with View but no Read may open the page but should not receive the section's records from the API.
Use Viewer as the safe default
Viewer is the built-in read-only baseline for staff, auditors, board members, or training users who need limited request awareness without changing church data. Viewer can see anonymous request queue rows, but cannot open request details, see PII, create, edit, delete, manage settings, bypass redaction, or access confidential care beyond the normal privacy model.
Rename and restore roles
In Settings -> Roles, select a role to edit its display name and permissions. Built-in roles can be renamed. Restore defaults puts a built-in role's name and permissions back to the system defaults: Admin, Pastoral Care Leader, Pastoral Care, Queue Manager, and Viewer.
Enable or disable roles
Admins can disable non-admin roles when they should not be assigned. Admin itself stays protected so the church is never locked out of account management.
Assign users
In Settings -> Users, choose the role for each user. Role changes revoke active sessions so the new permissions apply cleanly on the next sign-in.
Manage user access
Admins can reset a user's password, deactivate or reactivate them, soft-delete them, and reassign their open care requests, tasks, and care plans to another care assignee.
Tips
- Role section access never bypasses church scoping.
- Custom roles do not inherit system-only powers like admin elevation, confidential access, or Queue Manager redaction unless the underlying built-in role grants them.
- When in doubt, keep broad access off and use assignment or access requests for specific cases.
Role management is admin-only. Sensitive settings changes and exports require admin mode.