Relius guidebook
Documentation
Clear steps for the people, practices, and tools that help your church stay connected.
User Management
Quick Summary: Add users and review the access controls currently available for your workspace. Confirm each person's effective permissions before granting access to sensitive records.
Overview
User Management is where you organize team access in Relius. Available roles and permission boundaries vary, so test each person's effective access with non-sensitive records rather than assuming a title creates a precise boundary.
User access may be organized around roles such as Admin, Staff, Leader, or Member, with additional controls depending on the workspace and plan. Treat role labels as a starting point: test the effective access of each role and apply least privilege before inviting real users.
Additional security options such as two-factor authentication, activity logs, session controls, or bulk operations may depend on the current product configuration. Confirm availability and scope in your workspace before incorporating any option into a security or audit procedure.
Key Concepts
- User Account: A unique login with email and password that grants access to Relius
- Role: A predefined set of permissions (Admin, Staff, Leader, Member) that determines what a user can do
- Permissions: Specific capabilities like "view donations," "edit events," or "send communications"
- Two-Factor Authentication (2FA): A security feature requiring a secondary verification code in addition to password
- User Activity Log: A record of what actions a user performed and when
- Session: An active login period whose timeout and revocation behavior should be confirmed
Getting Started
Step 1: Access User Management
From your dashboard, navigate to Administration → Users and review the account, role, status, and activity fields currently available.
Step 2: Invite a New User
Click Add User in the top-right corner. Enter the person's name and email address, then select their role. For new staff members, choose "Staff" and customize specific permissions on the next screen. For volunteer leaders who need limited access, choose "Leader." Click Send Invitation to email them a signup link.
Step 3: Customize Permissions
After selecting a role, review the default permissions and adjust as needed. For example, a staff role might default to full access to People, Groups, and Events but restricted access to Giving. If your new worship pastor shouldn't see financial data, uncheck "View Giving" and "View Donor History" before sending the invitation.
Step 4: Review Additional Sign-In Protection
For users with administrative or financial access, check whether two-factor authentication is currently available and how enrollment and recovery work. If it is not available, document compensating controls and contact support about current sign-in options.
Features
User Roles Explained
Relius provides four standard roles, each with progressively broader permissions:
Member
A Member role may support self-service portal features. Test what a representative member can view or change in the current configuration, especially other people's information, giving, directories, and administrative routes.
Leader
For volunteer leaders like small group hosts, team captains, or ministry coordinators who need limited administrative access. Leaders can manage their specific group or team, view contact information for members assigned to them, send communications to their group, and track attendance. They cannot access financial data, edit church settings, or manage other groups.
Example: A small group leader gets a Leader account with permissions to view members in their group, send group emails, update group meeting times, and track attendance. They can't see other small groups or access the church's full member directory.
Staff
For paid staff and key volunteers who need broad access across multiple ministry areas. Staff can typically view and edit members, manage groups and events, send communications, schedule volunteers, and access reports. By default, Staff cannot view giving/donations, change church settings, or manage other users—but you can grant these permissions selectively.
Example: A children's ministry director gets a Staff account with full access to People, Groups, Events, Volunteers, and Communications. You disable access to Giving and Administration so they focus on their ministry area without exposure to sensitive financial or administrative functions.
Admin
Administrative access can include sensitive settings and data. Confirm the effective permission set, keep the group small, and require separate approval for financial or billing access where possible.
Security Note: Treat administrative roles with caution. Review their effective permissions, limit the number of admins, and use the strongest sign-in protection currently available.
Adding Staff and Admin Users
When you click "Add User," you'll enter their full name and email address. Relius sends an invitation email with a secure signup link. The user creates their password, completes their profile, and immediately gains access according to their assigned role and permissions.
For bulk onboarding (like adding 10 new staff members after a church merger), use the "Bulk Invite" feature to upload a CSV file with names, emails, and roles. Relius processes the list and sends invitations to everyone at once.
Role Permissions Matrix
Permissions are organized by functional area. When creating or editing a user, you'll see permission categories like:
- People – View, create, edit, delete member profiles and families
- Groups – Manage small groups, view rosters, track attendance
- Events – Create events, manage registrations, view check-in data
- Giving – View donations, access donor history, generate receipts
- Communications – Send emails and SMS, view message history
- Volunteers – Schedule teams, view availability, send reminders
- Reports – Access analytics, export data, view dashboards
- Administration – Manage users, edit church settings, configure integrations
Permission detail varies by product configuration. Review which categories, actions, and scope restrictions are actually offered, then test them with a non-sensitive account before rollout.
Two-Factor Authentication Setup
Two-factor authentication can add a second verification step beyond a password. If Relius offers it for your workspace, review the supported authenticator and account-recovery process before requiring enrollment.
Follow the sign-in security controls visible in the user profile. Interface labels and verification methods can change, so test enrollment and recovery with a staff account before publishing internal instructions.
Best Practice: Apply the strongest sign-in protection available to administrators and staff handling sensitive data, supported by a documented recovery process.
User Activity Logs
If activity logging is available, review the events currently captured from the user or security area. Do not assume views, edits, exports, or communications are all recorded.
If activity logs are available, confirm which events, fields, and access actions they capture and how long entries are retained. Logs can support an investigation only within that verified scope.
Illustrative example: A leader investigates a changed event time. Staff review any available activity record, compare it with other evidence, and contact the relevant users rather than assuming the log is complete.
Advanced Features
Custom Roles
If custom roles are available, build one from the minimum permissions needed and test its effective access. Do not assume a category label prevents access through reports, integrations, exports, or linked records.
Temporary Access Grants
If temporary access is available, use an expiration date and verify that access is removed as expected. Otherwise, create a manual removal task and have a second administrator confirm completion.
Delegation and Substitute Users
If delegated access is available, confirm its scope, expiration, and logging behavior before use. Avoid sharing credentials; create a distinct account for the interim user whenever possible.
Access Request Workflow
Enable self-service permission requests: a Leader can request temporary Staff access for an upcoming event, triggering an approval workflow to an Admin. This reduces bottlenecks while maintaining administrative oversight.
Single Sign-On (SSO) Integration
Ask Relius support whether single sign-on is currently available for your plan and identity provider. Confirm provisioning, deprovisioning, group mapping, recovery, and audit behavior before relying on it.
User Deactivation vs. Deletion
When staff leave, use the account status options currently available and verify that sign-in access has ended. Before deleting an account, confirm what historical associations or logs would be affected and consult the church's retention and privacy process.
Scheduled Permission Changes
Schedule permission changes to take effect at a specific date/time. For example, when promoting an intern to full-time staff next month, schedule their role upgrade to coincide with their start date. Useful for coordinating access changes with personnel transitions.
Best Practices
- Use the principle of least privilege – Grant only the permissions necessary for each role
- Use the strongest sign-in protection available – Prioritize administrators and staff handling sensitive data
- Review user access quarterly – Remove departed staff, adjust permissions for role changes
- Document custom permission decisions – Keep notes explaining why certain users have non-standard access
- Test new user accounts before sending invitations – Create a test Staff account to verify permissions work as expected
- Use groups when available – Test inherited permissions before assigning people in bulk
- Review available activity records – Confirm their scope before using them in an access review
- Establish an offboarding checklist – When staff leave, immediately deactivate their account, review their activity logs, and document their final actions
Common Questions
Q: Can someone have multiple roles?
A: The role and permission model can vary by plan and release. Review the controls currently available, test effective access with a non-sensitive account, and contact support before designing a custom access model.
Q: What happens when we deactivate a user account?
A: Confirm how deactivation affects active sessions, integrations, historical attribution, and reactivation in the current product. After deactivation, verify sign-in is blocked and review any sessions or tokens separately.
Q: Can users change their own permissions?
A: Test this with each role in your workspace. Permission management should be restricted to approved administrators, but the effective controls must be verified in the current configuration.
Q: How many admin accounts should we have?
A: Aim for 2-4 admins: typically the senior pastor, executive pastor, and one or two key office staff. Too many admins create security risks; too few creates bottlenecks when admin actions are needed.
Q: What if someone loses their 2FA device?
A: Follow the recovery options currently presented by Relius and confirm the requester's identity before resetting sign-in protection. Contact support if the available recovery path is unclear.
Q: Can we see what a user is currently doing in real-time?
A: Logging and active-session visibility vary. Confirm which actions and sessions the current dashboard exposes, its retention period, and any gaps before relying on it for an investigation.
Related Topics
- User Roles & Permissions – Understanding access levels
- Security Settings – Password policies, audit logs, session management
- Church Settings – Configuring church-wide preferences
- Administration Overview – All administrative features
- Setting Up Your Church – Initial setup guide
