Church Cashbook Admin Manual
How the admin area is organised, and what “read-only” means for administrators.
Read / write / edit / delete
- Read-only pages let you inspect data without changing it (e.g. transactions list).
- Edit actions are limited to governance-safe operations (e.g. mark a user dormant; adjust role assignments).
- No delete for core records. This protects audit integrity and simplifies examiner review.
Visibility and permissions
The Admin menu is only visible to users with a SUPERADMIN or DIOCESE_ADMIN role. Even when the menu is visible, every action is enforced server-side — a user cannot bypass RBAC controls by manipulating URLs. If an action would be outside a user's permitted scope, the server will reject it regardless of how the request is made.