Church Cashbook Data Schema Manual
Roles, scopes, and schema touchpoints that enforce access boundaries.
Role and scope model
RBAC is enforced via role assignments across one of three scopes:
- Global — system-wide roles (e.g., superadmin).
- Deanery — multi-church grouping role scope.
- Church — specific church scope (most common).
Schema touchpoints
- users — user identities and login state.
- roles — role catalogue.
- user_role_assignments — the RBAC grants (scope-aware).
ERD
Do-not-break: Every endpoint that queries scoped tables must always constrain by
church_id (or equivalent scope) and verify the effective user permissions.