Church Cashbook Data Schema Manual
System-wide invariants that must remain true for audit and reporting.
System invariants
- Void-not-delete: transactions are voided with reason and timestamp; totals exclude voided items.
- Opening balances per FY: reports start from opening balance for the selected financial year.
- Default FY filtering: transaction lists must default to FY to keep performance and usability.
- RBAC scope isolation: a user must never see or mutate another church’s records without explicit scope.
- Receipts: stored paths must be system-managed; uploads must be MIME-validated; downloads must set safe headers.
Governance notes
- Admin privileges should be minimal and auditable.
- Superadmin-only areas (logs, snapshots, dev tools) must stay locked down.