People and roles
Owners and org admins invite the team. Roles load from the church membership, not from a token claim.
The signed-in user is identified by login. What they may do comes from membership in this church. Super-admins work under /platform and are not a church role.
Church roles
| Role | In this church |
|---|---|
| Org owner | First key-holder. Invited by Kairos. Invites admins and the rest of the team. |
| Org admin | Same steward work as the owner for people, roles, and church settings. |
| Pastor | Invites colleagues and runs Sermon Flow. Knowledge Flow comes later. |
| Ministry worker | Serves in a live flow — today that is Sermon Flow. Does not assign roles. |
| Member | Belongs to the church workspace with a lighter seat. |
Inviting
Org admins send invites from People. Choose pastor, ministry worker, or member. The person must accept with the named email. Removing someone leaves the church; they can be invited again later.
Member QR
Staff with invite permission open Member QR on People and print one poster for this church. Visitors scan it, open /join/…, and ask for a Member seat. Applications show as Waiting until an admin approves — that sends the usual member invite — or rejects. Creating a new code retires the old printed poster.