Access scoped to your church
Organization boundaries and database row policies form the primary authorization layer. This is not a visual filter.

Church data can include family relationships, care details, children’s check in, giving records, staff conversations, and member identity. Cemstree is designed so access follows a person’s role and church context.
Organization boundaries and database row policies form the primary authorization layer. This is not a visual filter.
Staff, pastors, leaders, members, and check in workers receive different access based on their job.
Pastoral notes and sensitive records are isolated from broad workspace visibility.
Audit and activity history keep operational changes connected to a durable record.
Restricted kiosks, guardian context, digest only security codes, labels, and checkout support child safety workflows.
Consent, opt outs, provider routing, replies, and delivery state are treated as operating requirements.

Reports surface incomplete contact data, possible duplicates, missed attendance alerts, unassigned care, registrations waiting, and delivery failures so problems can be handled deliberately.
Organization scope, role checks, database policies, and audit history work together so each record stays visible to the appropriate people.