Skip to content

Roles & Permissions Overview

Role-based access control (RBAC) lets you give each member of your team exactly the access they need — no more, no less. Instead of every user being a full administrator, you assign each person a role, and that role determines which areas of WeGive they can view, create, edit, and delete.

This protects sensitive data (supporter PII, financial records, integration credentials) and makes WeGive safer to roll out across a larger team.

Key concepts

  • Permissions are the smallest unit of access — a single action on a single feature, such as “view supporters,” “refund a transaction,” or “manage integration credentials.” WeGive defines a catalog of roughly 160 permissions across every area of the dashboard.
  • Roles are named bundles of permissions. WeGive ships six managed roles that cover the most common job functions, plus a No access state for members who haven’t been assigned a role yet.
  • Managed roles are maintained by WeGive and kept up to date as new features ship. They’re marked with a Managed badge and are read-only — their permission sets can’t be edited.
  • Custom roles can be created by an Admin when the managed roles don’t fit — pick exactly the permissions you want. See Custom roles.
  • Assignment happens per member: each team member is given one role, which you set when you invite them or change later from Settings → Team.

The six managed roles

RoleBest for
AdminOrganization owners and leads who need full access, including team and billing management.
FinanceFinance and operations staff working with transactions, payouts, pledges, and billing.
MarketingMarketing and fundraising staff running campaigns, events, communications, and automation.
DeveloperTechnical staff managing integrations, API access, data imports, and customization.
Customer SuccessSupport staff who work directly with supporters, notes, and conversations.
Read-onlyStakeholders who need visibility into non-sensitive data without the ability to change anything.

Every member’s access is determined by their role across the dashboard — navigation, pages, and individual actions are all gated by the permissions that role grants.

The Roles & Permissions viewer listing the six managed roles plus the No access state, each with its permission count.

Where RBAC applies

RBAC governs team members (your organization’s staff). It does not change how supporters access the donor portal — supporters only ever see their own records, which is enforced separately and is unaffected by roles.

Next steps

Support

Questions about access control or which role fits a team member? Email support@wegive.com.