Understanding Team Roles & Permissions

Last updated: August 4, 2026

WeGive now supports role-based access control, so you can give every member of your team exactly the level of access that fits their job — no more, no less. This article covers the two places you'll manage access — Team and Roles & Permissions — breaks down each built-in role, and shows you how to build a custom role.

Managing your team

You can view and manage your team from the dashboard:

  1. Go to Settings → Team (under Organization).

  2. You'll see each team member, their current Role, and their Status (Active or Pending).

  3. To change someone's role, click the dropdown in the Role column and select a new role. The change takes effect immediately.

  4. To add someone new, click + Invite Member and choose the role they should have. They'll appear as Pending until they accept the invitation.

Seeing exactly what each role can do

Alongside Team, there's a dedicated Settings → Roles & Permissions page. It lists every role in your organization with a count of the permissions it grants. Click into any role to see the complete permission list, organized by area — Giving Data, Giving Elements, Communications, Automation, Money & Ops, Technical, Data & Customization, and Org Admin.

Roles labeled Managed are maintained by WeGive: they're kept up to date automatically and can't be edited or deleted, so their behavior is always predictable. If you need something different, you can create your own custom role (more on that below).

As you browse permissions, you'll notice small badges that flag what a permission touches:

  • pii — involves personal supporter information

  • financial — involves money, transactions, or billing

  • destructive — deletes or permanently changes data

  • capability — an action (like sending messages or issuing refunds) rather than viewing or editing

  • secrets — involves credentials, like API keys or integration passwords

These badges are a handy guide when deciding who should hold what.

The built-in roles

WeGive includes seven managed roles. Each grants exactly the access described below; anything not listed is off. For the precise permission-by-permission breakdown, open the role in Settings → Roles & Permissions.

Admin

Full access to everything — every feature and every sensitive action, including managing your team and their roles, WeGive billing and subscription, payment processor setup, integrations and credentials, API tokens, and rolling back audited changes.

Best for: The account owner or a very small number of trusted leaders. This is the "owner" role — give it sparingly.

Developer

Everything an Admin can do, except managing your WeGive billing and subscription. Built for a technical owner who needs to configure integrations, manage API tokens, install and embed snippets, set up custom fields, and manage redirects — without controlling the paid account.

Best for: A web developer, IT staffer, or technical consultant. Practically identical to Admin for day-to-day work, so treat it with similar care.

Finance

Owns the money. Full control over transactions (including refunds and voids), pledges, soft credits, payouts, funds, designations, pledge templates, reporting and exports, batch payment imports, payment settings, and WeGive billing. Other areas of the dashboard, like supporters, campaigns, events, and forms, are view-only — and areas like communications and team management are not included.

Best for: Your finance director, bookkeeper, or accountant.

Marketing

Owns outreach and giving experiences. Full control over campaigns, fundraisers, events, checkouts, forms, peer-to-peer templates, impact stories and impact numbers, pledge templates, all communications (messages and broadcasts, journeys, communication lists, conversations, email settings, phone numbers, RSS feeds, email health), tags and automation, notes, and reporting. Supporter records and financial data like funds are view-only, and areas like billing, integrations, and team management are not included.

Best for: Your marketing or communications team and campaign managers.

Customer Success

Built for the people who work directly with your supporters. Full access to supporter records (viewing, creating, and updating donor profiles), notes, and conversations, plus the ability to view and apply existing tags. Customer Success can also view transactions, messages, journeys, communication lists, campaigns, events, and forms — so they always have full context when answering supporter questions.

What it deliberately leaves out: financial actions (recording donations, charging cards, issuing tax receipts), creating or editing tags, running automations, and reporting exports. Customer Success can see the full picture but can't move money.

Best for: Support staff, donor relations coordinators, and anyone answering supporter questions.

Read-only

Exactly what it sounds like. Read-only members can view data across most of the dashboard — supporters, transactions, pledges, payouts, campaigns, communications, funds, and more — but every create, edit, delete, tag, and export action is blocked.

A few sensitive areas are hidden entirely, even for viewing: WeGive billing, payment and organization settings, integrations, developer tools, team and role management, and the audit log.

Best for: Board members, auditors, volunteers, or anyone who needs visibility without the ability to change anything.

No access

A zero-permission role. Members with No access can't view or do anything in the dashboard.

Best for: Temporarily suspending someone's access without removing them from your team — for example, a seasonal staff member between seasons, or a placeholder while you decide which role fits a new member.

Building a custom role

If none of the managed roles fits, create your own from Settings → Roles & Permissions → + New role:

  1. Give the role a name (e.g., "Event Coordinator") and an optional description.

  2. Choose a starting point: start from scratch, or start from any existing role (like Marketing) and adjust from there.

  3. Check or uncheck individual permissions across every area of the dashboard — each section has a Select all shortcut.

  4. Click Create role, then assign it to team members from the Team page.

Unlike the managed roles, custom roles can be edited or deleted anytime.

One important safeguard: you can only grant permissions you hold yourself. No one can create or assign a role with more access than their own.

Frequently asked questions

Can I change someone's role later?
Yes — role changes take effect immediately from the Team page. No need to re-invite anyone.

Can someone give another team member more access than they have themselves?
No. A team member can only assign permissions they hold themselves — this applies to managed roles and custom roles alike.

Can I edit the managed roles?
No. Managed roles are maintained by WeGive so their behavior is always predictable. Start a custom role from a managed role's template and tweak it instead.

What happens to a pending invitation if I change my mind about the role?
You can cancel a pending invite from the Team page and send a new one with the correct role.

What role should most of my team have?
A good rule of thumb: start with the most restrictive role that lets someone do their job, and move up only if they hit a wall. Reserve Admin and Developer for the few people who truly need them.

Questions about which roles are right for your team? Reach out to us — we're happy to help you map your team to the right access levels.