Summary: Learn how the system applies member roles when users are invited to your Breeze database, including the critical differences between admin-initiated invites and self-service account creation.
Before You Begin
Who this applies to: This update specifically clarifies functionality for Breeze accounts (organizations that have not yet migrated their billing and do not have access to the new Groups tab).
Security Update: To protect your database from unauthorized access, the system now uses two distinct logic paths for assigning roles to new users depending on whether an admin is involved in the process.
Understanding the Two Invite Flows
1. Admin-Initiated Invites
When an admin manually kicks off the action to invite a user (e.g., sending an invite directly from the database), the system will use whatever standard member role you have set for them (such as "Member" or "Member Deluxe").
Because an admin is explicitly authorizing this person, the role does not have to pass the strictest security checks required for public sign-ups.
This functionality has been fully restored to work exactly as it did previously.
2. Self-Service Invites (No Admin Interaction)
When a user creates an account entirely on their own, the system will automatically force them into the highly restrictive Default Member Access role. This applies to users creating an account via:
The login page
The online giving page
A public link you share
Because there is no admin actively vetting the user during these interactions, the system defaults to this locked-down role to prevent fraudsters or bad actors from accessing sensitive congregation data.
Troubleshooting & FAQs
Why did my member invite flows temporarily break recently? During the recent rollout of Groups, the system began looking for a mandatory "Default Member Access" role across all invite flows. Because unmigrated accounts do not have the Groups tab or new purchase flows, this default role was never systematically auto-generated for your account, causing the admin invite flows to fail. We have updated the logic so your admin-initiated invites work smoothly again without requiring that specific default role.
Can a self-service user be given a higher role? Yes, but not automatically. When a user self-registers, they will always start with the highly restrictive Default Member Access role. An admin must then log in and manually upgrade their permissions if they need greater access.