Journal

Who should see a pastoral note? Getting church-care privacy right

July 2026

Every church that keeps any kind of care record eventually runs into the same quiet problem: not every note belongs to everyone. A note that a family is bringing a meal to someone after surgery is fine for the whole care team to see — it's practical coordination. A note that a marriage is struggling, written by the pastor who's counseling the couple, is not. Treat both the same way and you get one of two bad outcomes: either the sensitive note gets left out of the record entirely, which makes the record incomplete and unreliable, or it goes in anyway and becomes visible to people who had no reason to know.

The shared-spreadsheet problem

A shared spreadsheet makes this worse by design, not by accident. Everyone with the link sees everything in it — there's no in-between. So a well-meaning care team ends up self-censoring, quietly agreeing not to write down the things that matter most, because writing them down means everyone on the team reads them, including people the person confiding in a pastor never agreed to be known by. The record that results looks complete but isn't. It holds the logistics and leaves out the substance, which means the next person who needs context — a new pastor, a visiting elder, the person's own pastor six months later — gets a thin, sanitized version of a much fuller story.

The damage isn't hypothetical. A staff member who finds out a sensitive note about their own family was visible to the whole volunteer care team loses trust in the church's ability to hold anything in confidence — and that trust, once broken, is hard to rebuild. The fix isn't to stop taking notes. It's to stop treating all notes as one category.

A simple framework for visibility

Most pastoral notes fall into one of three buckets, and the useful exercise is asking, before writing anything down, which bucket a given note belongs in. Shared with the team is for anything the whole care group needs to coordinate around — a meal train, a hospital visit schedule, a general prayer need someone's comfortable being known for. Private to the writer is for a pastor's own working notes — impressions, follow-up reminders, things useful for that one person's memory but not meant as a team record. Confidential to clergy is for anything disclosed in real confidence — a marriage struggle, an addiction, a crisis someone trusted one pastor with specifically, not the volunteer team at large.

The framework only works if it's easy to apply in the moment. If marking a note confidential takes extra steps or requires switching to a different system, it won't happen consistently — the sensitive note will either get typed into the shared record by default, or not written down at all. The visibility choice has to be as fast as writing the note itself.

How Shepherd implements it

Shepherd builds this framework directly into how a note gets written, not as an afterthought. Every note carries one of the three layers — shared, private, or confidential to clergy — chosen at the moment it's created, with no separate system or extra step required. A shared note appears in the person's care history for the whole team. A private note stays visible only to the person who wrote it. A confidential note is walled off to clergy, so a sensitive disclosure stays exactly as protected as it needs to be, while still living in the same record instead of existing only in one pastor's memory or a private notebook nobody else can find later.

The goal isn't more privacy for its own sake — it's a record the whole team can trust, because everyone knows what they're looking at when they read it. A note marked shared can be acted on by anyone. A note marked confidential can be trusted to stay that way. That distinction is what makes a shared care record actually usable, instead of quietly incomplete.

Write notes your team can trust — shared, private, or confidential, by design.

Try Shepherd free