You oversee every case, invite people, restrict the rare sensitive case, and read the reports. This is the whole system in ten minutes.
Tend is where we record and follow up pastoral care. It answers four questions: who is being cared for and how urgently; who owns each case and what happens next; is anyone falling through the cracks; and what patterns show up by community group.
It is private and invitation-only. It is not a chat app, not a diary, and not an emergency service.
There is no password. Each time you sign in, Tend emails you a link.
Open tend.citylightsdubai.org on your phone or computer. Add it to your home screen — it behaves like an app.
Within a minute you’ll get an email from Tend <Ryan@citylightsdubai.org> with a Sign in to Tend button. Tap it.
The link works once and expires after 15 minutes. If it’s expired, just request another.
You land on your dashboard and stay signed in on that device for about a week. After that, request a new link.
Nothing arrived? Check spam once, then make sure you typed the exact address you were invited with. If it still doesn’t come, ask Ryan to check you are active in Admin → Users.
Why no password? A password can be guessed, shared or written on a sticky note. A link that only reaches your inbox can’t. It is also what lets us switch someone off instantly if a phone is lost.
As an administrator you have a My cases / All cases switch. My cases is what you are personally on; All cases is the whole church’s caseload (except restricted cases you are not named on — more below).
Every case carries a colour. Four people grading the same situation four different ways would make every report meaningless, so these definitions are shared and printed wherever you choose a colour. Tap a card.
Tend is a record-keeping tool, not an emergency service. If there is immediate risk to someone’s life or safety, contact emergency services first, then record it here.
Tap + New case. It is three short screens and should take under two minutes.
Search first. Type the person’s first name or surname. If they already exist, pick them — that keeps one person’s history together and avoids duplicates. The search shows names and community group only, never anyone’s case history.
If they are new, add first name, surname, and anything you know (preferred name, phone, community group).
Choose the care level (colour — the definitions are right there), the category (emotional / marriage / family / grief / spiritual / addiction / trauma / other), the care type (pastoral, professional, or both) and whether escalation is needed.
If you’re torn between two colours, pick the higher one and say why in the update — it is easy to come down later.
Name the go-to person (who coordinates this care — usually you), add anyone else walking with them, and tag an administrator.
Then write two things in plain words: Where things stand and What happens next, and set the next follow-up date. That date is the heartbeat of the system: Tend emails you the morning it arrives, and flags the case if it slips.
As an administrator you don’t have to tag anyone — but do tag a second admin on anything orange or red, so it is never only in one head.
Write as if it will be read later by someone who wasn’t there — because it will be, and because updates are permanent. Facts, what was said, what was agreed, what worries you. Initials are fine for third parties.
Open the case → Post update. This is the thing you will do most, ideally from your phone right after a conversation.
Everyone attached to a case. The go-to person coordinates; others walk alongside. Anyone on the case can add someone; the go-to can only be changed by reassigning. Only an administrator can add a Team member to an orange or red case.
“Can you look at this?” Ping a colleague on a case; they get a bell notification and an email, and acknowledge it so you know it landed. Use it instead of WhatsApp for anything about a person in care.
Private notes-to-self with a date and time (“call back Thursday”). Nobody else can see them — not even administrators. Tend emails you when one is due.
The bell holds everything in-app. Emails go out for new cases, updates on your cases, pings, follow-ups due that morning, and a Monday-morning digest of what you are carrying. Emails contain the case reference and the person’s name — treat your inbox accordingly.
You have an Admin tab (and People, Reports). Here is what each does and when to reach for it.
Admin → Users → Invite. Enter name, email and role. Their account is created immediately and they receive an invitation email; they sign in with a magic link like everyone else.
Deactivate switches someone off instantly (all reads denied, sessions ended) but never deletes them — their name must stay on the updates they wrote. Reactivate any time. You can’t deactivate yourself, and there must always be at least one active administrator.
Anyone can fix their own display name on the Account page; you can rename anyone from Users.
Admin → Groups. Add a group with its leader’s first name and surname (stored permanently, so trends stay readable even after a leader moves on). Add groups as cases arise — not every group needs to exist on day one. Archive rather than delete.
For the rare case too sensitive for the whole admin group (e.g. involving staff, or a safeguarding matter). Open the case → Restrict → name exactly three administrators including yourself → reason. Instantly:
Any of the three can lift the restriction later. Requires at least three active administrators to exist.
Admin → Handover. When a pastor goes on leave or moves on, reassign all their open cases to someone else in one step. Each case gets a timeline entry and the new go-to is notified. For a single case, use the star on the care team panel.
Reports: category × colour, workload per carer, monthly volume, and success stories (only cases resolved with the success flag — meant to be read aloud in a meeting). CSV export downloads the non-restricted caseload for a period; every export is logged with your name, so export when you need to, not out of habit.
Admin → Audit. Who signed in, who viewed what, every change, every export. Filter by person, case or action. If something ever feels wrong, this is where you look first. It is append-only; nobody — including the developer — can edit it.
Five questions, instant answers. Nobody sees your score.
A pastor opens a case and tags you. Who can see it?
You restrict a case and name three admins. What does a fourth admin see?
A red case has had no update for eight days. What happens?
Someone leaves the team. What do you do?
Can you edit a mistaken update?
Tick these off as you go — this page remembers them on this device.
Can’t sign in? Request a fresh link; check you used your invited address; then ask Ryan to confirm you are active.
Not sure what colour? Choose the higher one and write why.
Something looks broken? Tell Ryan what you were doing and roughly when — the team can see errors and logs.
Pastoral questions (who should own this, should this be restricted): Ryan.