Appearance
Roles and access
Access is granted by roles, and a role is granted within a scope. The scope is an institution, a library, a store, or the whole platform.
Permissions
Permissions are organised by page. Most pages have view, add, edit and delete, and many add their own, for example:
| Page | Examples of extra permissions |
|---|---|
| Students | view profile, view achievements, manage wallet |
| Teachers | import, assign classes, assign subjects |
| Course Tracking | log progress, allocate students, view reports |
A role is a set of these permissions. Manage roles in Roles & Access (institution) or Super Admin → Access (platform).
How far a permission reaches
Each grant also has a data scope:
| Data scope | Sees |
|---|---|
| All | Every record in the scope |
| Assigned | Records for the classes, subjects or students the person is assigned to (for a mentor, their mentees) |
| Own | Only the person's own records |
A class teacher with Attendance → add at Assigned can mark attendance for their classes and no one else's.
Features beat permissions
If a feature is switched off for an institution, its pages are hidden and refused for every role, administrators included. Nobody can be granted a page the institution doesn't run. See Institution types and features.
Where it is enforced
Permissions are carried in the signed-in session and checked by the database on every read and write. Hiding a menu item is a convenience; it isn't the security. Changing someone's role takes effect on their next request, without them signing out.
Common set-ups
| Person | Suggested grant |
|---|---|
| Institution administrator | The administrator role, data scope All |
| Class teacher | Students (view), Attendance (view, add), Exam marks (add): Assigned |
| Subject teacher | Exam marks (view, add), Question bank: Assigned |
| Accountant | Accounts, Wallets: All |
| Hifz mentor (Ustadh) | Course Tracking (view, log progress): Assigned |