Skip to content

Roles and access ​

Access is granted by roles, and a role is granted within a scope. The scope is an institution, a library, a store, or the whole platform.

Permissions ​

Permissions are organised by page. Most pages have view, add, edit and delete, and many add their own, for example:

PageExamples of extra permissions
Studentsview profile, view achievements, manage wallet
Teachersimport, assign classes, assign subjects
Course Trackinglog progress, allocate students, view reports

A role is a set of these permissions. Manage roles in Roles & Access (institution) or Super Admin → Access (platform).

How far a permission reaches ​

Each grant also has a data scope:

Data scopeSees
AllEvery record in the scope
AssignedRecords for the classes, subjects or students the person is assigned to (for a mentor, their mentees)
OwnOnly the person's own records

A class teacher with Attendance → add at Assigned can mark attendance for their classes and no one else's.

Features beat permissions ​

If a feature is switched off for an institution, its pages are hidden and refused for every role, administrators included. Nobody can be granted a page the institution doesn't run. See Institution types and features.

Where it is enforced ​

Permissions are carried in the signed-in session and checked by the database on every read and write. Hiding a menu item is a convenience; it isn't the security. Changing someone's role takes effect on their next request, without them signing out.

Common set-ups ​

PersonSuggested grant
Institution administratorThe administrator role, data scope All
Class teacherStudents (view), Attendance (view, add), Exam marks (add): Assigned
Subject teacherExam marks (view, add), Question bank: Assigned
AccountantAccounts, Wallets: All
Hifz mentor (Ustadh)Course Tracking (view, log progress): Assigned

Qurtuba Foundation · Sign in at app.qurtuba.in