7-Level Permission Matrix with Complete Data Isolation Per Role
Not everyone should see everything. Our RBAC engine provides granular, role-based access control across 7 distinct roles — each with precisely defined permissions for every module, page, and data field. Complete data isolation ensures staff only see what they're authorized to see.
The platform ships with seven pre-configured roles, each designed for a specific user type in the academy ecosystem. Super Admin (platform owner) has full control across all tenants. Academy Owner manages their single academy with all modules. Branch Manager controls a specific branch with limited financial access. Teacher sees their assigned classes and students only. Accountant accesses financial modules without academic data. Parent views their own children's data. Student sees only their personal academic information.
Each role is a collection of permissions across all system modules: attendance, CRM, HR/payroll, timetable, academics, finance, settings, and reports. Permissions are defined at three levels: View (can see data), Edit (can modify data), and Manage (can configure settings and add/delete records). This granularity allows you to create exactly the access pattern your academy needs — for example, a Senior Teacher who can edit attendance but not delete students.
Teachers only see students in their assigned classes — they cannot search for, view, or edit records of students in other classes. Branch Managers only see data for their branch, not other branches. Parents see only their own children, never other students. This isolation is enforced at the database query level, not just at the UI level — even if someone manipulates the frontend, the backend will never return unauthorized data.
The system includes a comprehensive audit log that records every data access and modification: who accessed what, when, from which IP address, and what changes were made. This audit trail is essential for compliance, investigation of data breaches, and accountability. Administrators can review access patterns and flag suspicious activity.
Beyond the seven default roles, administrators can create custom roles tailored to their academy's unique organizational structure. Need a "Librarian" role that can manage book inventory and student borrowing records but nothing else? Or a "Sports Coach" who can only access attendance for their team and the sports facilities module? Create it in minutes by selecting the appropriate permission checkboxes.
Role assignment is managed per-user with effective date support. When a teacher is promoted to Department Head, their role changes take effect immediately, and all permission changes are logged. Temporary role elevation (granting temporary admin access during an emergency) can be set with an expiry date, ensuring permissions automatically revert after the specified period.
Start your 7-day free trial today. No credit card required.
🚀 Start Free Trial