Security & IT
Role-based access control: keeping school data on a need-to-know basis
Teachers, finance, admissions, and families should each see a scoped workspace - with audit trails when sensitive records change.
Not reviewed by a named subject-matter expert. This piece passed our automated checks for dated evidence, working internal links, and claims that stay inside what the product does, see our editorial standards.

Least privilege is not optional
Student records, fee balances, and payroll data require different access patterns. A teacher’s homeroom scope should not expose school-wide finance; a bursar should not edit exam papers.
What Schoolyi enforces
- Permission matrix gating pages and API routes
- Teacher scoping to assigned classes and subjects
- Parent access limited to linked children
- Activity log with export for operational review
- Secure session auth with password reset flows
Operational trust
When staff know the system enforces scope automatically, they spend less time requesting access and more time serving students.
Frequently asked questions
Straightforward answers for visitors evaluating the product.
Which roles should see student data?+
Each role should receive only the pages, records, and actions needed for its work; teachers, finance, admissions, and guardians have different scopes.
Test both permitted and denied access with representative accounts, including exports and linked-family views.
Does role-based access replace an access review?+
No.
Schools should test allowed and denied routes, exports, family links, and role changes with representative accounts.




