Getting started
RBAC quick reference for admins
The roles that actually exist, what each can and cannot do, the four capabilities that ignore the role entirely, and where the interface and the API disagree.
Getting started guide for day and boarding schools.
Last updated August 29, 2026
Access in Schoolyi is decided by four things, and only the first is a role. The role name drives most module gates. The account type, derived from that name, decides which portal a person lands in. The staffType field on the employment record decides library and laboratory authority. Committee membership decides admissions and exam authority. An administrator who only ever looks at roles will misdiagnose a large share of access tickets.
What each role can do
| Role | Can | Cannot |
|---|---|---|
| Platform Admin | Everything, and the only role that may create users, edit roles, activate an academic year, or change settings | Approve a high-value fee waiver or refund - that is reserved to Principal and Vice Principal |
| Principal and Vice Principal | Classes and subjects, timetable structure and publishing, report card publishing, transport changes, promotions, certificates, year rollover, and fee approvals | Create users or edit roles. Vice Principal additionally cannot publish website content, being an editor rather than a publisher |
| Teacher | Mark the register for a class they are named homeroom teacher of, enter marks where an active assignment covers the class and subject, publish homework, and write notices | Open the timetable Generate, Tools, or Analytics tabs, publish report cards, or mark a class they only teach a subject in |
| Support Staff - Finance | Fee operations, finance screens, payroll totals, transport back office as read-only, and reports in the fee and finance domains | Generate academic or operational reports, or change transport records |
| Support Staff - Purchasing | Vendors, purchase orders, and inventory movements | Anything outside procurement and stock |
| Support Staff - Facilities | Inventory, classrooms, hostel, and mess records | Fee, academic, or roster changes |
| Support Staff - Lab Assistant | Laboratory records, equipment, and session bookings | Other operations modules |
| Student, Parent, Vendor, Transport | Their own portal only - learner screens, child-scoped family screens, own purchase orders, or duty screens | Any school operations screen; these accounts are redirected away from staff routes |
The four grants that are not roles
- Homeroom. The attendance register follows the Class teacher and Co-class teacher fields on the class record, edited at /classes. A subject assignment never grants it.
- Teacher assignments. Mark entry, timetable visibility, and exam participation all follow an active assignment for the current academic year, edited in the Configure step of /timetable.
- Committee membership. Admissions screens require the Admissions committee; exam coordination requires the Examination committee, and publishing results additionally requires its chair.
- staffType on the employment record. Librarian opens the circulation desk, LabAssistant opens laboratory equipment, and PRT, TGT, or PGT decide who may be made a homeroom teacher.
Common questions
Quick answers in plain language.
Where do I edit what a role is allowed to do?+
Nowhere, and this surprises most administrators. Every access decision in the product is made from the role name. The role record has a permissions column, but it is unused and nothing reads it, so /roles only manages the name, the description, and whether the role is active. Changing what somebody can do means moving their account to a different role at /users.
Which roles does the standard seed actually create?+
Platform Admin, Principal, Vice Principal, Teacher, Student, Parent, Vendor, Transport, User, five support staff roles - Finance, IT, Lab Assistant, Purchasing, and Facilities - and six boarding roles: Boarding Head, Warden, House Parent, Nurse, Security Officer, and Designated Safeguarding Lead. Notably it does not create a role called Admin, even though several screens treat that name as the office administrator.
Why does a new account see almost no navigation even with a sensible role?+
Because the role name did not map to an account type. Only Teacher, Principal, Vice Principal, and names beginning with Support Staff produce a staff account; Student produces a student and Platform Admin produces an admin. Every other role, including User, Transport, the boarding roles, and a manually created Admin role, leaves the user type empty, which hides most navigation and keeps the person out of the staff directory and teacher pickers.
Is there anywhere the interface and the API disagree?+
Two places worth knowing. The settings index shows a Roles and Permissions tile to the office Admin role, but /roles redirects anyone who is not Platform Admin and the API answers 403 - the tile is a dead end. In the other direction, admissions cycle and enrolment endpoints treat Principal and Vice Principal as in charge, while the admissions screens require Admissions committee membership, so an API call can succeed for somebody who cannot reach the button.
Related searches
School leaders and IT teams often search for: how to platform rbac reference in school management software, best school software onboarding for K-12 schools, Schoolyi platform rbac reference guide, school ERP go live checklist, migrate from Excel to school ERP, and school software training guide.

