Operations
File manager
School drive, incoming shares, outgoing share links, and public token links.
Operations guide for day and boarding schools.
Last updated August 29, 2026
The file manager is an internal document repository with folder hierarchy, upload, rename/move, and share links. Access is role-gated for school file-manager users.
Treat it as one shared school drive rather than personal storage. There is a single folder tree on the application server, and every staff user who can open /files sees all of it - there are no per-folder permissions. Confidentiality is achieved by not putting a document in the drive at all, or by sharing a specific item with named people through a link. Upload is capped at 20 MB per file, and paths are resolved against the drive root so a crafted filename cannot escape it.
Screens
- /files - school drive (folders, upload, preview, bulk select)
- /files/incoming - files and folders shared with you
- /files/outgoing - share links you created (copy, revoke, expiry)
- /files/shared/[token] - public share link page for external recipients
Who owns it
The drive is open to staff and administrator accounts, plus the Teacher, Admin, Platform Admin, Principal, and Vice Principal roles. Students, parents, and vendor portal users are refused at the API, so a document put in the drive is never visible to a family unless someone deliberately creates a share link for it. Share links are owned by whoever created them: only the creator sees the link on /files/outgoing and can revoke it there.
What the drive can do
- Create folders, upload, rename, move, and delete files and folders.
- Select several items and download them together as a single zip.
- See total storage used, and the size of an individual folder on request. Both walk the tree, so they are slow on very large drives.
- Keep previous versions: uploading over an existing filename archives the old blob into a hidden versions store first, and you can list or restore earlier versions of that path.
Share links
| Sharing type | Who can open the link |
|---|---|
| PUBLIC | Anyone with the token URL, no login |
| ORGANIZATION | Any signed-in user of the app |
| INDIVIDUAL | Only the users whose email addresses you listed when creating the link |
- Each link gets a long random token and is served from /files/shared/[token].
- Optional controls: a password (checked through a header on every fetch), an expiry timestamp, and a maximum download count.
- An expired link returns 410 and a link past its download cap returns 403, both with a clear reason rather than a generic error.
- Creating an INDIVIDUAL share fails if any address you type does not match an active user, so the link is never created half-configured.
- View and download counters are recorded per link, and the token endpoint is rate limited per IP address to blunt token guessing.
Limits
- No per-folder or per-role permissions inside the drive.
- No approval or retention policy on documents - deletion is immediate and recursive for a folder.
- Storage is local disk on the app server, so drive capacity is server capacity.
Common questions
Quick answers in plain language.
Can I give one department its own private folder in the school drive?+
No. /files is a single shared tree and access is all-or-nothing for staff. Any user who can open the drive can browse every folder in it. Use a share link with INDIVIDUAL sharing when only named people should see something.
How do I stop a share link that has already gone out?+
Open /files/outgoing and revoke it. You can also cap it in advance with an expiry date, a maximum download count, or a password, all set when the link is created.
Where are uploaded files actually stored?+
Under uploads/files on the application server, outside the web root. Nothing goes to object storage, so that directory must be part of the server backup along with the database.
A colleague says a shared file is not in their Incoming list. Why?+
Incoming shows only shares aimed at that person - explicit INDIVIDUAL permissions, or ORGANIZATION shares within the same school - and never shows shares they created themselves. A PUBLIC token link is not listed anywhere for the recipient; it has to be sent to them.
Related searches
School leaders and IT teams often search for: how to file manager in school management software, best school transport software for K-12 schools, Schoolyi file manager guide, school bus tracking app, library management software, and school inventory management.

