Glossary
Role-based access (RBAC)
Permissions that limit each user to the pages and student data their job requires, with audit trails for sensitive changes.
Schools handle sensitive child data. RBAC ensures teachers see only their classes, finance sees fee records, and families see only their children. Principals get oversight without granting every staff member full administrative rights.
Strong platforms gate both UI navigation and API routes so permissions cannot be bypassed from the browser console. Sensitive operations - mark publish, fee waivers, payroll runs - should require the right role every time.
Onboarding new hires should mean assigning a role matrix, not inventing ad-hoc access in chat. Bulk import and role assignment keep IT from becoming a bottleneck at the start of term.
Schoolyi centralises user management, role assignment, and school configuration so each workspace matches the job - with activity review when leadership needs an audit trail.
How this works in a running school
Role-based access is the mechanism that makes a shared student record safe. A class teacher needs attendance and marks for their own students, a bursar needs fee position across the school without assessment detail, a registrar needs admissions data, and a parent needs their own children only. Getting this wrong is not a configuration inconvenience; in a school it is a safeguarding and data protection issue.
The case that separates well-designed permission models from poor ones is the person holding two roles, which is normal in smaller schools. A model that forces either two logins or blanket administrator rights will, in practice, produce blanket administrator rights, and the audit trail loses its meaning.
What to check when evaluating it
- Whether one account can hold multiple roles with the union of their permissions, and an audit trail.
- Whether teachers are scoped to their own classes and subjects by default.
- Who can edit a published result or waive a fee, and whether that action is logged.
- Whether sensitive categories such as medical or safeguarding notes have separate access control.
- What a support engineer at the vendor can see, and whether that access is logged.
- How access is removed when a staff member leaves, and how quickly.
What it costs to get wrong
The failure mode here is not a breach; it is a quiet slide into everyone being an administrator. It starts with one person who holds two jobs and cannot be modelled, so they are given full rights as a workaround. Within a year several staff have the same, the audit trail no longer distinguishes who did what, and a school holding minors’ data has no meaningful access control. Reversing it means taking permissions away from colleagues, which is far harder than designing the model correctly at the outset.
Roles and permissions
A role is a named job: class teacher, bursar, registrar. A permission is a specific capability: view fee balance, edit published result, export student list. Roles exist so permissions are granted consistently to everyone doing the same job. Systems that let permissions be granted directly to individuals drift quickly and become impossible to audit.
Role-based access (RBAC): common questions
- What is role-based access control in school software?
Granting capabilities through named roles rather than to individuals, so that everyone doing the same job has the same access and access can be reviewed by role.
In a school it is what allows one shared student record to be used safely by teachers, office staff, leadership, and families.
- Can one person hold more than one role?
They need to be able to, because in smaller schools one person frequently handles both admissions and finance.
The alternatives, two separate logins or full administrator rights, are respectively inconvenient and unsafe.
- Who should be able to change a published grade?
A small, named set of roles, with the change recorded.
Correction has to be possible because errors happen, but an unlogged correction on a published result is a governance gap, and it is worth testing explicitly during evaluation.
Related on Schoolyi
Related terms
School management software
A connected platform that runs admissions, student records, academics, fees, exams, and family portals on one academic calendar.
Parent portal
A guardian-facing login for fees, receipts, attendance summaries, and published grades across all linked children.
Student information system (SIS)
The authoritative register of students, classes, guardians, and enrollments that other school modules depend on.
School management system (SMS)
A cloud platform where admissions, academics, fees, exams, transport, and family portals share one student roster and academic calendar.

See role-based access (rbac) in a live walkthrough
We will show the modules that implement this capability for your school type.
Already using Schoolyi? Sign in
