Every colleague sees only what they should
5 sub-roles cover every kind of staff on a modern school. 8 sensitive scopes can be toggled per role, per school and per person — and every access is logged.
6 staff sub-roles
Substitute, pedagogical assistant, TAP, consultant, leader and psychologist — each with sensible defaults from day one.
9 sensitive scopes
Grades, wellbeing, SEN, use-of-force, finance, journal notes and more — controlled per role and per person.
School- and user-level overrides
Defaults can be adjusted for the whole school or for one person — without restructuring anything.
Only what's needed
A substitute doesn't see grade history. A TAP doesn't see grading. The pedagogical assistant sees wellbeing without grades.
Full audit log
Every access to a sensitive scope is logged — who, when and why. Ready for DPO review.
systemet-enforced
The access check runs inside a secure server function (staff_can_access) — never in the client.
Why 6 sub-roles?
- Substitute — short-term access to class and schedule
- Pedagogical assistant — wellbeing and message log without grades
- TAP — administration without pupil data
- Consultant — curricula and aggregate data without identifiable access
- Leader — full access with audit on sensitive actions
- Psychologist — confidential journal notes behind a lock (see /psychologist-journal)
- All defaults can be changed without a new role-mapping project

