Skip to content

Who does what

Who logs in, what each person can see, and who is allowed to change what. Read this before you create your first users — it saves undoing them later. Time to read: 5 minutes.

The three levels

The system has three levels, and confusing them is the most common early mistake.

LevelWhoWhat they control
PlatformYou, the owner of the installationEverything — creating schools, plans, payment gateways, SMS providers, backups, updates
Group / BranchThe head office of a group or trustOnly the branches assigned to them. No platform settings
SchoolEach school's own staffEverything inside their own school — students, staff, fees, exams, attendance

The middle level is optional. A single school that is not part of a group simply does not use it.

A school's staff can never see another school's data, and cannot reach platform settings at all. You sit above everyone.

Platform level

Superadmin

The owner account. Full access to everything: every school, every setting, billing, backups, updates and the platform dashboard.

There is normally one of these. Treat the password accordingly — this account can read every school's data.

Group / Branch level

Branch admin

For a group or trust running several branches. The head office gets its own login that oversees its branches — and nothing outside them.

You create one by marking a platform account as restricted and choosing which schools it may reach.

The panel renames itself for these accounts, so a branch admin sees:

They seeInstead of
Branch OverviewDashboard
My BranchesSchools

A branch admin can:

  • Open Branch Overview — combined figures across their branches
  • Open My Branches and work inside any branch assigned to them
  • See Payments and Templates
  • Run every report: Login Logs, Schools Usage, Fee Collections, Attendance Trends, Engagement Audit, Communications — across their branches only
  • Edit their own profile

A branch admin cannot:

  • Create or edit Plans
  • Manage the platform Team
  • Reach Settings at all — no payment gateways, SMS providers, backups or updates
  • See any school outside their assigned branches

Who is this for?

A trust with 6 schools appoints one head-office person as branch admin. They compare fee collection and attendance across all 6, and can step into any of them — but they cannot change your gateway keys, your plans, or touch the other 40 schools on your installation.

School level

Every school gets its own set of staff logins. Five roles come ready to use, and you can create more.

School admin

Full control of their own school — every module, every setting inside it. This is the principal or the person who runs the office.

Verified: this role is granted every school-level permission that exists.

Teacher

The largest role after school admin. A teacher can:

  • See the student list and student profiles
  • Take and manage student attendance
  • View the academics dashboard and manage the timetable
  • Enter exam marks and generate marksheets
  • Create and run online exams
  • Manage syllabus, study material, homework and live classes
  • Post notices and events
  • Apply for their own leave

A teacher cannot see fees, accounts, payroll, or other staff's records.

Accountant

Money only:

  • Fees dashboard, fee collection, fee setup, assigning fees to students, and dues
  • Income and expense entries
  • Apply for their own leave

An accountant cannot see exams, attendance or academic records.

Librarian

  • Full library management
  • Apply for their own leave

Nothing else.

Receptionist

Front desk only:

  • Front office dashboard
  • Enquiries, visitors, complaints and postal records
  • Apply for their own leave

A receptionist cannot see student academic records, fees or staff data.

These five are starting points, not limits

Roles are fully editable. You can change what any role may do, or create new ones — "Exam Controller", "Transport Manager", "Vice Principal" — and tick exactly the permissions they need.

Parents and students

Parents log in through the parent mobile app or the parent web page, using the account created with their child's record. A parent sees only their own children: attendance, marks, fees, homework, notices and messages from the school.

Parents are never given a staff login and can never reach the school panel.

Drivers

Drivers work differently from everyone else, and this catches people out.

A driver does not get a user account. The driver app signs in against the vehicle, using three things:

FieldWhat to enterExample
School emailThe email address on the school's recordoffice@stmarys.edu.in
Vehicle numberThe bus registration number as entered in TransportMH12AB1234
PasswordThe driver password set on that vehicleset by the school admin

So the login belongs to the bus, not the person. If a relief driver takes the vehicle tomorrow, they use the same details — nothing to create, nothing to reset.

"No driver password has been set for this vehicle"

If a driver sees this message, the vehicle exists but no driver password was saved on it. A school admin sets it on the vehicle record in Transport. It is not a user account, so there is nothing to look for under staff or users.

Choosing roles for a new school — worked example

A school with 400 students and 22 staff typically sets up:

PersonRoleWhy
PrincipalSchool adminNeeds everything, including settings
Office managerSchool adminSecond full account, so the school is not locked out if the principal is away
Accounts clerkAccountantCollects fees, records expenses — no reason to see exam marks
18 teaching staffTeacherAttendance, marks, homework for their classes
Front deskReceptionistVisitors and enquiries only
LibrarianLibrarianBook issue and return

The mistake to avoid: making everyone a school admin because it is quicker. It works on day one and causes trouble later — fee records altered by people who should not have been able to reach them, with no way to tell who did it.

Always create a second school admin

If the only school admin account is lost — someone leaves, or the password is forgotten — nobody inside that school can restore access. Only the platform superadmin can. Two admin accounts per school avoids the support call entirely.


Role capabilities above are taken directly from the permissions granted in the code, not from a description. If a role behaves differently on your installation, someone has edited it — check the role's permission list in the school panel.