Basics
Roles and Permissions
Understand who can view, create, update, delete, and finalize data.
Role summary
| Role | Main job | Can manage | Cannot access |
|---|---|---|---|
| Org Admin | Owns the organization workspace. | All organization users, programs, majors, cycle archives, academic setup, settings, finance, grade finalization, and records. | Platform administration outside the organization. |
| Sub Admin | Runs delegated operational administration. | Users and academic/program operations inside assigned departments, schedules, cycles, cohorts, majors, reassignment, and grade review. | Cycle archive creation, unassigned departments, main admin management, and platform administration. |
| Manager | Monitors academic work for assigned sections. | Assigned students, assigned sections, attendance, assessments, grades, and finalization review where allowed. | Finance management, settings, broad user administration, and unrestricted student data. |
| Finance Manager | Handles fee and payment operations. | Finance structures, entries, payment claims, transactions, and finance communication. | Academic setup, teaching workflows, settings, and grade management. |
| Teacher | Runs assigned classes. | Assigned sections, materials, assessments, submissions, attendance, and grading. | Finance management, school settings, and unassigned student records. |
| Student | Uses the student portal. | Own submissions, fee claims, personal timetable, materials, grades, attendance, and transcripts. | Other students, staff tools, settings, and management pages. |
| Guardian | Views linked student records. | Read-only linked-student overview, attendance, grades, timetable, and fee status. | Unlinked students, staff tools, academic setup, and group chat creation. |
Feature matrix
| Feature | Admin | SubAdmin | Manager | FinanceManager | Teacher | Student | Guardian |
|---|---|---|---|---|---|---|---|
| Students | Create, edit, delete, view all | Create, edit, delete, view all | View assigned | Finance-related view | View assigned | View self | View linked |
| Teachers and Managers | Create, edit, delete | Create, edit, delete | View assigned context | No | View peers where allowed | No | No |
| Sub Admins | Create, edit, delete | No | No | No | No | No | No |
| Finance Managers | Create, edit, delete | Create, edit, delete | No | No | No | No | No |
| Guardians | Create, edit, link to student | Create, edit, link to student | No | Finance communication only | No | No | Own account only |
| Courses and Sections | Manage | Manage | View assigned | No | View assigned | View enrolled | View linked-student context |
| Academic Cycles and Cohorts | Manage | Manage | Read academic context | No | Read academic context | Read own context | Read linked-student context |
| Programs and Majors | Manage all departments | Manage assigned departments | Read scoped context | No | Read scoped context | Read own major | No management access |
| Past Records | View all; create/verify archives from cycle controls | View department scope | View department scope | No | View archived assigned sections | View self | View linked students |
| Timetable and Attendance | Manage schedules, view all, review attendance | Manage schedules, view all, review attendance | Assigned schedule ownership for marking | No | Assigned schedule ownership for marking | View self | View linked |
| Assessments and Grades | Review and finalize | Review and finalize | Assigned academic scope and finalization review | No | Assigned creation, grading, publish/finalize flow | View own visible grades | View linked visible grades |
| Finance | Manage | Read/audit where allowed | No | Manage | Self/assigned finance view where allowed | View and claim own payments | View linked-student fees |
| Settings and GPA Policies | Manage | Manage GPA/academic settings where allowed | No | No | No | No | No |
| Chat and Mail | Org-level communication | Org-level communication | Academic-scope communication | Finance mail and limited direct chat | Assigned academic communication | Assigned-teacher chat and own mail limits | Admin/finance/support communication |
Scope matters
Manager and Teacher access is not school-wide by default. Their student, transcript, attendance, and group-chat access follows assigned academic sections where the workflow depends on student data.
Write boundaries
EduVerse separates what users can see from what they can change. Some actions are limited by role, school status, or academic rules such as finalized grades.
| Rule | What happens |
|---|---|
| Account status and organization status | Backend access checks can limit read or write actions when an organization is inactive, suspended, rejected, or still pending. |
| Frontend navigation | The sidebar hides pages that do not belong to the signed-in role, but backend guards still decide the final authority. |
| Assigned-section filtering | Teachers and Managers only see or change academic records connected to their assigned sections where the workflow is scoped. |
| Linked-student filtering | Guardians see only students linked to their guardian account. |
| Program department filtering | Sub Admin program writes require explicit assignment to the owning department; moving a program checks both departments. |
| Archived data | Past Records is always read-only and the server removes student rows outside the actor scope. |
| Finance separation | Finance Managers handle finance workflows; Managers do not receive finance management access. |
Finalized academic data
When finalized grades exist for an academic cycle, the GPA policy assigned to that cycle cannot be changed. This preserves historical transcript calculations.