Basics

Roles and Permissions

Understand who can view, create, update, delete, and finalize data.

Role summary

RoleMain jobCan manageCannot access
Org AdminOwns the organization workspace.All organization users, programs, majors, cycle archives, academic setup, settings, finance, grade finalization, and records.Platform administration outside the organization.
Sub AdminRuns delegated operational administration.Users and academic/program operations inside assigned departments, schedules, cycles, cohorts, majors, reassignment, and grade review.Cycle archive creation, unassigned departments, main admin management, and platform administration.
ManagerMonitors academic work for assigned sections.Assigned students, assigned sections, attendance, assessments, grades, and finalization review where allowed.Finance management, settings, broad user administration, and unrestricted student data.
Finance ManagerHandles fee and payment operations.Finance structures, entries, payment claims, transactions, and finance communication.Academic setup, teaching workflows, settings, and grade management.
TeacherRuns assigned classes.Assigned sections, materials, assessments, submissions, attendance, and grading.Finance management, school settings, and unassigned student records.
StudentUses the student portal.Own submissions, fee claims, personal timetable, materials, grades, attendance, and transcripts.Other students, staff tools, settings, and management pages.
GuardianViews linked student records.Read-only linked-student overview, attendance, grades, timetable, and fee status.Unlinked students, staff tools, academic setup, and group chat creation.

Feature matrix

FeatureAdminSubAdminManagerFinanceManagerTeacherStudentGuardian
StudentsCreate, edit, delete, view allCreate, edit, delete, view allView assignedFinance-related viewView assignedView selfView linked
Teachers and ManagersCreate, edit, deleteCreate, edit, deleteView assigned contextNoView peers where allowedNoNo
Sub AdminsCreate, edit, deleteNoNoNoNoNoNo
Finance ManagersCreate, edit, deleteCreate, edit, deleteNoNoNoNoNo
GuardiansCreate, edit, link to studentCreate, edit, link to studentNoFinance communication onlyNoNoOwn account only
Courses and SectionsManageManageView assignedNoView assignedView enrolledView linked-student context
Academic Cycles and CohortsManageManageRead academic contextNoRead academic contextRead own contextRead linked-student context
Programs and MajorsManage all departmentsManage assigned departmentsRead scoped contextNoRead scoped contextRead own majorNo management access
Past RecordsView all; create/verify archives from cycle controlsView department scopeView department scopeNoView archived assigned sectionsView selfView linked students
Timetable and AttendanceManage schedules, view all, review attendanceManage schedules, view all, review attendanceAssigned schedule ownership for markingNoAssigned schedule ownership for markingView selfView linked
Assessments and GradesReview and finalizeReview and finalizeAssigned academic scope and finalization reviewNoAssigned creation, grading, publish/finalize flowView own visible gradesView linked visible grades
FinanceManageRead/audit where allowedNoManageSelf/assigned finance view where allowedView and claim own paymentsView linked-student fees
Settings and GPA PoliciesManageManage GPA/academic settings where allowedNoNoNoNoNo
Chat and MailOrg-level communicationOrg-level communicationAcademic-scope communicationFinance mail and limited direct chatAssigned academic communicationAssigned-teacher chat and own mail limitsAdmin/finance/support communication

Scope matters

Manager and Teacher access is not school-wide by default. Their student, transcript, attendance, and group-chat access follows assigned academic sections where the workflow depends on student data.

Write boundaries

EduVerse separates what users can see from what they can change. Some actions are limited by role, school status, or academic rules such as finalized grades.

RuleWhat happens
Account status and organization statusBackend access checks can limit read or write actions when an organization is inactive, suspended, rejected, or still pending.
Frontend navigationThe sidebar hides pages that do not belong to the signed-in role, but backend guards still decide the final authority.
Assigned-section filteringTeachers and Managers only see or change academic records connected to their assigned sections where the workflow is scoped.
Linked-student filteringGuardians see only students linked to their guardian account.
Program department filteringSub Admin program writes require explicit assignment to the owning department; moving a program checks both departments.
Archived dataPast Records is always read-only and the server removes student rows outside the actor scope.
Finance separationFinance Managers handle finance workflows; Managers do not receive finance management access.

Finalized academic data

When finalized grades exist for an academic cycle, the GPA policy assigned to that cycle cannot be changed. This preserves historical transcript calculations.