Permissions guide
Who can do what? Roles, permissions and sensitive actions
Understand role, capability and data scope, then control viewing, creation, editing, deletion, review and approval.
- Written by
- Raqeem content team
- Product review
- Raqeem product team
Direct answer
Reliable access control does not depend on the role name alone. It defines the allowed capability, the data scope and whether the action is ordinary or sensitive. A user may view without editing, prepare without approving, or create a request without being allowed to delete it.
Guide method and boundaries
This guide reflects capabilities reviewed in Raqeem at the stated revision date. It separates available functionality from planned work and does not claim external certification, integration or synchronisation without published evidence.
A role is not the whole permission
Director, reception, teacher and parent are role names, while actual decisions use capabilities such as view, create, edit, delete, review and approve.
The scope may differ according to the user’s real responsibility.
Define the data scope
A permission may cover the institution, a class, a student or only children linked to the account.
Scope prevents a valid permission from becoming unnecessarily broad access.
Strengthen sensitive actions
Deletion, conversion, approval, financial changes and publishing require appropriate permissions, review or audit evidence.
Access should be updated promptly when responsibilities change or a user leaves.
Permission review
- Keep role and capabilities separate.
- Define institution, class or record scope.
- Separate preparation, review and approval.
- Restrict deletion, finance and publishing.
- Review access when responsibilities change.
Related questions
Is hiding a button enough?
No. The permission must protect the operation itself, not only the interface.
Do all directors have the same permissions?
Not necessarily. Capabilities and scope may differ according to assigned responsibility.
More guides on governance and security
Guides on institutional data isolation, permissions, information protection and timetable conflicts.
How does Raqeem isolate each school’s data?
A clear explanation of institution separation, permissions and the rule against transferring one school’s methods to another.
How should a school protect student, family and staff data?
Practical principles for limiting access, isolating institutions, protecting accounts and separating production from testing.
How should a school build a timetable and review conflicts before publishing?
A journey from setup and draft to teacher, class and room conflict checks, then review and publication.
