How permissions work
Access levels
A provision holds some of the most sensitive data there is: safeguarding concerns, staff supervision notes, HR files. The portal handles that by giving every person exactly one access level and building their portal around it.
Administrator / Director
The person accountable for the whole provision
Sees: Everything: leadership dashboards, finance, HR, safeguarding, staff records and the settings that control who sees what.
Cannot: Nothing is hidden — this level owns access control.
Leader
Operations or provision leads
Sees: Leadership dashboards, quality, compliance and reporting for the whole setting.
Cannot: Cannot change other people's access, and cannot open staff supervision notes unless they line manage that person.
Senior staff / line manager
Team leads who line manage a group of staff
Sees: My Team for their own reports only: profiles, compliance, supervisions, appraisals and tasks.
Cannot: Cannot see other managers' teams, finance or organisation-wide settings.
Designated Safeguarding Lead
DSL and deputy
Sees: Every safeguarding concern the moment it is logged, plus the KCSiE compliance pack.
Cannot: Cannot change staff pay, HR records or access levels.
Coach
Day-to-day teaching and support staff
Sees: Their register, session records, learner profiles, evidence, training and policies.
Cannot: Cannot see leadership dashboards, HR, finance or other staff members' records.
Animal care
Welfare staff with no learner-facing role
Sees: A locked-down home screen: daily animal checks, medication, licence records.
Cannot: Cannot see learner names, safeguarding or any staff records.
The four rules behind it
One account, one view
Staff sign in with their own work email. What they see is decided by their access level, not by remembering which link to avoid.
Enforced in the database, not the menu
Access rules live on the data itself, so a hidden page is genuinely inaccessible, not simply missing from the sidebar.
Least access by default
New staff start as a coach. Extra access is granted deliberately by an administrator and can be removed the same way.
Auditable
Access changes and record views are logged, so you can show a commissioner or the ICO exactly who could see what, and when.
In this demonstration every area is unlocked so you can look around. In a live partner portal you would only see the areas your own access level allows.
