Skip to content

Roles and permissions

School Admin

This page explains who can do what in SolAssists, how to read and change a role, and the traps that make a new account see nothing.

Three things decide what a person sees

  1. Modules — what your institution has. SOL staff choose these. A module you don't have never appears, whatever a role says.
  2. The role's permissions — what that kind of person may do inside those modules (for example Attendance — MARK).
  3. Where their access applies — every access is given over part of the institution: Institution-wide, or a unit such as one campus "and everything under it". A role cannot reach outside that part, even an administrator role.

On top of that, each permission has a reach (called data scope) that narrows which records it covers:

ReachIn plain wordsUsed by
Whole organizationEverything inside the part of the institution they were givenSchool Admin
Branch / assigned unitRecords in their unit and belowCampus-level staff roles
Assigned classesOnly divisions they have a teaching assignment for in the current academic sessionTeacher
Linked childrenOnly students linked to them as guardianParent / Guardian
SelfOnly their own recordStudent

Reach cannot be changed in the app

There is no control on the role screen to choose a permission's reach. Roles created during onboarding already have the right reach. See Custom roles for what this means when you create a new role.

The roles you start with

Onboarding creates four roles for your institution. Their permissions only cover modules your institution has.

RoleReachWhat it's for
School AdminWhole organizationRuns the institution: every action in every module you have, plus users and roles.
TeacherAssigned classesTeaches assigned divisions: marks attendance, enters marks, sets study material.
StudentSelfSees their own timetable, attendance, marks, study material and fees.
Parent / GuardianLinked childrenFollows their children's attendance, results and fees.

Don't use roles marked "built-in"

The Roles screen also lists Student, Parent / Guardian, Teacher and Management with a Built-in badge, and the Give access dialog shows them as "STUDENT · built-in" and so on. These have no permissions at all. Someone given one signs in to "Nothing available yet". Always choose your institution's own role.

Role × feature matrix

Legend: Yes — can do it. Own classes — only divisions they're assigned to teach this session. Own — their own record. Children — their linked children. — cannot. Everything applies only if your institution has the module.

Structure, academics and timetable

FeatureSchool AdminTeacherStudentParent
View / change institution structureYes
View academic sessions and subjectsYesYesYesYes
Create or edit sessions and subjectsYes
Bell schedule, rooms, student groupsYes
Manage teaching assignmentsYes
Schedule lectures for anyoneYes
Schedule own one-off lecturesYesOwn classes, if the institution allows it
See own timetableYesYesYesChildren

Students, parents and admissions

FeatureSchool AdminTeacherStudentParent
View studentsYesOwn classes
Add, import, edit, enrol studentsYes
Transfer / promote studentsYes
Reveal full Aadhaar numberYes
Admissions (view, decide, allocate)Yes
View guardiansYesGuardians of own classes
Add, edit, link guardiansYes
Create a parent sign-inYes, with People Directory module
Progress pageChildren

Daily operations

FeatureSchool AdminTeacherStudentParent
Mark attendanceYesOwn classes
View attendanceYesOwn classesOwnChildren
Devices and attendance policyYesMenu items visible ¹
Create exams, enter marksYesOwn classes
Publish exam resultsYes
View exams and resultsYesOwn classesOwn ¹Children ¹
Create, edit, publish study materialYesOwn classes
Read study materialYesOwn classes¹¹
Draft announcementsYesOwn classes¹
Send or schedule announcementsYes
Read announcementsYesYesYesYes
View fees and invoicesYesOwnChildren
Fee setup, collect paymentsYes
Approve concessionsYes
Apply for leaveYesYes
Approve leave, manage leave typesYes
Staff recordsYes
View reportsYesYes ¹Yes ¹
Export attendance reportYesYes

Access and administration

FeatureSchool AdminTeacherStudentParent
Give, change, suspend or revoke accessYes, within their own part of the institution
Create roles, change permissionsYes
People DirectoryYes, with People Directory module
BrandingYes
Audit TrailYes
My Profile, change passwordYesYesYesYes

¹ The role holds this permission. Check what the screen shows with a test account for that role before relying on it.

Things teachers can't do by default

  • Send announcements. Teachers can write a draft; an administrator must send it.
  • Publish exam results. An administrator publishes.
  • Approve leave.

Permissions reference

On a role's page each module shows chips for its actions. READ, CREATE, UPDATE, DELETE mean view, add, change, remove. The extra actions are:

ModuleActionAllows
StudentsPROMOTEPlace a student in a later session's division, including bulk promotion
StudentsTRANSFERMove a student to another division, including bulk transfer
StudentsEXPORTReveal a student's full Aadhaar number
Parents & GuardiansLINK_STUDENTLink or unlink a guardian and a student
StaffEXITRecord a staff member leaving
StaffEXPORTReveal a staff member's full Aadhaar number
AdmissionsAPPROVEDecide an application and enrol the applicant
AdmissionsALLOCATE_DIVISIONAllocate an applicant to a division
TimetablePUBLISHBell schedule, rooms, groups, teaching assignments, sessions and subjects, and scheduling other people's lectures
Staff LeaveAPPROVESee and decide colleagues' leave requests
AttendanceMARKMark a register
Study MaterialPUBLISHPublish a draft post
ExaminationsENTER_MARKSEnter marks on a paper
ExaminationsPUBLISH_RESULTMove an exam through its stages and publish results
FeesCOLLECTRecord and reverse payments
FeesWAIVEApprove or reject a concession
CommunicationBROADCASTSend and schedule announcements
ReportsEXPORTDownload the attendance report
Access Management → RolesASSIGN_PERMISSIONChange what a role can do

Chips that currently do nothing

Teachers — ASSIGN_DIVISION, Academics — PUBLISH, Attendance — REGULARIZE, Roles — CLONE and Users — DELETE appear on the grid but are not used anywhere in the product. Ticking them has no effect.

A few modules need another to be useful: Parents & Guardians, Admissions, Attendance and Fees need Students; Timetable and Study Material need Academics; Examinations needs Students and Academics; Staff Leave needs Staff.

View a role

  1. Access & Security → Roles & Permissions. The table lists Role, What it's for, Permissions (count) and Status.
  2. Click a row. The page shows Permissions granted, Modules available, and the card What this role can do — "Only modules your institution is subscribed to appear here."

Built-in roles open read-only ("Built-in — read only").

Change what a role can do

  1. Open the role.
  2. Tick or untick action chips. Use a module's checkbox to select all its actions, or All / None at the top.
  3. Click Save permissions. Reset discards unsaved changes.

Changes apply to everyone holding that role the next time their app loads its permissions.

Don't remove your own way back in

Nothing stops you removing Access Management permissions from the role you hold yourself. If every administrator loses them, only SOL staff can restore access.

Adding a module later doesn't update roles

If SOL adds a module to your institution after onboarding (for example Fees), the Teacher, Student and Parent / Guardian roles are not given its permissions automatically — tick them on each role yourself. For School Admin too, check that the new module's actions are ticked.

Custom roles

  1. Access & Security → Roles & Permissions → New role.
  2. Enter Name (e.g. "Head of Department"), Code (capital letters, digits and underscores, starting with a letter — permanent) and optionally What it's for.
  3. Click Create role. You are taken to the new role to tick permissions.

A brand-new role sees only "self"

Because the app cannot set a permission's reach, permissions ticked on a brand-new role get the narrowest reach (self). A new "Office Clerk" role with Students — READ will see an empty student list. Until reach can be set in the app, give staff one of the onboarding roles, or ask SOL to set the reach for a custom role.

A role's name, description and status cannot be edited, and roles cannot be deleted or copied from the app.

Something on this page doesn't match what you see? Contact SolAssists support.