> ## Documentation Index
> Fetch the complete documentation index at: https://help.edustream.ng/llms.txt
> Use this file to discover all available pages before exploring further.

# User Roles and Staff Access Management in Edustream

> Understand Edustream's five user roles, what each role can access, and how to invite staff, assign permissions, and add parents and students securely.

Edustream uses a role-based access model to ensure that every person on your platform — from the proprietor to a student — sees exactly what they need and nothing more. Getting your role assignments right from the start protects sensitive data, simplifies daily operations, and prevents accidental changes to critical settings. This guide walks you through each role, their permissions, and the practical steps for inviting and managing users.

## The Five User Roles

<CardGroup cols={2}>
  <Card title="Super Administrator" icon="crown">
    Full access to all modules, settings, and billing. Typically the school proprietor or IT lead. There should be at most one or two of these per school.
  </Card>

  <Card title="School Administrator" icon="building">
    Manages daily school operations — student records, attendance, finance, and communications. Cannot access billing or subscription settings.
  </Card>

  <Card title="Teacher" icon="chalkboard-user">
    Enters CA and exam scores for assigned subjects, views class attendance, and accesses the e-learning portal. Scoped strictly to their assigned classes and subjects.
  </Card>

  <Card title="Parent / Guardian" icon="person-breastfeeding">
    Views their ward's report cards, fee invoices, and school broadcasts. Can make fee payments through the parent portal. Read-only across all academic data.
  </Card>

  <Card title="Student" icon="graduation-cap">
    Views their own report cards, fee receipts, and e-learning content. Cannot see other students' data or any administrative settings.
  </Card>
</CardGroup>

***

## Permissions Reference

The table below shows which modules and actions are available to each role. A ✅ indicates full access, **View** means read-only access, and ❌ means no access.

| Feature / Module           | Super Admin | School Admin |      Teacher     |    Parent   |   Student  |
| -------------------------- | :---------: | :----------: | :--------------: | :---------: | :--------: |
| School Profile & Settings  |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Billing & Subscription     |      ✅      |       ❌      |         ❌        |      ❌      |      ❌     |
| Academic Year & Terms      |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Grade Scale Configuration  |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Class & Subject Management |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Invite & Manage Staff      |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Student Enrollment         |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| CA Score Entry             |      ✅      |       ✅      | ✅ (own subjects) |      ❌      |      ❌     |
| Exam Score Entry           |      ✅      |       ✅      | ✅ (own subjects) |      ❌      |      ❌     |
| View All Student Scores    |      ✅      |       ✅      | View (own class) |      ❌      |      ❌     |
| Attendance Management      |      ✅      |       ✅      | View (own class) |      ❌      |      ❌     |
| Report Card Generation     |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| View Own Report Card       |      ✅      |       ✅      |         ❌        | View (ward) | View (own) |
| Fee & Invoice Management   |      ✅      |       ✅      |         ❌        |      ❌      |      ❌     |
| Make Fee Payments          |      ✅      |       ✅      |         ❌        |      ✅      |      ❌     |
| View Fee Receipts          |      ✅      |       ✅      |         ❌        | View (ward) | View (own) |
| School Broadcasts          |      ✅      |       ✅      |         ❌        |     View    |      ❌     |
| E-Learning Portal          |      ✅      |       ✅      |         ✅        |      ❌      |    View    |
| User Role Management       |      ✅      |       ❌      |         ❌        |      ❌      |      ❌     |

<Info>
  Teacher access to scores and attendance is always scoped to the classes and subjects they have been explicitly assigned to. A teacher cannot view or edit scores for a class they have not been assigned, even if they are in the same school.
</Info>

***

## How to Invite a Staff Member

Staff members — School Administrators and Teachers — are added to Edustream via email invitation. They receive a link to create their account and are immediately granted the permissions associated with their assigned role.

<Steps>
  <Step title="Navigate to User Management">
    From the main dashboard, click **Settings** in the left sidebar and select **Users & Roles**. The user list displays all active accounts in your school.
  </Step>

  <Step title="Click 'Invite Staff'">
    Click the **+ Invite Staff** button in the top-right corner. An invitation dialog opens.
  </Step>

  <Step title="Enter the staff member's details">
    Fill in the following fields:

    * **First Name** and **Last Name**
    * **Email Address** — this becomes their Edustream login email; it must be unique across the platform.
    * **Role** — select either **School Administrator** or **Teacher** from the dropdown. (The Super Administrator role can only be assigned by another Super Administrator and should be granted sparingly.)
  </Step>

  <Step title="Send the invitation">
    Click **Send Invite**. Edustream sends an email to the address you provided with a secure, time-limited invitation link. The link expires after **72 hours** — if the staff member does not accept in time, you can resend the invite from the **Pending Invitations** tab.
  </Step>

  <Step title="Confirm acceptance">
    Once the staff member clicks the link and sets their password, their status in the user list changes from *Pending* to *Active*. They can now log in and access the platform according to their role's permissions.
  </Step>
</Steps>

<Note>
  Invitation emails are sent from `noreply@edustream.app`. Ask new staff members to check their spam or junk folder if they do not see the email within a few minutes.
</Note>

***

## How to Assign or Change a User's Role

You can update a staff member's role at any time — for example, if a teacher is promoted to an administrative position.

<Steps>
  <Step title="Find the user">
    Go to **Settings → Users & Roles** and search for the staff member by name or email address.
  </Step>

  <Step title="Open their profile">
    Click the staff member's name to open their user profile panel on the right side of the screen.
  </Step>

  <Step title="Change the role">
    In the **Role** field, click the current role label to open the role selector. Choose the new role from the dropdown.
  </Step>

  <Step title="Confirm the change">
    Click **Save Changes**. A confirmation dialog asks you to acknowledge that the user's permissions will change immediately. Click **Confirm**. The role update takes effect on the user's next page load — they do not need to log out and back in.
  </Step>
</Steps>

<Warning>
  Changing a Teacher to a School Administrator grants them access to all student records and financial data. Changing a School Administrator to a Teacher immediately revokes their access to billing-adjacent modules. Review the permissions table above before making role changes.
</Warning>

***

## How Parents and Students Are Added

Parents and students are **not** added through the staff invitation flow. They are linked to the platform automatically during the student enrollment process.

<Tabs>
  <Tab title="Adding a Student">
    <Steps>
      <Step title="Go to Student Enrollment">
        From the dashboard, navigate to **Students → Enrol Student**.
      </Step>

      <Step title="Complete the enrollment form">
        Enter the student's personal details — full name, date of birth, gender, class, and any additional profile fields your school requires.
      </Step>

      <Step title="Create login credentials">
        In the **Portal Access** section, enter a login email address for the student (this can be a personal email or a school-issued address) and set a temporary password. The student will be prompted to change this password on first login.
      </Step>

      <Step title="Save the enrollment">
        Click **Enrol Student**. The student account is created automatically with the **Student** role. They can immediately log in to view their report cards, fee receipts, and e-learning content.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Adding a Parent or Guardian">
    <Steps>
      <Step title="Open the student's profile">
        Navigate to **Students**, search for the enrolled student, and open their profile.
      </Step>

      <Step title="Add a guardian">
        Scroll to the **Parents / Guardians** section and click **+ Add Guardian**.
      </Step>

      <Step title="Enter guardian details">
        Provide the guardian's full name, relationship to the student (e.g., *Father*, *Mother*, *Guardian*), phone number, and email address. The email address becomes their Edustream login.
      </Step>

      <Step title="Send portal access">
        Toggle **Send Portal Invitation** to **On** and click **Save**. Edustream emails the parent a link to activate their account. Once activated, they can view their ward's report cards, fee invoices, and school broadcasts, and make fee payments directly through the portal.
      </Step>
    </Steps>

    <Note>
      One parent account can be linked to multiple students (e.g., siblings at the same school). From the **Parents / Guardians** section of the second student's profile, search for the existing parent by email and link them rather than creating a duplicate account.
    </Note>
  </Tab>
</Tabs>

***

## Best Practices for Role Management

Following these guidelines will keep your Edustream account secure and your data well-organised as your school grows.

<CardGroup cols={2}>
  <Card title="Apply Least Privilege" icon="lock">
    Grant users the minimum role needed for their job. A teacher who occasionally helps with administration does not need a School Administrator role — use the Teacher role and ask a School Administrator to handle admin tasks.
  </Card>

  <Card title="Limit Super Administrators" icon="shield-halved">
    Restrict the Super Administrator role to one or two trusted individuals (e.g., the proprietor and the IT lead). This role has access to billing and can delete school data — it should not be used as a general admin account.
  </Card>

  <Card title="Review Users Each Session" icon="clipboard-check">
    At the start of each academic session, audit your user list. Deactivate accounts for staff who have left the school and ensure new hires have been properly invited before term begins.
  </Card>

  <Card title="Use Unique Email Addresses" icon="envelope">
    Every Edustream account requires a unique email address. Avoid creating shared or role-based email accounts (e.g., `admin@school.edu`) for individual users — shared credentials make auditing and accountability impossible.
  </Card>
</CardGroup>

<Tip>
  To deactivate a staff member's account without permanently deleting it (preserving their score entry history), go to **Settings → Users & Roles**, open the user's profile, and click **Deactivate Account**. Deactivated users cannot log in but their historical data — scores, attendance records, and notes — remains intact.
</Tip>

<CardGroup cols={2}>
  <Card title="School Profile Setup" icon="school" href="/getting-started/school-profile">
    Configure your school name, logo, and branding before inviting your team.
  </Card>

  <Card title="Academic Year Setup" icon="calendar" href="/getting-started/academic-year">
    Set up terms, grade scales, and assign teachers to subjects and classes.
  </Card>
</CardGroup>
