Start here

Roles and permissions

Why two people see two different schools, and how to build a role that fits your staff.

Written for School admin
On this page

This page has no sections.

Nothing in Alviyora is hidden by convention or by politeness. Every menu entry, every page and every action is gated on a permission, and permissions reach a person through a role. Understanding those two words explains almost every “why can’t I see…” question a school will ever ask.

Who can change any of this

Only somebody holding Manage Roles. By default that is the Admin role and nobody else.

Permissions, roles and people

A permission is one narrow ability — View Learners, Take Learner Attendance, Manage Finance. There are 36 of them, grouped into categories that match the sidebar: General, Attendance, Users, Academics, Timetable, Homework, Communication, Settings and Finance.

A role is a named bundle of permissions. Teacher is a bundle. So is a Bursar you invent yourself.

A person holds one or more roles at a school. Their permissions are everything their roles add up to. Hold two roles and you get the union of both — permissions never subtract.

Per school, not per person

Roles are held at a school. The same human can be an Admin at one school and a Teacher at another, on the same login. Switching schools switches the whole set.

The four roles you start with

Every school is created with these four already in place, already populated:

RoleWho it is forWhat it can do
AdminPrincipals, deputies, office staffEverything, across the whole school
TeacherClassroom staffTheir classes: register, homework, marks, timetable, learner list, notes
LearnerEnrolled learnersTheir own timetable, homework and published results
GuardianParents and caregiversTheir children’s attendance, results, homework, announcements and fees

Admin and Teacher are marked staff roles, which means they appear on the Staff page and can be assigned when registering staff. Learner and Guardian are not.

What Teachers deliberately do not get

Two permissions are left out of the Teacher role on purpose, though both exist and both can be granted to a role you build:

  • Edit Learner Profiles — profile information stays with administrators.
  • Manage Announcements — creating and deleting announcements stays with administrators.

Teachers do get View Notes and Manage Notes: they are the people with something worth writing down about a learner. Notes marked admin only stay invisible to them regardless — that check is on the note, not on the role.

Building your own role

Roles on the left with a member count each; the selected role's permissions on the right, grouped the same way the sidebar is.

Open Roles & Permissions

Set up your school → Roles & Permissions.

Choose New Role

Give it a name your staff will recognise — Head of Department, Bursar, Groundskeeper — and a one-line description.

Decide whether it is a staff role

Tick Staff role if the people holding it work at the school and should appear on the Staff list. Leave it unticked for anything else.

Tick the permissions it needs

Work down the categories. Each permission carries a plain-English description of what it unlocks, so you are not guessing from a codename.

Save, then assign it

Roles are assigned to people from Manage Users, or on a person’s profile. Someone can hold several.

Start from what someone already does

The quickest way to get a custom role right is to open the role closest to it, read down its ticks, and reproduce those plus the extra ones. A “Head of Department” is usually Teacher plus View Academics across more than their own classes.

The four default roles cannot be edited

Admin, Teacher, Learner and Guardian are marked Default and open read-only. That is deliberate: they are the roles every school in the system shares, and a school that quietly removed View Dashboard from Teacher would produce a support problem nobody could diagnose from the outside.

If the standard Teacher role is not what your school needs, copy it into a new role and adjust that. Then assign the new one.

One permission you cannot delegate

Generate Timetable is restricted and does not appear in the permission matrix at all. It stays with the Admin role specifically.

The reason is blast radius: editing one class’s timetable is Manage Timetable and is delegable to anyone sensible. Generating and publishing replaces the whole school’s timetable in one action. However senior a custom “Principal” role is otherwise, that particular button is not something a school should be able to hand out through a tick box.

What happens when a permission is missing

Alviyora hides rather than disables. Someone without Manage Finance does not see a greyed-out Finance menu — they see no Finance group at all. A group whose every item is filtered out disappears entirely, because showing a teacher an empty “Finance” heading makes a stranger statement about their access than showing nothing.

Two consequences worth knowing:

  • A missing menu item is not a fault. It is the answer to a question about access.
  • Typing the URL directly does not help. The check runs on the server as well as in the browser. A page you cannot see in the menu will bounce you to your dashboard, and the attempt is recorded.

If someone's access looks wrong

Check three things, in this order:

  1. Which school are they in? The school name is at the bottom of the sidebar.
  2. Which roles do they hold? Open their profile.
  3. What does that role actually tick? Open Roles & Permissions.

The Activity Log records role changes, so “it worked yesterday” is answerable.