Tenant isolation
Every school is treated as an independent tenant. Tenant-owned operations use the authenticated school context.
Security
Security is designed into tenant access, permissions, financial transitions and operational audit trails—not left to frontend visibility rules.
Every school is treated as an independent tenant. Tenant-owned operations use the authenticated school context.
SuperAdmin, School Admin, Teacher, Student and Parent workflows have separate authorization boundaries.
Amounts are calculated by the server and money is credited only after signed gateway confirmation.
Refresh sessions, revocation and protected routes reduce unauthorized access risk.
Sensitive operational changes and financial transitions produce audit records.
Backups, monitoring, provider UAT and restore testing remain mandatory before production activation.