Security and data governance

Academic timetables contain staff and student information. The platform is built so that isolation and authorization are enforced by the database, not by the interface.

Tenant isolation in the database

Every record carries its institution. Row-level security policies, not application code, decide what a request can read or write, so one university can never reach another university's data.

Scoped role assignments

Roles are bundles of fine-grained permissions granted at platform, institution, campus, faculty, department or programme level. One person can hold different roles in different faculties.

Separation of duties

Generating a schedule and approving it are distinct permissions. Publication requires an approver-scoped grant.

Append-only audit trail

Privileged actions, approvals, publications, integration syncs and vendor support access are all recorded and cannot be edited from the application.

Credentials stay server-side

Service credentials and integration secrets are never included in the browser application. Public callback endpoints verify a signature or a run-scoped token before any write.

Accessibility as a requirement

WCAG 2.2 AA is a release gate for dashboards, forms, tables and the timetable grid, including full keyboard operation.