Tenant isolation in the database
Every record carries its institution. Row-level security policies, not application code, decide what a request can read or write, so one university can never reach another university's data.
Academic timetables contain staff and student information. The platform is built so that isolation and authorization are enforced by the database, not by the interface.
Every record carries its institution. Row-level security policies, not application code, decide what a request can read or write, so one university can never reach another university's data.
Roles are bundles of fine-grained permissions granted at platform, institution, campus, faculty, department or programme level. One person can hold different roles in different faculties.
Generating a schedule and approving it are distinct permissions. Publication requires an approver-scoped grant.
Privileged actions, approvals, publications, integration syncs and vendor support access are all recorded and cannot be edited from the application.
Service credentials and integration secrets are never included in the browser application. Public callback endpoints verify a signature or a run-scoped token before any write.
WCAG 2.2 AA is a release gate for dashboards, forms, tables and the timetable grid, including full keyboard operation.