Privacy 6 min read Updated September 2026
Who sees what: designing permissions
In an educational organization the information is sensitive by definition. Permissions that are too broad intrude on the student’s dignity; permissions that are too narrow silence information that needs to reach the person providing care. The model below holds both sides.
1. Permission follows the role, not the person
When permission is attached to a role rather than a person, changing roles leaves no leftover access and blocks no work. It is also what allows a clear answer to an audit question: who was allowed to see what, and when.
2. A counselor sees their own group
A counselor needs the students they are responsible for, at the level required for daily work. Access to the entire organization is not necessary and increases exposure with no benefit.
3. Care information is separated from operational information
Therapeutic, emotional or medical information should not sit in the same layer as attendance reporting. Separating the layers makes it possible to share what operations require without exposing what belongs to the professional providing care.
4. What never goes into the system
Not everything should be written down. A private conversation, a family detail or a staff member’s assumption is not a system record. The practical rule: write what is needed to continue care, in language you could show the student and the parents.
5. Access logging is part of the protection
Logging actions and views is not suspicion of the staff. It is what makes it possible to answer a question, to identify misuse, and to protect the staff themselves when a claim is raised.
Want to build a permission model that fits your structure? We can go through the roles in one session.
Book a demo