GUIDE / ROLE INFORMATION FLOW
Map who sees, changes and approves
School role information flow maps what teachers, students, parents or guardians, and administrators can view, create, change, approve and export. The map should include temporary access, corrections, notifications and role changes. It gives a school a neutral way to test any platform demonstration while avoiding assumptions that an illustrated Easy Edu view is already a released workflow.
Reviewed draft · 14 September 2026
KEY TAKEAWAYS
What should the reader carry into the decision?
- Map records first, then assign who may view, create, correct, approve, export and administer each one.
- Include temporary teachers, guardians with several children, transfers, leavers and emergency access.
- Connect every notification to its authoritative record, recipient, timing and correction path.
- Turn each permission cell into a permitted, denied or transition test with retained evidence.
“Parents and guardians can view assigned classwork via a link sent by educators, or access it from weekly guardian email summaries.”
Google for Education
Method and scope. This role-action matrix is a vendor-neutral test method reviewed against official Google Classroom role documentation. It describes questions for Easy Edu and does not claim that the platform already has these controls.
Which school records should a role map start with?
List the records that matter: timetable, attendance, assignments, results, announcements, consent, support requests and user profiles. For each record, identify the authoritative source and every person who needs it. Menu labels vary between products; the underlying information and responsibility are more stable. This makes the role map usable across several vendor demonstrations.
Start with four records such as timetable, attendance, result and parent communication. For each, name the authoritative source and every role that can view or change it. This prevents a role map from becoming a list of menus while the information itself remains undefined.
Google Classroom's official page describes 4 relevant audiences: teachers, students, administrators and parents or guardians. Source: Google for Education Classroom →
- 01Record
- 02Authoritative source
- 03People who need it
- 04Purpose
Which actions must be separated for every role?
Viewing is different from downloading; creating is different from approving; correcting is different from deleting. Use clear verbs for each role and record. Ask whether changes are immediate, reviewed or scheduled, and whether the original value remains visible in history. Precision prevents a broad statement such as “parents have access” from hiding what access actually allows.
Build a permission matrix with view, create, correct, approve and export as separate columns. Avoid a single edit label because correcting an error and approving a release carry different authority. Ask for a demonstration and written permission model for every claimed cell.
UNESCO reports global internet connection rates of 40% for primary, 50% for lower-secondary and 65% for upper-secondary schools. Source: UNESCO 2023 GEM Report →
Which role exceptions and transitions should be tested?
A guardian may have several children, a learner may change class, a teacher may cover temporarily, and an administrator may move to a different role. Ask how access is granted, reviewed and removed in each case. Include leavers and dormant accounts. A platform should be evaluated on these transitions because school identities and responsibilities change throughout the year.
Add a substitute teacher, guardian with several children, staff transfer, student leaver and temporary administrator. Show who opens and closes access, how quickly changes apply and what history remains. Exceptions reveal the operational owner of identity and permission changes.
UNESCO reports that 85% of countries have policies intended to improve school or learner connectivity. Source: UNESCO 2023 GEM Report →
- Temporary cover
- Record the result
- Multiple-child guardian
- Record the result
- Class transfer
- Record the result
- Leaver
- Record the result
How should notifications connect to an authoritative record?
For every alert or message, identify the underlying record, recipient, timing, channel and correction path. Ask whether the recipient can tell when information changed and who made the change. A notification without a dependable source can spread confusion faster. A role-flow diagram should show both the message and the record that authorises it.
A notification is useful only when it points back to the authoritative record. Trace who receives it, what it contains, what action follows and how delivery or failure is recorded. Test delayed and duplicate notifications without using real student information.
Malaysia's Personal Data Protection Department lists 6 rights for data subjects in its public FAQ. Source: Malaysia Personal Data Protection Department FAQ →
How can a school test least access?
Ask why each role needs each action and how sensitive records are limited. Review bulk downloads, administrator privileges, support access and shared devices. Google Classroom’s official overview illustrates differentiated teacher, student, administrator and guardian experiences, but it does not validate Easy Edu. Easy Edu must provide its own current role and permission evidence.
Review least access by asking why every role needs each action and record. Include support personnel, vendor administrators and emergency access. Easy Edu's controls are not yet verified, so the output is a list of required evidence rather than a security assessment. For each elevated role, ask who approves it, how long it lasts, how often it is reviewed and what event removes it. Place temporary and emergency access in their own rows so a broad administrator label does not hide exceptional authority.
The same department sets out 7 personal-data-protection principles under section 5(1) of Act 709. Source: Malaysia Personal Data Protection Department →
- Need
- Scope
- Duration
- Review
How should the role map become repeatable test cases?
Write short scenarios with an expected result: a teacher corrects attendance, a parent sees an approved result, an administrator removes a departed staff member, or a student views only their own work. Ask the vendor to demonstrate each case and its audit trail. Record anything that needs configuration, custom work or future development separately.
Turn the map into named tests with precondition, actor, action, expected result and retained evidence. Include one permitted action, one denied action and one role transition. A vendor can then demonstrate the exact flow without the school treating unrelated screens as proof. Keep the test data non-sensitive, record the product version and attach the demonstration result to the matching permission cell. A failed test should identify whether the gap sits in configuration, product scope, training or the underlying access model. Repeat the denied-action test after a role change and confirm that the audit history identifies both the access change and the attempted action.
UNESCO reports that 89% of 163 education-technology products in one pandemic-era analysis could survey children. Source: UNESCO 2023 GEM Report →
| Check | Status | Evidence |
|---|---|---|
| Scenario | Open | Attach current record |
| Expected result | Open | Attach current record |
| Observed result | Open | Attach current record |
| Evidence gap | Open | Attach current record |
Carry the completed role map into the school data questions. →
QUICK ANSWERS
Frequently asked questions
Which actions belong in a school role matrix?
Separate view, create, correct, approve, export and administer for every important record. Add who grants access, its duration, review frequency and removal event. A broad statement such as parent access is incomplete until the permitted information and actions are defined.
Which exceptions should a role-flow test include?
Test a temporary teacher, a guardian linked to several children, a learner changing class, a departed staff member and an emergency support path. These cases reveal how access changes, notifications and audit records work when identities and responsibilities do not follow the simplest path.
Does this guide describe verified Easy Edu permissions?
No. Easy Edu has not supplied a current permission model, product version or demonstration evidence. The timetable and role imagery are illustrative. The matrix is a reusable request that a school can apply to Easy Edu or another vendor without assuming the answer.
See every guide in the insights index →
EXTERNAL CONTEXT
- Google for Education: Classroom roles and guardian context
- UNESCO: 2023 Global Education Monitoring Report
- Malaysia Personal Data Protection Department: FAQ
- Malaysia Personal Data Protection Department: principles
External sources explain category or evaluation context. They do not endorse Easy Edu or prove its product capabilities.
NEXT MOVE
Follow every role into the data record
Use the data guide to examine ownership, retention and exit.
Review school data questions