FEATURE · Identity & Access Management

Build the staff roles your school actually runs on. In minutes. No IT team needed.

Your school's office is full of people who wear two or three hats — the Maths teacher who is also a Class Teacher, the accountant who also handles transport fees, the librarian who also runs the front desk on Saturdays. The Custom Role Builder lets your principal name every one of those jobs, tick exactly what they should see and do inside Inkwelly, and reuse the role for every staff member who steps into that chair next year.

Why Indian schools end up sharing one password

It is admission week. Your office assistant needs to add 40 new students into the school ERP, but the software you bought five years ago only knows three kinds of users — Admin, Teacher, and Accountant. 'Admit Student' lives under Admin. So she walks into the principal's cabin at 11 a.m., asks for the password, types it into her own computer, finishes the work, and goes back to her desk. The principal's password is now on three computers in the building.

A few weeks later, a salary slip ends up in a parent's inbox by mistake — sent from a screen that someone had logged into using the principal's credentials. Nobody knows who clicked Send. The audit shows the principal sent it. He did not.

This is the everyday reality of staff access in most Indian schools running older ERPs. Either the role list is too narrow — Admin, Teacher, Accountant — and your real org chart (Vice Principal, Discipline Coordinator, House Master, Lab Assistant, Sports In-charge, Counsellor, Hostel Warden, Front Desk, Transport Coordinator, Librarian) is forced into one of three boxes. Or the system is so coarse that giving a teacher 'view student fees' also gives them 'edit fee receipts'. Either way, the office shares logins. The principal's password becomes the school's password. And when something goes wrong, nobody can prove who actually did it.

We rebuilt the role layer from scratch. With Inkwelly's Custom Role Builder, your principal sits down for thirty minutes and lays out the exact roles your school uses — by the names your school already calls them. For each role, your principal ticks exactly what that role should see and do inside Inkwelly. Save. From that day, every accountant, every class teacher, every coordinator who ever joins your school steps into a chair that already knows what they can and cannot do. No shared logins. No principal's password floating around. And when an inspector or auditor asks 'who can see what?', the answer is in front of you in ten seconds.

How the Custom Role Builder works in your school

Open the IAM dashboard in Inkwelly → click Roles → click + New Role. The builder opens with two simple sections — name and permissions.

Step 1 — name the role the way your school already names it. Type whatever your staffroom uses. Class Teacher. Vice Principal. Discipline Coordinator. Lab Assistant. Hostel Warden. Sports In-charge. Computer Teacher. House Master. Transport Coordinator. Library Assistant. Counsellor. Accounts Clerk. Front Desk. IT Helper. All valid. Add a one-line description if you want — like 'For class teachers of grades 1 to 5'. Save.

Step 2 — tick what the role can do. The permissions panel groups every Inkwelly area together — Students, Student Attendance, Employees, Fees, Payroll, Subjects, Timetable, Examinations, Transport, Library, Homework, Events, Media Center, Website CMS, AI Tools, IAM, Audit Logs. Each area opens up to show simple actions like view, create, edit, delete, import, export, approve. Tick what this role should be able to do. Skip what they shouldn't.

A Class Teacher role typically gets: see students, view and mark attendance, see the timetable, enter exam marks, create and check homework, upload media. Twelve clicks. Save. The role is live and ready to assign.

Only the modules your school subscribes to. If your school is on a basic plan and Transport is not part of it, Transport permissions do not appear in the builder. There is no way to accidentally give a role access to something your school does not own. The day you upgrade to add Transport, those permissions show up — and you decide which of your existing roles get them.

Reuse the role on every staff member. Once you have the Class Teacher role saved, every class teacher in your school gets that role assigned. Twenty-two class teachers? One role, twenty-two assignments. Tomorrow you decide class teachers should also see fee dues for their class before parent-teacher meetings — open the role, tick 'view student fees', save. All twenty-two teachers see fee dues from their next login. No per-teacher rework.

Six template roles, ready out of the box. Inkwelly ships with six pre-built role templates — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — covering the most common Indian school job patterns. Click Seed Default Roles and they appear instantly with sensible permissions already ticked. Most schools use these as a starting point and customise two or three permissions per role to match their structure.

What you can build a role from — every part of your school's day

  • Student records — see student profiles, admit new students, edit details, transfer students between classes, manage documents like birth certificates and previous school records, run student lists, import bulk data, manage admission settings.
  • Student attendance — view daily attendance, mark attendance for a class, manage leave applications, configure attendance rules, run period and reports for the principal's monthly review.
  • Employee records — see staff profiles, add new joiners, edit details, manage academic assignments, upload appointment letters and documents, run staff lists, manage HR settings.
  • Employee attendance — view staff attendance, mark in-out times, manage leave applications, approve subordinate leaves, configure shift settings, run department-wise reports.
  • Student fees — view fee status, set fee structures and discounts, raise invoices, collect cash and online payments, issue receipts, manage refunds, handle scholarships and RTE quotas, manage fines, manage cheque entries, see the fee dashboard. Fine-grained: most schools split this into a Senior Accountant who can do everything and a Junior Accountant who can only collect payments and issue receipts (no refunds, no reversals).
  • Employee payroll — view payslips, configure salary heads, run monthly payroll, manage loans, manage TDS, file EPFO and ESIC compliance, manage investment declarations, handle arrears, process full-and-final settlement, see the payroll dashboard.
  • Subjects — view subjects, create new subjects, edit, delete, manage which subjects each class offers.
  • Timetable — view the timetable, create and edit master templates, build class timetables, edit individual periods, handle substitution.
  • Examinations — view exams, configure assessment patterns, create exams, manage subject-exam mapping, enter marks, verify marks, manage final results, manage co-scholastic grading.
  • Transport — view routes, manage fleet and drivers, manage routes and stops, assign students and staff to routes, manage trips and route attendance, manage transport fees and refunds, handle parent transport requests, manage configuration and safety records.
  • Homework — view homework, create new homework, edit, delete, manage student submissions, see the homework dashboard.
  • Events — view the school calendar, create and edit events, delete, see event statistics.
  • Media center — view files, upload files, manage media, manage trash, manage storage limits.
  • Website content — manage school website pages, news, events, photo galleries, public API keys.
  • AI tools — view AI features, generate content with AI, manage AI configuration and quotas.
  • IAM itself — view roles, manage roles, view assignments, manage assignments. Most schools give this only to the Principal and one trusted IT helper.
  • Audit logs — view the master audit trail. Reserved for the Principal, the school trustee, and any external auditor with a temporary login during inspection week.

Only the modules your school owns. Nothing else.

The permission catalogue only shows the modules your school is actually using. If Transport is not part of your plan, Transport permissions do not appear in the builder. Not greyed out. Not hidden behind an upgrade pop-up. Just not there. There is no way to tick 'manage bus routes' for a role and discover six months later — when you finally add Transport — that someone got access by accident.

The day you upgrade to add Transport, every existing role keeps doing exactly what it was doing yesterday — and the new Transport section appears in the builder. You decide which roles get Transport access. A Principal role likely gets it all. A Class Teacher role likely gets none. New modules never silently expand an existing role's reach. You always tick the new permissions yourself.

Start from a template, not from a blank page

Click Seed Default Roles and Inkwelly creates six template roles instantly: Principal (full school access), Vice Principal (most areas, no payroll configuration), Teacher (attendance, homework, exams, timetable view), Accountant (full fees and payroll, view-only on staff and students), Clerk (basic data entry on students and attendance), Transport Manager (full transport area). Permission ticks are pre-filled for the typical Indian-school job pattern.

Most schools edit two or three permissions per template role to match their own structure — for example, adding 'view fee dues for my class' to the Teacher role so class teachers can spot pending fees before parent meetings. The seed action is safe to run more than once: if a role with the same name already exists, it skips it. Run it once when you set up a school. Customise from there. Add new roles for the jobs your school has that the templates do not cover.

Edit the role once, every assigned staff sees the change

A role in Inkwelly is a reusable definition, not a per-employee copy. When you tick one extra permission on the Class Teacher role, every class teacher in your school sees that new permission on their next login. No re-assignment. No support call. No browser-cache clearing. The role is the source of truth, and assignments are simply pointers to it.

This is how Inkwelly handles structural change in your school without the two-day rollout cycle older ERPs need. New CBSE circular asks class teachers to also approve transport waivers? Open the role, tick the permission, save. Twenty-two teachers, one change, one minute. Decide the next week it was a mistake? Untick the permission, save. Their access shrinks back in the same minute. The control sits with your principal — not with a vendor's helpdesk.

Safety rails so a misclick never breaks production

Inkwelly has two delete rules so an honest mistake on a busy morning does not lock your school out.

Built-in template roles cannot be deleted. The six template roles — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — are protected. The Delete button is greyed out with a tooltip explaining why. You can edit their permissions freely, deactivate them, even rename them. But you cannot remove them. So a school recovering from a misconfiguration always has these baselines to fall back to.

A role with active staff cannot be deleted. If even one teacher is currently assigned the role, the system blocks the delete with a clear message: 'This role has 22 active staff members and cannot be deleted'. Either revoke the assignments first using Role Assignments, or simply mark the role inactive — inactive roles stay in the system, retain their assignment history for audit, but no new logins use them. No teacher ever loses access by accident.

Each school in your trust has its own role list

Your Lucknow school's Accountant role and your Bareilly school's Accountant role are completely independent. Same name, separate permissions, separate audit history, separate staff. This is on purpose — different schools in the same trust often have different staff designations, different module subscriptions, and different governance rules.

A central trust admin can stand up the same role across all 12 schools using a one-time setup, but the rows stay independent. Editing the Lucknow Accountant role does not change the Bareilly one. Removing a teacher from the Patna school does not affect their access at any other school in the trust. Each school's data is isolated end-to-end — there is no path for a school-level user to read another school's role list, even if they tried.

Real-world roles Indian schools build in Inkwelly

Five realistic roles that production Inkwelly schools have running today, with what each role typically contains:

1. Class Teacher. See students. View and mark attendance for the class. See subjects and timetable. Enter exam marks. Create, edit, and check homework. View school events. Upload media. Self-service their own attendance. About 20 ticks. The daily-driver role used by most CBSE and ICSE schools.

2. Senior Accountant. Full access to fees — set structures, raise invoices, collect cash and online, issue receipts, manage refunds, run reversals, manage scholarships, manage cheques, see the dashboard. Full access to payroll — salary heads, monthly run, TDS, EPFO, ESIC, full-and-final. View-only on students and staff. View-only on transport with the ability to handle transport fees and refunds. The accountant who closes books, runs payroll, and files monthly compliance.

3. Junior Accountant. View fees. Collect cash and online payments. Issue receipts. Manage cheques. View students and staff so they can search. View transport. No refunds, no reversals, no payroll, no fee config. The collection counter operator at your front desk who can take money and issue receipts but cannot edit a fee structure or reverse a payment.

4. Transport Coordinator. Full transport access — fleet, drivers, routes, stops, student and staff route mapping, trips and attendance, transport fees, refunds, parent requests, configuration, safety. View students and staff so they can search. Zero access to fees, payroll, or examinations. The person who runs your morning bus operation.

5. Vice Principal. Read-only across most areas with edit access on academics, attendance, homework, events, and timetable. Cannot run payroll. Cannot edit fee configuration. Cannot delete a student profile. Exactly the principle of 'oversight without unilateral execution authority' that most schools' governance documents already specify on paper but no ERP has ever enforced.

Each role takes two to four minutes to build the first time. After that, every new staff member who steps into the chair is productive in 30 seconds — assign the role, give them their login, work begins.

Eight scenarios where the role builder pays for itself

  • A new accountant joins on April 1. Your principal opens IAM, ticks the existing Senior Accountant role for the new joiner, hands her the login. She is taking fee receipts at the counter by 10:30 a.m. — no shared password, no waiting for the vendor.
  • A class teacher is promoted to Vice Principal. Open her assignment, swap Class Teacher for Vice Principal, save. Her dashboard reshapes on her next login. No two-week IT rollout, no overlap of old and new roles.
  • Suspending a staff member during enquiry. Mark their role inactive using Role Assignments. Their access vanishes immediately. The history stays in the audit trail. Reinstate them in one click if the enquiry clears them.
  • Adding a new module mid-year (Library). When you upgrade to add Library, the new permission section appears in the builder. Decide which roles get library access. Most schools give Librarian role full access and Class Teachers view-only.
  • Different sister-schools, different staff structures. School A uses House Master, School B uses Coordinator. Each school builds its own role list. Trust admin sees both centrally without forcing a common name. Each school stays in control of its own structure.
  • Auditor visit during board inspection. Print the role-permission matrix from the IAM dashboard, attach to the inspection file. Auditors who ask 'who can edit fee receipts in your school?' get a precise printed answer in 30 seconds — not a meeting.
  • Quarterly DPDP access review. Filter assignments by role, run the IAM compliance export, sign off as Data Fiduciary. The quarterly review that takes a half-day in older ERPs takes 20 minutes in Inkwelly.
  • Adding a one-off role for a specific job. A teacher takes over the Computer Lab on Wednesdays. Build a Computer Lab Assistant role with only 'view students' and 'upload media'. Two-permission role, two-minute setup, one staff member assigned, problem solved.

See the role builder live on your school's modules

30-minute walkthrough — bring your school's actual staff designation list. We will build five of your most critical roles together, on your real Inkwelly setup.

See parent module — Identity & Access ManagementHow role assignment works

Limits, safety, and the small print

Build as many roles as you need. No per-school limit. Even schools with 200+ staff and 15 distinct designations rarely create more than 12 to 15 roles in production — the same role is reused across every staff member who does that job. If you find yourself making role number 25, that usually means the lines are too fine — group similar roles, or use multi-role assignment instead.

Your role definitions never silently expand. When Inkwelly ships a new feature, the new permissions are added to existing modules without renaming or removing anything you have already built. A role you saved in 2024 still works in 2026. New permissions default to off until you tick them. Your access policy never grows behind your back.

Template roles are templates, not frozen. The six built-in roles are fully editable. Remove permissions, add permissions, rename them — they are starting points, not contracts. The only restriction is that they cannot be deleted, so you always have a recovery baseline.

Role names must be unique within your school. Two roles named Accountant in the same school is rejected with a friendly error. Across different schools in the same trust, names are independent — Lucknow's Accountant and Bareilly's Accountant are separate.

Save-time validation. When you save a role, Inkwelly checks that every ticked permission belongs to a module your school has subscribed to. If something is wrong, the save fails with a clear message — never with the wrong permissions silently saved. Your role definition either works or returns a precise reason.

Live count of staff per role. The roles list shows, for every role, how many active staff currently hold it — Principal: 1, Class Teacher: 22, Accountant: 3. So before you change a high-impact role, you see the blast radius. The number updates in real time as your principal assigns or revokes.

Multi-school isolation. Like every Inkwelly area, your roles are strictly within your school. No role from another school is visible or assignable. Multi-school trusts run independently, with the trust-admin level providing cross-school visibility for reporting only — never for editing.

Built on the Inkwelly audit log. Every role created, edited, or deleted, and every permission ticked or unticked, is recorded in Audit Logs with timestamp and the admin who made the change. If a permission was added in May and removed in October, both events are in the log. This is the trail your DPDP-compliance evidence is built on.

Belongs to

1 module

Frequently asked

7 questions
How many custom roles can I create?

Unlimited. There is no per-school cap. Most Indian schools use 8–15 roles in production — Class Teacher, Subject Teacher, Vice Principal, Accountant, Junior Accountant, Clerk, Transport Coordinator, Librarian, and a few specialised roles like Hostel Warden or Lab Assistant. If you find yourself creating role 25, that usually means the granularity is too fine — group similar roles or use multi-role assignment (one staff member can hold multiple roles).

Can I edit Inkwelly's built-in system roles, or are they frozen?

You can edit them freely. The six seeded roles — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — are templates, not frozen. The system flag only protects them from deletion. You can rename them, modify their permission set, deactivate them, even change every permission. Most schools edit 2–3 permissions per system role to match their specific structure (for example, adding student_fee:view to the Teacher role so class teachers can see their students' fee status).

What happens to existing employees when I change a role's permissions?

All employees assigned that role get the new permission set on their next login. There is no re-assignment, no manual rollout, no support ticket. The role is the source of truth and assignments are pointers to it. If you tick one extra permission for the Class Teacher role and 22 teachers are assigned that role, all 22 see the new permission immediately on next login. The Inkwelly Audit Log records the role change with timestamp and admin user — so the change is fully traceable.

Can a role include permissions from a module I haven't subscribed to?

No. The permission catalogue in the role builder only shows permissions for modules enabled at your school. If Transport is not on your plan, Transport permissions do not appear in the builder — there is no way to accidentally grant access to a module you do not own. When you upgrade to add a new module, those permissions appear in the builder and you decide which existing roles should get them. The default for new modules is no access — never silent expansion of an existing role's reach.

Can the same role exist across all schools in our trust?

Each school has its own independent role list. A role you create at School A does not automatically appear at School B. This is deliberate — different schools in the same trust often have different staff designations, different module subscriptions, and different governance structures. A central trust admin can stand up the same role with the same permissions across all 12 schools using a one-time setup, but the rows are independent. Editing Lucknow's Accountant role does not change Bareilly's Accountant role.

Can I delete a role that employees are currently assigned to?

No — Inkwelly returns a clear error: 'This role has X active employee assignment(s) and cannot be deleted'. To delete, first revoke the assignments via Role Assignments, then delete the role. Or simply deactivate the role (isActive: false) — deactivated roles stay in the system with their assignment history intact for audit purposes, but no new logins use them. This safety rail prevents accidental access loss for active staff.

Is every role change recorded for DPDP Act compliance?

Yes — every role create, edit, delete, and every permission tick is written to the Inkwelly Audit Log with timestamp, user ID, role ID, and the diff of what changed. If a permission was ticked in May and unticked in October, both events are in the log with the admin who made each change. This is the foundation of your DPDP-compliance evidence — auditors who ask 'who had access to fee records on April 15' get a precise answer in seconds, not a forensic project.

You might also like

2 reads

See Inkwelly on your school

30-minute demo. We open your current ERP with you and load your data into Inkwelly on the call. Dated go-live plan by the end of it.