FEATURE · Identity & Access Management

अपने स्कूल के असली स्टाफ रोल बनाएं। मिनटों में। बिना IT टीम।

आपके स्कूल का ऑफिस ऐसे लोगों से भरा है जो दो-तीन भूमिकाएं निभाते हैं — Maths टीचर जो Class Teacher भी है, accountant जो transport fees भी देखता है, librarian जो शनिवार को Front Desk भी संभालती है। Custom Role Builder से आपके principal हर एक काम का नाम रखकर, Inkwelly में वो क्या देख और कर सकें यह तय करके, हर उस staff member के लिए वही रोल reuse कर सकते हैं जो अगले साल उस कुर्सी पर बैठेगा।

भारतीय स्कूल एक ही password क्यों share करने लग जाते हैं

Admission week चल रहा है। आपकी office assistant को 40 नए students ERP में डालने हैं, लेकिन पांच साल पहले खरीदा हुआ software सिर्फ तीन तरह के users जानता है — Admin, Teacher, Accountant। 'Admit Student' का बटन Admin के अंदर है। तो वो 11 बजे principal के cabin में जाती हैं, password मांगती हैं, अपने computer पर type करती हैं, काम पूरा करके अपनी कुर्सी पर लौट आती हैं। Principal का password अब building के तीन computers पर है।

कुछ हफ्ते बाद एक salary slip गलती से एक parent के inbox में चली जाती है — ऐसे screen से जिस पर किसी ने principal की login से काम किया था। किसने Send क्लिक किया कोई नहीं जानता। Audit बताता है principal ने भेजी। उन्होंने नहीं भेजी।

यह पुराने ERPs चला रहे ज़्यादातर भारतीय स्कूलों की रोज़मर्रा की हकीकत है। या तो role list बहुत संकुचित है — Admin, Teacher, Accountant — और आपका असली org chart (Vice Principal, Discipline Coordinator, House Master, Lab Assistant, Sports In-charge, Counsellor, Hostel Warden, Front Desk, Transport Coordinator, Librarian) तीन डिब्बों में ज़बरदस्ती फिट किया जाता है। या system इतना मोटा है कि teacher को 'view student fees' देने का मतलब 'edit fee receipts' भी देना है। नतीजा एक ही — office में login share होते हैं। Principal का password पूरे स्कूल का password बन जाता है। और जब कुछ गलत होता है, कोई साबित नहीं कर पाता कि वाकई किसने किया।

हमने role layer को बिल्कुल नए सिरे से बनाया। Inkwelly के Custom Role Builder से आपके principal तीस मिनट बैठकर अपने स्कूल में चलने वाले बिल्कुल सही रोल बना देते हैं — उन्हीं नामों से जिन नामों से आपका स्कूल पहले से बुलाता है। हर रोल के लिए वो टिक करते हैं कि वो रोल Inkwelly में क्या-क्या देख और कर सके। Save। उस दिन से, आपके स्कूल में जो भी accountant, class teacher या coordinator आता है, वो ऐसी कुर्सी पर बैठता है जो पहले से जानती है उन्हें क्या-क्या allowed है। Login कोई share नहीं करता। Principal का password कहीं नहीं घूमता। और जब कोई inspector या auditor पूछे 'किसको क्या दिखता है?' तो जवाब 10 second में आपके सामने होता है।

आपके स्कूल में Custom Role Builder कैसे काम करता है

Inkwelly में IAM dashboard खोलें → Roles क्लिक करें → + New Role क्लिक करें। Builder दो आसान सेक्शन के साथ खुलता है — name और permissions।

Step 1 — रोल का नाम वही रखें जो आपके staffroom में पहले से इस्तेमाल होता है। जो भी आपका स्कूल बुलाता है वही type करें। Class Teacher. Vice Principal. Discipline Coordinator. Lab Assistant. Hostel Warden. Sports In-charge. Computer Teacher. House Master. Transport Coordinator. Library Assistant. Counsellor. Accounts Clerk. Front Desk. IT Helper। सब valid हैं। एक छोटी description चाहें तो जोड़ सकते हैं — जैसे 'Grades 1 to 5 के class teachers के लिए'। Save।

Step 2 — टिक करें कि रोल क्या-क्या कर सके। Permission panel Inkwelly के हर area को साथ में group करता है — Students, Student Attendance, Employees, Fees, Payroll, Subjects, Timetable, Examinations, Transport, Library, Homework, Events, Media Center, Website CMS, AI Tools, IAM, Audit Logs। हर area खुलकर simple actions दिखाता है — view, create, edit, delete, import, export, approve। टिक करें वो काम जो यह रोल कर सके। बाकी छोड़ दें।

एक Class Teacher रोल को आम तौर पर मिलता है: students देखना, attendance देखना और mark करना, timetable देखना, exam marks डालना, homework बनाना और चेक करना, media upload करना। बारह क्लिक। Save। रोल लाइव है, assign होने को तैयार।

सिर्फ वही modules जो आपने subscribe किए हैं। अगर आपका स्कूल basic plan पर है और Transport उसमें नहीं है, तो Transport permissions builder में दिखेंगे ही नहीं। यह नहीं हो सकता कि आप गलती से किसी रोल को ऐसा access दे दें जो आपके पास है ही नहीं। जिस दिन Transport जुड़ता है, वो permissions अपने आप दिखने लगती हैं — और आप तय करते हैं कि कौन-से existing रोल को मिले।

हर staff पर वही रोल reuse करें। एक बार Class Teacher रोल save हो गया, तो आपके स्कूल का हर class teacher वही रोल assign कराता है। 22 class teachers? एक रोल, 22 assignments। कल आप तय करते हैं कि class teachers को parent-teacher meeting से पहले अपनी class की fee dues भी दिखनी चाहिए — रोल खोलें, 'view student fees' टिक करें, save। 22 teachers को अगली login से fee dues दिखने लगती हैं। हर teacher पर अलग काम नहीं।

Six template roles, बॉक्स के बाहर से ही तैयार। Inkwelly छह pre-built role templates के साथ आता है — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — जो भारतीय स्कूल के सबसे आम काम पैटर्न को cover करते हैं। Seed Default Roles पर क्लिक करें और वो instant आ जाते हैं, sensible permissions पहले से ticked। ज़्यादातर स्कूल इन्हें starting point की तरह इस्तेमाल करते हैं और हर रोल पर 2–3 permissions अपनी संरचना के हिसाब से customize करते हैं।

रोल किन हिस्सों से बनाया जा सकता है — आपके स्कूल का हर हिस्सा

  • Student records — student profiles देखना, नए students admit करना, details edit करना, classes के बीच transfer करना, birth certificates और previous school documents जैसे कागज़ात manage करना, student lists निकालना, bulk data import करना, admission settings manage करना।
  • Student attendance — रोज़ की attendance देखना, class की attendance mark करना, leave applications manage करना, attendance rules configure करना, principal के monthly review के लिए reports निकालना।
  • Employee records — staff profiles देखना, नए joiners जोड़ना, details edit करना, academic assignments manage करना, appointment letters और documents upload करना, staff lists निकालना, HR settings manage करना।
  • Employee attendance — staff attendance देखना, in-out times mark करना, leave applications manage करना, अधीनस्थ leaves approve करना, shift settings configure करना, department-wise reports निकालना।
  • Student fees — fee status देखना, fee structures और discounts set करना, invoices बनाना, cash और online payment लेना, receipts देना, refunds manage करना, scholarships और RTE quotas handle करना, fines manage करना, cheque entries manage करना, fee dashboard देखना। बारीकी: ज़्यादातर स्कूल इसे Senior Accountant (सब कुछ कर सकें) और Junior Accountant (सिर्फ payment लें और receipt दें — refunds और reversals नहीं) में बांटते हैं।
  • Employee payroll — payslips देखना, salary heads configure करना, monthly payroll चलाना, loans manage करना, TDS manage करना, EPFO और ESIC compliance file करना, investment declarations manage करना, arrears handle करना, full-and-final settlement process करना, payroll dashboard देखना।
  • Subjects — subjects देखना, नए subjects बनाना, edit, delete, हर class के subjects manage करना।
  • Timetable — timetable देखना, master templates बनाना और edit करना, class timetables बनाना, individual periods edit करना, substitution handle करना।
  • Examinations — exams देखना, assessment patterns configure करना, exams बनाना, subject-exam mapping manage करना, marks डालना, marks verify करना, final results manage करना, co-scholastic grading manage करना।
  • Transport — routes देखना, fleet और drivers manage करना, routes और stops manage करना, students और staff को routes assign करना, trips और route attendance manage करना, transport fees और refunds manage करना, parent transport requests handle करना, configuration और safety records manage करना।
  • Homework — homework देखना, नया homework बनाना, edit, delete, student submissions manage करना, homework dashboard देखना।
  • Events — school calendar देखना, events बनाना और edit करना, delete, event statistics देखना।
  • Media center — files देखना, files upload करना, media manage करना, trash manage करना, storage limits manage करना।
  • Website content — school website pages, news, events, photo galleries, public API keys manage करना।
  • AI tools — AI features देखना, AI से content generate करना, AI configuration और quotas manage करना।
  • IAM खुद — roles देखना, roles manage करना, assignments देखना, assignments manage करना। ज़्यादातर स्कूल यह सिर्फ Principal और एक भरोसेमंद IT helper को देते हैं।
  • Audit logs — master audit trail देखना। Principal, school trustee, और inspection week में आने वाले external auditor के अस्थायी login के लिए reserved।

सिर्फ वही modules जो आपके स्कूल के पास हैं। और कुछ नहीं।

Permission catalogue सिर्फ वही modules दिखाता है जो आपका स्कूल असल में इस्तेमाल कर रहा है। अगर Transport आपके plan में नहीं है, तो Transport permissions builder में आती ही नहीं। न grey, न upgrade pop-up के पीछे छुपी। बस नहीं हैं। यह संभव नहीं कि किसी रोल के लिए 'manage bus routes' टिक हो जाए और 6 महीने बाद — जब Transport जुड़े — पता चले कि किसी को गलती से access मिल गया था।

जिस दिन Transport जुड़ता है, हर मौजूदा रोल वही करता रहता है जो वो कल कर रहा था — और builder में नया Transport section दिखाई देने लगता है। आप तय करते हैं कि किस रोल को Transport access मिले। Principal रोल को शायद सब कुछ। Class Teacher रोल को शायद कुछ नहीं। नए modules कभी चुपके से किसी रोल का दायरा नहीं बढ़ाते। नई permissions हमेशा आप ही टिक करते हैं।

खाली पन्ने से नहीं — template से शुरू करें

Seed Default Roles क्लिक करें और Inkwelly छह template रोल instant बना देता है: Principal (पूरे स्कूल का access), Vice Principal (ज़्यादातर areas, payroll configuration नहीं), Teacher (attendance, homework, exams, timetable view), Accountant (पूरे fees और payroll, staff और students पर सिर्फ view), Clerk (students और attendance पर basic data entry), Transport Manager (पूरा transport area)। Permission ticks आम भारतीय स्कूल के काम पैटर्न के लिए पहले से भरी होती हैं।

ज़्यादातर स्कूल हर template रोल पर दो-तीन permissions अपनी संरचना के हिसाब से बदलते हैं — जैसे Teacher रोल में 'view fee dues for my class' जोड़ना ताकि class teachers parent meeting से पहले pending fees देख सकें। Seed action एक से ज़्यादा बार चलाना सुरक्षित है: अगर उसी नाम का रोल पहले से है, तो वो skip हो जाता है। एक स्कूल setup करते समय एक बार चलाएं। उसके बाद customize करते रहें। जो रोल templates में नहीं हैं उन्हें नया जोड़ लें।

एक बार रोल edit करें, हर assigned staff को बदलाव दिखता है

Inkwelly में रोल एक reusable definition है, हर employee की अलग copy नहीं। जब आप Class Teacher रोल पर एक extra permission टिक करते हैं, तो आपके स्कूल के हर class teacher को अगली login पर वो नई permission दिख जाती है। न re-assignment, न support call, न browser-cache क्लियर करना। रोल ही source of truth है, और assignments उसी की तरफ इशारा करते हैं।

इसी तरह Inkwelly आपके स्कूल में होने वाले बदलाव को पुराने ERPs के 2-दिन के rollout cycle के बिना handle करता है। नया CBSE circular कहता है कि class teachers को transport waivers भी approve करनी चाहिए? रोल खोलें, permission टिक करें, save। 22 teachers, एक बदलाव, एक मिनट। अगले हफ्ते लगा कि गलती हो गई? Permission untick करें, save। Access उसी मिनट में सिकुड़ जाती है। Control आपके principal के पास है — vendor की helpdesk के पास नहीं।

Safety rails ताकि एक misclick से production न रुके

Inkwelly में दो delete rules हैं ताकि व्यस्त सुबह में हुई एक ईमानदार गलती आपके स्कूल को lock-out न कर दे।

Built-in template roles delete नहीं हो सकते। छह template रोल — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — protected हैं। Delete बटन grey होता है, साथ में tooltip कारण समझाता है। आप उनकी permissions स्वतंत्र रूप से edit कर सकते हैं, deactivate कर सकते हैं, यहां तक कि rename भी कर सकते हैं। पर हटा नहीं सकते। तो किसी misconfiguration से recover करता स्कूल हमेशा यह baseline रोल वापस इस्तेमाल कर सकता है।

जिस रोल पर active staff हैं वो delete नहीं हो सकता। अगर एक भी teacher को वो रोल assigned है, तो system delete को साफ message के साथ रोक देता है: 'This role has 22 active staff members and cannot be deleted'। या तो पहले Role Assignments से assignments revoke करें, या रोल को inactive कर दें — inactive रोल system में रहते हैं, अपनी assignment history audit के लिए रखते हैं, पर नई logins उन्हें इस्तेमाल नहीं करतीं। कोई teacher गलती से access नहीं खोता।

आपके trust के हर स्कूल की अपनी role list है

आपके Lucknow स्कूल का Accountant रोल और Bareilly स्कूल का Accountant रोल बिल्कुल अलग हैं। नाम वही, permissions अलग, audit history अलग, staff अलग। यह जानबूझकर है — एक ही trust के अलग-अलग स्कूलों में अक्सर अलग staff designations, अलग module subscriptions, और अलग governance rules होते हैं।

एक central trust admin एक बार के setup से सभी 12 स्कूलों में एक ही रोल खड़ा कर सकते हैं, पर rows independent ही रहती हैं। Lucknow Accountant रोल edit करने से Bareilly वाला नहीं बदलता। Patna स्कूल से teacher हटाने से उनकी access trust के किसी और स्कूल पर असर नहीं डालती। हर स्कूल का data end-to-end isolated है — किसी school-level user के लिए दूसरे स्कूल की role list पढ़ने का कोई रास्ता नहीं, चाहे वो कोशिश ही क्यों न करे।

असल भारतीय स्कूल Inkwelly में कौन-से रोल बनाते हैं

पांच असल रोल जो आज production Inkwelly स्कूलों में चल रहे हैं, और हर एक में आम तौर पर क्या होता है:

1. Class Teacher. Students देखना। Class की attendance देखना और mark करना। Subjects और timetable देखना। Exam marks डालना। Homework बनाना, edit करना, चेक करना। School events देखना। Media upload करना। अपनी attendance self-service करना। करीब 20 ticks। CBSE और ICSE स्कूलों में रोज़ काम आने वाला सबसे आम रोल।

2. Senior Accountant. Fees पर पूरा access — structures बनाना, invoices निकालना, cash और online payment लेना, receipts देना, refunds manage करना, reversals चलाना, scholarships manage करना, cheques manage करना, dashboard देखना। Payroll पर पूरा access — salary heads, monthly run, TDS, EPFO, ESIC, full-and-final। Students और staff पर सिर्फ view। Transport पर सिर्फ view, साथ में transport fees और refunds। वो accountant जो books बंद करता है, payroll चलाता है, और महीने का compliance file करता है।

3. Junior Accountant. Fees देखना। Cash और online payment लेना। Receipts देना। Cheques manage करना। Students और staff देखना ताकि search कर सकें। Transport देखना। Refunds नहीं, reversals नहीं, payroll नहीं, fee config नहीं। Front desk का collection counter जो पैसे ले सकता है और receipt दे सकता है — पर fee structure edit नहीं कर सकता और payment reverse नहीं कर सकता।

4. Transport Coordinator. पूरा transport access — fleet, drivers, routes, stops, student और staff route mapping, trips और attendance, transport fees, refunds, parent requests, configuration, safety। Students और staff देखना ताकि search कर सकें। Fees, payroll, या examinations पर शून्य access। वो व्यक्ति जो आपकी सुबह की bus operation चलाता है।

5. Vice Principal. ज़्यादातर areas पर read-only, और academics, attendance, homework, events, timetable पर edit access। Payroll चला नहीं सकते। Fee configuration edit नहीं कर सकते। Student profile delete नहीं कर सकते। बिल्कुल वही 'oversight without unilateral execution authority' का सिद्धांत जो ज़्यादातर स्कूलों के governance documents कागज़ पर बताते हैं — पर आज तक किसी ERP ने लागू नहीं किया।

हर रोल बनाने में पहली बार 2–4 मिनट लगते हैं। उसके बाद, उस कुर्सी पर बैठने वाला हर नया staff member 30 second में productive हो जाता है — रोल assign करें, login दें, काम शुरू।

8 परिस्थितियां जहां role builder अपनी कीमत वसूल कर लेता है

  • 1 अप्रैल को नया accountant join होता है। आपके principal IAM खोलते हैं, मौजूदा Senior Accountant रोल नए joiner के लिए टिक करते हैं, login हाथ में देते हैं। 10:30 तक वो counter पर fee receipts ले रही हैं — कोई shared password नहीं, vendor का इंतज़ार नहीं।
  • Class teacher को Vice Principal बनाया जाता है। Assignment खोलें, Class Teacher को Vice Principal से swap करें, save। उनकी dashboard अगली login पर बदल जाती है। दो हफ्ते का IT rollout नहीं, पुराने और नए रोल का overlap नहीं।
  • जांच के दौरान staff suspend। Role Assignments से उनके रोल को inactive mark करें। उनकी access तुरंत खत्म। History audit trail में रहती है। जांच साफ हो जाए तो एक क्लिक में बहाल कर दें।
  • बीच साल में नया module जुड़ना (Library)। जब आप Library जोड़ते हैं, builder में नई permission section दिखती है। तय करें कौन-से रोल को library access मिले। ज़्यादातर स्कूल Librarian रोल को पूरा access और Class Teachers को सिर्फ view देते हैं।
  • Sister-schools, अलग staff structures। School A House Master कहता है, School B Coordinator कहता है। हर स्कूल की अपनी role list बनाती है। Trust admin दोनों को centrally देखता है, बिना एक common नाम मनवाए।
  • Board inspection में auditor visit। IAM dashboard से role-permission matrix print करें, inspection file में लगाएं। 'आपके स्कूल में fee receipts कौन edit कर सकता है?' पूछने वाले auditors को 30 second में precise printed जवाब मिलता है — meeting नहीं।
  • त्रैमासिक DPDP access review। रोल से assignments filter करें, IAM compliance export चलाएं, Data Fiduciary के तौर पर sign-off करें। पुराने ERPs में आधा दिन लगने वाला review अब Inkwelly में 20 मिनट।
  • किसी एक काम के लिए one-off रोल। एक teacher बुधवार को Computer Lab संभालती हैं। Computer Lab Assistant रोल बनाएं, उसमें सिर्फ 'view students' और 'upload media'। दो-permission रोल, दो मिनट का setup, एक staff को assigned, मसला हल।

अपने स्कूल के modules पर live role builder देखें

30-मिनट का walkthrough — अपने स्कूल की असली staff designation list लेकर आएं। हम आपके पांच सबसे ज़रूरी रोल आपके असली Inkwelly setup पर एक साथ बना देंगे।

Parent module — Identity & Access ManagementRole assignment कैसे काम करती है

सीमाएं, सुरक्षा, और छोटी बारीकियां

जितने रोल चाहिए, उतने बनाएं। स्कूल के अंदर कोई limit नहीं। 200+ staff और 15 अलग designations वाले स्कूल भी production में 12 से 15 से ज़्यादा रोल कम ही बनाते हैं — हर वो staff जो वही काम करता है, वही रोल इस्तेमाल करता है। अगर आप 25वां रोल बना रहे हैं, तो यह आम तौर पर मतलब है कि लाइनें बहुत बारीक हो गई हैं — मिलते-जुलते रोल को एक करें, या multi-role assignment इस्तेमाल करें।

आपकी role definitions कभी चुपके से नहीं बढ़तीं। जब Inkwelly कोई नई feature launch करता है, नई permissions मौजूदा modules में जुड़ती हैं — पुरानी जो आपने बनाई हैं, उन्हें न rename किया जाता है न हटाया जाता है। 2024 में save किया रोल 2026 में भी काम करता है। नई permissions तब तक off रहती हैं जब तक आप टिक नहीं करते। आपकी access policy कभी आपकी पीठ पीछे नहीं बढ़ती।

Template रोल templates हैं, frozen नहीं। छह built-in रोल पूरी तरह editable हैं। Permissions हटाएं, जोड़ें, rename करें — वो starting points हैं, contracts नहीं। एकमात्र restriction यह है कि उन्हें delete नहीं कर सकते, ताकि आपके पास हमेशा एक recovery baseline हो।

रोल नाम स्कूल के अंदर unique होने चाहिए। एक ही स्कूल में दो Accountant रोल reject हो जाते हैं friendly error के साथ। एक ही trust के अलग स्कूलों में नाम independent हैं — Lucknow का Accountant और Bareilly का Accountant अलग हैं।

Save-time validation। जब आप रोल save करते हैं, Inkwelly check करता है कि हर ticked permission उस module की हो जिसे आपके स्कूल ने subscribe किया है। कुछ गलत हो तो save fail होता है साफ message के साथ — गलत permissions कभी चुपके से save नहीं होतीं।

हर रोल पर live staff count। Roles list हर रोल के लिए दिखाती है कि कितने active staff उसे hold करते हैं — Principal: 1, Class Teacher: 22, Accountant: 3। तो high-impact रोल बदलने से पहले आप blast radius देख लेते हैं। जब assign या revoke होता है, यह number real time में update होता है।

Multi-school isolation। Inkwelly के हर area की तरह, आपके रोल सख्ती से आपके स्कूल के अंदर हैं। दूसरे स्कूल का कोई रोल न दिखता है न assignable है। Multi-school trusts independent चलते हैं, trust-admin level सिर्फ reporting के लिए cross-school visibility देता है — editing के लिए नहीं।

Inkwelly audit log पर बना है। हर रोल जो बनाया, edit, या delete हुआ, और हर permission जो टिक या untick हुई — Audit Logs में timestamp और बदलाव करने वाले admin के साथ दर्ज होती है। अगर मई में permission जुड़ी और अक्टूबर में हटी, तो दोनों events log में हैं। आपका DPDP-compliance evidence इसी trail पर बनता है।

किस मॉड्यूल का हिस्सा

2 modules

अक्सर पूछे गए सवाल

7 सवाल
मैं कितने custom रोल बना सकता हूं?

Unlimited। स्कूल पर कोई cap नहीं। ज़्यादातर भारतीय स्कूल production में 8–15 रोल इस्तेमाल करते हैं — Class Teacher, Subject Teacher, Vice Principal, Accountant, Junior Accountant, Clerk, Transport Coordinator, Librarian, और कुछ specialised जैसे Hostel Warden या Lab Assistant। अगर आप 25वां रोल बना रहे हैं, तो आम तौर पर मतलब है कि लाइनें बहुत बारीक हैं — मिलते-जुलते रोल को एक करें, या multi-role assignment इस्तेमाल करें (एक staff member कई रोल hold कर सकता है)।

क्या मैं Inkwelly के built-in system roles edit कर सकता हूं?

हां — आज़ादी से। छह pre-built रोल — Principal, Vice Principal, Teacher, Accountant, Clerk, Transport Manager — templates हैं, frozen नहीं। System flag सिर्फ deletion से बचाता है। आप उन्हें rename कर सकते हैं, उनकी permissions बदल सकते हैं, deactivate कर सकते हैं। ज़्यादातर स्कूल हर system रोल पर 2–3 permissions अपनी संरचना के हिसाब से बदलते हैं — जैसे Teacher रोल में 'view fee dues for my class' जोड़ना ताकि class teachers parent meeting से पहले pending fees देख सकें।

जब मैं किसी रोल की permissions बदलता हूं, तो मौजूदा staff पर क्या असर होता है?

जो भी staff उस रोल को hold करते हैं उन्हें अगली login पर नई permission set मिल जाती है। न re-assignment, न manual rollout, न support ticket। रोल ही source of truth है, और assignments उसी की तरफ इशारा करते हैं। अगर आप Class Teacher रोल पर एक extra permission टिक करते हैं और 22 teachers उसे hold करते हैं, तो सभी 22 को अगली login पर वो permission दिखती है। Inkwelly Audit Log बदलाव को timestamp और admin user के साथ record करता है — पूरा traceable।

क्या किसी ऐसे module की permissions रोल में जुड़ सकती हैं जो मैंने subscribe नहीं किया?

नहीं। रोल builder में permission catalogue सिर्फ वो modules दिखाता है जो आपके स्कूल में enabled हैं। अगर Transport आपके plan में नहीं है, तो Transport permissions builder में आती ही नहीं — गलती से access देने का कोई रास्ता नहीं। जब आप नया module जोड़ते हैं, उसकी permissions builder में दिखने लगती हैं और आप तय करते हैं कि कौन-से existing रोल को मिले। नए modules की default access शून्य होती है — कभी चुपके से रोल का दायरा नहीं बढ़ता।

क्या एक ही रोल हमारे trust के सभी schools में हो सकता है?

हर स्कूल की अपनी independent role list है। एक स्कूल में बनाया रोल दूसरे में अपने आप नहीं दिखता। यह जानबूझकर है — एक ही trust के अलग-अलग स्कूलों में अक्सर अलग staff designations, अलग module subscriptions, और अलग governance होती है। Trust admin एक बार के setup से सभी 12 स्कूलों में same रोल same permissions के साथ खड़े कर सकते हैं — पर rows independent रहती हैं। Lucknow का Accountant edit करने से Bareilly का नहीं बदलता।

क्या मैं ऐसे रोल को delete कर सकता हूं जिस पर staff अभी assigned हैं?

नहीं — Inkwelly साफ error देता है: 'This role has X active staff members and cannot be deleted'। Delete करने के लिए, पहले Role Assignments से assignments revoke करें, फिर रोल delete करें। या रोल को inactive कर दें — inactive रोल system में रहते हैं, history बरकरार रहती है audit के लिए, पर नई logins उन्हें इस्तेमाल नहीं करतीं। यह safety rail active staff की accidental access loss रोकता है।

क्या हर रोल बदलाव DPDP Act compliance के लिए record होता है?

हां — हर रोल create, edit, delete, और हर permission tick Inkwelly Audit Log में timestamp, user ID, role ID, और बदलाव के diff के साथ लिखी जाती है। अगर permission मई में टिक हुई और अक्टूबर में untick, तो दोनों events log में हैं उस admin के साथ जिसने हर बदलाव किया। यह आपका DPDP-compliance evidence का foundation है — '15 अप्रैल को fee records किसको दिख सकते थे' पूछने वाले auditors को seconds में precise जवाब मिलता है, forensic project नहीं।

आपको ये भी पसंद आ सकता है

3 लेख

Inkwelly आपके स्कूल पर — खुद देखें

30 मिनट का डेमो। आपके मौजूदा ERP को आपके साथ खोलकर, कॉल पर ही आपका डेटा Inkwelly में लोड करते हैं। कॉल ख़त्म होते-होते एक तय तारीख़ का गो-लाइव प्लान आपके हाथ में।