EdiWay brings school, family, learner and authorised professional workflows into one connected education environment. That creates opportunities to reduce duplication, preserve learner continuity and keep important evidence closer to the process that created it—but connection should never mean unrestricted access.
EdiWay is designed around a governed operating model in which identity, organisation, relationship, purpose, information sensitivity and permissions help determine what each person can see and what actions they can take.
EdiWay's platform architecture is built around shared learner, organisation, workflow, evidence and permission foundations.
This allows authorised workflows to use the same underlying context instead of repeatedly copying information between disconnected systems.
But a connected learner record does not mean a single visibility level.
One learner can have one connected journey without every user seeing the whole journey.
Ordinary role-based permissions are only part of EdiWay's access model.
Access can also take account of:
What is this person authorised to do?
Which school, trust, provider or organisation are they acting for?
Why does this person have a relationship with this learner?
Are they involved in the specific work being accessed?
Why is the information needed?
Does the information require stronger protection?
Are there additional controls that should prevent access?
This creates a more purposeful model than assuming everyone with the same job title should automatically have the same access everywhere.
Sensitive workflows are designed around a fail-closed principle.
Where the platform cannot establish the required actor, organisation, learner, relationship or record scope for a sensitive action, permission should not be inferred.
The action should be denied until the appropriate access conditions can be established.
This principle is especially important where information relates to:
Uncertainty should not become permission.
EdiWay distinguishes between having a platform account and having an authorised relationship with a learner.
Different relationships can carry different rights.
This helps EdiWay reflect how education actually works:
Access comes from responsibility and purpose, not simply from knowing who the learner is.
A connected system becomes less trustworthy when the origin of information disappears.
EdiWay is designed to preserve provenance.
Remains attributable to the school or authorised staff source.
Remains attributable to the learner.
Remain attributable to parents and carers.
Retain professional authorship.
Should retain relevant source and historical context.
Source matters because meaning depends on where information came from.
EdiWay's evidence model is designed to connect evidence back to the process that produced it. Where appropriate, an item can remain associated with:
Better governance depends on evidence remaining meaningful – not becoming another uncontrolled document archive.
EdiWay is designed to help people organise information, coordinate workflows, prepare evidence, surface actions and reduce repetitive administration.
It is not designed to remove human accountability from consequential education decisions.
Depending on the workflow, responsibility may remain with:
The platform may help structure the evidence. The responsible person remains accountable for the conclusion.
Some information requires stronger access boundaries than ordinary educational records.
EdiWay distinguishes sensitive domains rather than treating every learner record as equally visible.
Restricted to appropriately authorised safeguarding workflows and roles.
Purpose-limited and separately permissioned.
Available according to relevant role, relationship and workflow.
Can require controlled visibility depending on sensitivity and context.
Limited according to the authorised relationship and purpose.
Not automatically available to every person working with the learner.
A connected platform should reduce fragmentation without flattening important confidentiality boundaries.
Schools and families sometimes need to share information with another setting, provider or authorised professional.
EdiWay's governance model is designed around controlled sharing rather than unrestricted record access.
Important sharing decisions can consider:
Who is receiving the information?
Who does it concern?
Why is it being shared?
What information is actually needed?
What permission or lawful basis supports the disclosure where applicable?
Is access temporary or continuing?
Can the relationship or access be ended?
Can the disclosure itself be traced?
This supports collaboration while keeping the difference between sharing selected information and opening the learner record clear.
When a learner changes education pathway, selected information may need to move with them.
EdiWay's Transition Pack model is designed around a defined recipient and purpose rather than treating an exported record as unrestricted permission to reuse everything indefinitely.
Depending on the workflow, governance can consider:
A learner can therefore maintain continuity without every future organisation inheriting unrestricted access to the entire historical record.
Governance is stronger when material actions can be traced.
EdiWay's shared platform foundations are designed to support audit and security events around areas such as:
Audit does not replace good policy or professional accountability. It helps make those responsibilities more visible.
EdiWay AI is designed as an assistance layer within the same permission and learner boundaries as the wider platform.
Where enabled, AI may help authorised users:
But AI should only work with information the user is permitted to use for the relevant purpose.
Sensitive data does not become available simply because an AI feature is being used. Consequential AI output remains subject to human review.
AI can assist the work. It does not inherit the professional’s authority.
Safeguarding information should not be treated like ordinary platform content.
EdiWay's architecture deliberately excludes safeguarding records from broad AI search or retrieval by default.
Any AI capability involving safeguarding information would require a separately governed, purpose-specific workflow with the appropriate permissions and assurance.
This boundary matters because convenience should never silently widen access to highly sensitive records.
Schools and other organisations using education technology have their own data-protection responsibilities.
EdiWay is designed to support those responsibilities through platform controls around areas such as:
However, software alone does not make an organisation compliant. Schools and other responsible organisations still need appropriate policies, lawful bases, notices, staff practice, retention decisions and governance processes.
Different types of education information can have different retention requirements.
EdiWay should therefore not treat one retention period as appropriate for every record.
Governance can depend on:
The wider EdiWay learner-continuity model does not remove an organisation’s own responsibility to apply appropriate retention rules.
A platform can be secure and still fail users if people cannot access or understand it.
Accessibility therefore forms part of EdiWay's wider assurance approach. That includes considering how different users interact with:
Accessibility assurance is an ongoing product responsibility rather than a one-time design claim.
EdiWay's organisation model is designed to represent relationships between schools, trusts, local authorities, providers and shared services.
Those organisational relationships can support delegated responsibilities and appropriate oversight.
But being part of the same trust or organisation group should not automatically grant access to individual learner information.
Detailed school governance, policy and improvement workflows remain within the dedicated School Governance area.
Reports, dashboards, documents and exports should reflect the authoritative records behind them. EdiWay's reporting model is designed so that outputs remain permission-scoped and connected to canonical source information.
A report should not silently become a new independent record simply because it has been exported to a spreadsheet or document.
The same principle applies to analytics. Where EdiWay combines measures across areas such as attendance, SEND, behaviour, workforce or operations, definitions and access boundaries still matter. Correlation should not be presented as an automatic conclusion.
EdiWay distinguishes between different levels of product maturity.
A capability that can be described within its documented boundaries.
The core capability exists, but deployment, migration, role, provider, accessibility, legal or other assurance work may still be required.
A workflow is deliberately unavailable until the required configuration, permission, entitlement or policy is active.
A direction or capability that should not yet be marketed as available.
This distinction helps keep public product claims aligned with actual product assurance.
Moving education data between systems requires more than importing a spreadsheet. EdiWay's implementation approach is designed around stages such as:
Understand source systems and responsible data owners.
Identify where information belongs in the EdiWay model.
Recognise sensitive or high-risk records.
Use staged or dry-run migration where appropriate.
Move information through controlled processes.
Check counts, duplicates, attachments and exceptions.
Test roles, permissions and workflow behaviour.
Keep appropriate completion and exception evidence.
Historic information should not silently become a current statutory, safeguarding or professional conclusion simply because it was imported.
A secure platform cannot be assessed only by checking that authorised users can complete a workflow.
Sensitive areas also need testing for situations such as:
EdiWay’s assurance approach recognises that preventing the wrong action is as important as enabling the right one. Detailed technical and operational controls belong on the Data Security and Governance page.
EdiWay is designed around UK education workflows, including schools, families, SEND, safeguarding, Home Education, alternative provision, transition and emerging statutory processes.
The platform can be designed to support applicable workflows and policy requirements.
That does not mean EdiWay should claim:
Responsible organisations and authorised professionals remain responsible for the decisions that belong to them.
EdiWay should not automatically determine:
The platform can structure workflows, preserve evidence, enforce permissions and help people prepare information. Human decision-makers remain accountable.
Who is acting?
In which authorised context are they working?
Why do they have access to this learner or workflow?
What are they trying to do?
Does the information need stronger controls?
Apply the relevant permissions and restrictions.
Keep clear where information came from.
Retain appropriate audit and workflow evidence.
Ensure consequential decisions remain with the responsible person.
Change or end access when responsibility changes.Let college become the next stage – not a reset.
This is how a connected education platform can remain connected without becoming indiscriminate.
No.
EdiWay is designed so access can depend on role, organisation, learner relationship, case, purpose, sensitivity and other restrictions.
No.
A job title alone should not determine access to every learner or information area.
Sensitive actions are designed to fail closed rather than infer access.
No.
Family access remains dependent on the relationship, information type, permissions and applicable workflow.
No.
Professional access is designed to remain learner-specific and purpose-limited.
No.
Organisation membership does not automatically create learner-level access.
The platform is designed to preserve source and provenance so school, family, learner, professional and imported information can remain distinguishable.
No.
AI should operate within the same underlying access and purpose boundaries as the authorised user.
No.
Consequential professional and statutory decisions remain human decisions.
No.
Safeguarding information is excluded from broad AI retrieval by default.
No.
EdiWay can support governed workflows and evidence, but organisational compliance depends on law, policy, configuration, implementation and human practice.
EdiWay should not claim DfE or Ofsted endorsement unless a specific formal approval exists and can be evidenced.
The platform foundation is designed to record material actions, access, denials and lifecycle changes.
No.
Some capabilities may be supported, controlled, configuration-dependent, in assurance or part of a later product stage.
Explore platform access, security, audit and operational data controls.
Understand how relationships, purpose and information scope govern sharing.
See how EdiWay keeps AI permission-aware and human-reviewed.
Understand why safeguarding information requires separate, stronger controls.
Read how privacy and organisational data responsibilities fit around the platform.
Understand retention, account lifecycle and information rights.
See how EdiWay approaches migration, deployment and capability assurance.