EdiWay brings school, family, learner and authorised professional workflows into one connected education environment. That creates opportunities to reduce duplication, preserve learner continuity and keep important evidence closer to the process that created it—but connection should never mean unrestricted access.
EdiWay is designed around a governed operating model in which identity, organisation, relationship, purpose, information sensitivity and permissions help determine what each person can see and what actions they can take.
EdiWay's platform architecture is built around shared learner, organisation, workflow, evidence and permission foundations. This allows authorised workflows to use the same underlying context instead of repeatedly copying information between disconnected systems. But a connected learner record does not mean a single visibility level.
Ordinary role-based permissions are only part of EdiWay's access model. Access can also take account of:
What is this person authorised to do?
Which school, trust, provider or organisation are they acting for?
Why does this person have a relationship with this learner?
Are they involved in the specific work being accessed?
Why is the information needed?
Does the information require stronger protection?
Are there additional controls that should prevent access?
Sensitive workflows are designed around a fail-closed principle. Where the platform cannot establish the required actor, organisation, learner, relationship or record scope for a sensitive action, permission should not be inferred. The action should be denied until the appropriate access conditions can be established. This principle is especially important where information relates to:
EdiWay distinguishes between having a platform account and having an authorised relationship with a learner. Different relationships can carry different rights.
A connected system becomes less trustworthy when the origin of information disappears. EdiWay is designed to preserve provenance.
Remains attributable to the school or authorised staff source.
Remains attributable to the learner.
Remain attributable to parents and carers.
Retain professional authorship.
Should retain relevant source and historical context.
EdiWay's evidence model is designed to connect evidence back to the process that produced it. Where appropriate, an item can remain associated with:
EdiWay is designed to help people organise information, coordinate workflows, prepare evidence, surface actions and reduce repetitive administration. It is not designed to remove human accountability from consequential education decisions. Depending on the workflow, responsibility may remain with:
Some information requires stronger access boundaries than ordinary educational records. EdiWay distinguishes sensitive domains rather than treating every learner record as equally visible.
Restricted to appropriately authorised safeguarding workflows and roles.
Purpose-limited and separately permissioned.
Available according to relevant role, relationship and workflow.
Can require controlled visibility depending on sensitivity and context.
Limited according to the authorised relationship and purpose.
Not automatically available to every person working with the learner.
Schools and families sometimes need to share information with another setting, provider or authorised professional. EdiWay's governance model is designed around controlled sharing rather than unrestricted record access. Important sharing decisions can consider:
Who is receiving the information?
Who does it concern?
Why is it being shared?
What information is actually needed?
What permission or lawful basis supports the disclosure where applicable?
Is access temporary or continuing?
Can the relationship or access be ended?
Can the disclosure itself be traced?
When a learner changes education pathway, selected information may need to move with them. EdiWay's Transition Pack model is designed around a defined recipient and purpose rather than treating an exported record as unrestricted permission to reuse everything indefinitely. Depending on the workflow, governance can consider:
Governance is stronger when material actions can be traced. EdiWay's shared platform foundations are designed to support audit and security events around areas such as:
EdiWay AI is designed as an assistance layer within the same permission and learner boundaries as the wider platform. Where enabled, AI may help authorised users:
Safeguarding information should not be treated like ordinary platform content.
EdiWay's architecture deliberately excludes safeguarding records from broad AI search or retrieval by default.
Any AI capability involving safeguarding information would require a separately governed, purpose-specific workflow with the appropriate permissions and assurance.
This boundary matters because convenience should never silently widen access to highly sensitive records.
Schools and other organisations using education technology have their own data-protection responsibilities. EdiWay is designed to support those responsibilities through platform controls around areas such as:
Different types of education information can have different retention requirements. EdiWay should therefore not treat one retention period as appropriate for every record. Governance can depend on:
A platform can be secure and still fail users if people cannot access or understand it. Accessibility therefore forms part of EdiWay's wider assurance approach. That includes considering how different users interact with:
EdiWay's organisation model is designed to represent relationships between schools, trusts, local authorities, providers and shared services.
Those organisational relationships can support delegated responsibilities and appropriate oversight.
But being part of the same trust or organisation group should not automatically grant access to individual learner information.
Reports, dashboards, documents and exports should reflect the authoritative records behind them. EdiWay's reporting model is designed so that outputs remain permission-scoped and connected to canonical source information.
A report should not silently become a new independent record simply because it has been exported to a spreadsheet or document.
The same principle applies to analytics. Where EdiWay combines measures across areas such as attendance, SEND, behaviour, workforce or operations, definitions and access boundaries still matter. Correlation should not be presented as an automatic conclusion.
EdiWay distinguishes between different levels of product maturity.
A capability that can be described within its documented boundaries.
The core capability exists, but deployment, migration, role, provider, accessibility, legal or other assurance work may still be required.
A workflow is deliberately unavailable until the required configuration, permission, entitlement or policy is active.
A direction or capability that should not yet be marketed as available.
Moving education data between systems requires more than importing a spreadsheet. EdiWay's implementation approach is designed around stages such as:
Understand source systems and responsible data owners.
Identify where information belongs in the EdiWay model.
Recognise sensitive or high-risk records.
Use staged or dry-run migration where appropriate.
Move information through controlled processes.
Check counts, duplicates, attachments and exceptions.
Test roles, permissions and workflow behaviour.
Keep appropriate completion and exception evidence.
A secure platform cannot be assessed only by checking that authorised users can complete a workflow. Sensitive areas also need testing for situations such as:
EdiWay is designed around UK education workflows, including schools, families, SEND, safeguarding, Home Education, alternative provision, transition and emerging statutory processes. The platform can be designed to support applicable workflows and policy requirements. That does not mean EdiWay should claim:
EdiWay should not automatically determine:
Who is acting?
In which authorised context are they working?
Why do they have access to this learner or workflow?
What are they trying to do?
Does the information need stronger controls?
Apply the relevant permissions and restrictions.
Keep clear where information came from.
Retain appropriate audit and workflow evidence.
Ensure consequential decisions remain with the responsible person.
Change or end access when responsibility changes.Let college become the next stage – not a reset.
No.
EdiWay is designed so access can depend on role, organisation, learner relationship, case, purpose, sensitivity and other restrictions.
No.
A job title alone should not determine access to every learner or information area.
Sensitive actions are designed to fail closed rather than infer access.
No.
Family access remains dependent on the relationship, information type, permissions and applicable workflow.
No.
Professional access is designed to remain learner-specific and purpose-limited.
No.
Organisation membership does not automatically create learner-level access.
The platform is designed to preserve source and provenance so school, family, learner, professional and imported information can remain distinguishable.
No.
AI should operate within the same underlying access and purpose boundaries as the authorised user.
No.
Consequential professional and statutory decisions remain human decisions.
No.
Safeguarding information is excluded from broad AI retrieval by default.
No.
EdiWay can support governed workflows and evidence, but organisational compliance depends on law, policy, configuration, implementation and human practice.
EdiWay should not claim DfE or Ofsted endorsement unless a specific formal approval exists and can be evidenced.
The platform foundation is designed to record material actions, access, denials and lifecycle changes.
No.
Some capabilities may be supported, controlled, configuration-dependent, in assurance or part of a later product stage.
Explore platform access, security, audit and operational data controls.
Understand how relationships, purpose and information scope govern sharing.
See how EdiWay keeps AI permission-aware and human-reviewed.
Understand why safeguarding information requires separate, stronger controls.
Read how privacy and organisational data responsibilities fit around the platform.
Understand retention, account lifecycle and information rights.
See how EdiWay approaches migration, deployment and capability assurance.