hello@ediway.co.uk

hello@ediway.co.uk

TRUST AND GOVERNANCE

Connect the Journey.Control Who Can See and Do What.

EdiWay brings school, family, learner and authorised professional workflows into one connected education environment. That creates opportunities to reduce duplication, preserve learner continuity and keep important evidence closer to the process that created it—but connection should never mean unrestricted access.

EdiWay is designed around a governed operating model in which identity, organisation, relationship, purpose, information sensitivity and permissions help determine what each person can see and what actions they can take.

ONE CONNECTED SOURCE OF TRUTH

Connect the Record.Preserve the Boundaries.

EdiWay's platform architecture is built around shared learner, organisation, workflow, evidence and permission foundations. This allows authorised workflows to use the same underlying context instead of repeatedly copying information between disconnected systems. But a connected learner record does not mean a single visibility level.

One learner can have one connected journey without every user seeing the whole journey.

PERMISSION-AWARE BY DESIGN

A Job Title AloneShould Not Open the Record.

Ordinary role-based permissions are only part of EdiWay's access model. Access can also take account of:

Role

What is this person authorised to do?

Organisation

Which school, trust, provider or organisation are they acting for?

Learner Relationship

Why does this person have a relationship with this learner?

Case or Workflow

Are they involved in the specific work being accessed?

Purpose

Why is the information needed?

Sensitivity

Does the information require stronger protection?

Explicit Restrictions

Are there additional controls that should prevent access?

This creates a more purposeful model than assuming everyone with the same job title should automatically have the same access everywhere.

DENY FIRST

When EdiWay Cannot Establish Access,
It Should Not Guess.

Sensitive workflows are designed around a fail-closed principle. Where the platform cannot establish the required actor, organisation, learner, relationship or record scope for a sensitive action, permission should not be inferred. The action should be denied until the appropriate access conditions can be established. This principle is especially important where information relates to:

Uncertainty should not become permission.

RELATIONSHIPS MATTER

An Account Is Notthe Same Thing as Authority.

EdiWay distinguishes between having a platform account and having an authorised relationship with a learner. Different relationships can carry different rights.

For example:

Those relationships may also have:

This helps EdiWay reflect how education actually works: access comes from responsibility and purpose, not simply from knowing who the learner is.

SOURCE-AWARE RECORDS

Know Where Information Came From.
Don't Turn Every Contribution Into the Same Kind of Fact.

A connected system becomes less trustworthy when the origin of information disappears. EdiWay is designed to preserve provenance.

School Information

Remains attributable to the school or authorised staff source.

Learner Evidence

Remains attributable to the learner.

Family Contributions

Remain attributable to parents and carers.

Professional Reports

Retain professional authorship.

Imported Information

Should retain relevant source and historical context.

AI-Assisted Drafts

Source matters because meaning depends on where information came from.

EVIDENCE WITH CONTEXT

Don't Just Store a Document.Preserve Why It Exists.

EdiWay's evidence model is designed to connect evidence back to the process that produced it. Where appropriate, an item can remain associated with:

This helps authorised users understand more than the existence of a file. They can understand:

Better governance depends on evidence remaining meaningful – not becoming another uncontrolled document archive.

HUMAN ACCOUNTABILITY

Automate Administration.Don't Automate Responsibility.

EdiWay is designed to help people organise information, coordinate workflows, prepare evidence, surface actions and reduce repetitive administration. It is not designed to remove human accountability from consequential education decisions. Depending on the workflow, responsibility may remain with:

The platform may help structure the evidence. The responsible person remains accountable for the conclusion.

SENSITIVE INFORMATION

One Learner.Different Levels of Protection.

Some information requires stronger access boundaries than ordinary educational records. EdiWay distinguishes sensitive domains rather than treating every learner record as equally visible.

Safeguarding

Restricted to appropriately authorised safeguarding workflows and roles.

Medical and Care Information

Purpose-limited and separately permissioned.

SEND and Support

Available according to relevant role, relationship and workflow.

Learner Voice

Can require controlled visibility depending on sensitivity and context.

Professional Information

Limited according to the authorised relationship and purpose.

Family Information

Not automatically available to every person working with the learner.

A connected platform should reduce fragmentation without flattening important confidentiality boundaries.

INFORMATION SHARING

Share for a Reason.Keep the Disclosure Accountable.

Schools and families sometimes need to share information with another setting, provider or authorised professional. EdiWay's governance model is designed around controlled sharing rather than unrestricted record access. Important sharing decisions can consider:

Recipient

Who is receiving the information?

Learner

Who does it concern?

Purpose

Why is it being shared?

Scope

What information is actually needed?

Authority

What permission or lawful basis supports the disclosure where applicable?

Duration

Is access temporary or continuing?

Revocation

Can the relationship or access be ended?

Evidence

Can the disclosure itself be traced?

This supports collaboration while keeping the difference between sharing selected information and opening the learner record clear.

TRANSITION WITHOUT UNRESTRICTED TRANSFER

Let Useful Context Travel.Don't Treat Export as Permanent Permission.

When a learner changes education pathway, selected information may need to move with them. EdiWay's Transition Pack model is designed around a defined recipient and purpose rather than treating an exported record as unrestricted permission to reuse everything indefinitely. Depending on the workflow, governance can consider:

A learner can therefore maintain continuity without every future organisation inheriting unrestricted access to the entire historical record.

AUDITABILITY

Important ActionsShould Leave Evidence.

Governance is stronger when material actions can be traced. EdiWay's shared platform foundations are designed to support audit and security events around areas such as:

Audit information helps answer important questions:

Audit does not replace good policy or professional accountability. It helps make those responsibilities more visible.

GOVERNED AI

AI Inside the Rules.Not Outside Them.

EdiWay AI is designed as an assistance layer within the same permission and learner boundaries as the wider platform. Where enabled, AI may help authorised users:

But AI should only work with information the user is permitted to use for the relevant purpose. Sensitive data does not become available simply because an AI feature is being used. Consequential AI output remains subject to human review.

And EdiWay AI must not independently:

AI can assist the work. It does not inherit the professional’s authority.

SAFEGUARDING AND AI

Sensitive Records Needa Stronger Boundary.

Safeguarding information should not be treated like ordinary platform content.

EdiWay's architecture deliberately excludes safeguarding records from broad AI search or retrieval by default.

Any AI capability involving safeguarding information would require a separately governed, purpose-specific workflow with the appropriate permissions and assurance.

This boundary matters because convenience should never silently widen access to highly sensitive records.

PRIVACY AND DATA PROTECTION

Governance Is MoreThan a Privacy Notice.

Schools and other organisations using education technology have their own data-protection responsibilities. EdiWay is designed to support those responsibilities through platform controls around areas such as:

However, software alone does not make an organisation compliant. Schools and other responsible organisations still need appropriate policies, lawful bases, notices, staff practice, retention decisions and governance processes.

RETENTION AND SUBJECT RIGHTS

Keep Informationfor the Right Reasons and the Right Period.

Different types of education information can have different retention requirements. EdiWay should therefore not treat one retention period as appropriate for every record. Governance can depend on:

The wider EdiWay learner-continuity model does not remove an organisation’s own responsibility to apply appropriate retention rules.

ACCESSIBILITY

Trust IncludesBeing Able to Use the Platform.

A platform can be secure and still fail users if people cannot access or understand it. Accessibility therefore forms part of EdiWay's wider assurance approach. That includes considering how different users interact with:

Accessibility assurance is an ongoing product responsibility rather than a one-time design claim.

ORGANISATIONS, TRUSTS AND SCHOOL GROUPS

Wider Oversight
Should Not Mean Wider Learner Access.

EdiWay's organisation model is designed to represent relationships between schools, trusts, local authorities, providers and shared services.

Those organisational relationships can support delegated responsibilities and appropriate oversight.

But being part of the same trust or organisation group should not automatically grant access to individual learner information.

Cross-school reporting should continue to respect:

Organisational visibility is not a shortcut around learner-level permissions.

Detailed school governance, policy and improvement workflows remain within the dedicated School Governance area.

REPORTING FROM GOVERNED SOURCES

A Dashboard Is a View.Not a Second Source of Truth.

Reports, dashboards, documents and exports should reflect the authoritative records behind them. EdiWay's reporting model is designed so that outputs remain permission-scoped and connected to canonical source information.

A report should not silently become a new independent record simply because it has been exported to a spreadsheet or document.

The same principle applies to analytics. Where EdiWay combines measures across areas such as attendance, SEND, behaviour, workforce or operations, definitions and access boundaries still matter. Correlation should not be presented as an automatic conclusion.

PRODUCT ASSURANCE

A Feature ExistingIs Not the Same as Every Deployment Being Assured.

EdiWay distinguishes between different levels of product maturity.

Supported / Available

A capability that can be described within its documented boundaries.

Integrated Foundation

The core capability exists, but deployment, migration, role, provider, accessibility, legal or other assurance work may still be required.

Controlled / Policy-Dependent

A workflow is deliberately unavailable until the required configuration, permission, entitlement or policy is active.

Future / Not Claimed

A direction or capability that should not yet be marketed as available.

This distinction helps keep public product claims aligned with actual product assurance.

IMPLEMENTATION AND MIGRATION

Trust BeginsBefore the First User Logs In.

Moving education data between systems requires more than importing a spreadsheet. EdiWay's implementation approach is designed around stages such as:

Discover

Understand source systems and responsible data owners.

Map

Identify where information belongs in the EdiWay model.

Classify

Recognise sensitive or high-risk records.

Test

Use staged or dry-run migration where appropriate.

Migrate

Move information through controlled processes.

Reconcile

Check counts, duplicates, attachments and exceptions.

Verify

Test roles, permissions and workflow behaviour.

Record

Keep appropriate completion and exception evidence.

Historic information should not silently become a current statutory, safeguarding or professional conclusion simply because it was imported.

SECURITY ASSURANCE

Test What Should Fail.Not Only What Should Work.

A secure platform cannot be assessed only by checking that authorised users can complete a workflow. Sensitive areas also need testing for situations such as:

EdiWay’s assurance approach recognises that preventing the wrong action is as important as enabling the right one. Detailed technical and operational controls belong on the Data Security and Governance page.

DESIGNED FOR UK EDUCATION

Understand the Context.Don't Turn Context Into an Endorsement Claim.

EdiWay is designed around UK education workflows, including schools, families, SEND, safeguarding, Home Education, alternative provision, transition and emerging statutory processes. The platform can be designed to support applicable workflows and policy requirements. That does not mean EdiWay should claim:

EdiWay supports governed education workflows.

Responsible organisations and authorised professionals remain responsible for the decisions that belong to them.

TRUST THROUGH CLEAR BOUNDARIES

Be Clear AboutWhat the Platform Does Not Decide.

EdiWay should not automatically determine:

The platform can structure workflows, preserve evidence, enforce permissions and help people prepare information.
Human decision-makers remain accountable.

A GOVERNED INFORMATION JOURNEY

Connect. Control. Evidence. Review.

Connect. Control. Evidence. Review.

Who is acting?

2. Establish the Organisation

In which authorised context are they working?

3. Resolve the Relationship

Why do they have access to this learner or workflow?

4. Check the Purpose

What are they trying to do?

5. Evaluate Sensitivity

Does the information need stronger controls?

6. Allow or Deny

Apply the relevant permissions and restrictions.

7. Preserve the Source

Keep clear where information came from.

8. Record Important Actions

Retain appropriate audit and workflow evidence.

9. Keep Humans Accountable

Ensure consequential decisions remain with the responsible person.

10. Review the Relationship

Change or end access when responsibility changes.Let college become the next stage – not a reset.

This is how a connected education platform can remain connected without becoming indiscriminate.

FREQUENTLY ASKED QUESTIONS

Trust and Governance

Does one connected learner record mean every user can see everything?

No.

EdiWay is designed so access can depend on role, organisation, learner relationship, case, purpose, sensitivity and other restrictions.

 

Is access controlled only by staff role?

No.

A job title alone should not determine access to every learner or information area.

What happens when EdiWay cannot confirm permission?

Sensitive actions are designed to fail closed rather than infer access.

Can parents and carers see all school information about their child?

No.

Family access remains dependent on the relationship, information type, permissions and applicable workflow.

Can an external professional see the whole learner record?

No.

Professional access is designed to remain learner-specific and purpose-limited.

Does being part of the same trust grant access to every learner?

No.

Organisation membership does not automatically create learner-level access.

Does EdiWay keep track of where information came from?

The platform is designed to preserve source and provenance so school, family, learner, professional and imported information can remain distinguishable.

Can EdiWay AI access information a user cannot normally see?

No.

AI should operate within the same underlying access and purpose boundaries as the authorised user.

Does AI make safeguarding or SEND decisions?

No.

Consequential professional and statutory decisions remain human decisions.

Are safeguarding records included in general AI searches?

No.

Safeguarding information is excluded from broad AI retrieval by default.

Does EdiWay guarantee that a school is legally compliant?

No.

EdiWay can support governed workflows and evidence, but organisational compliance depends on law, policy, configuration, implementation and human practice.

Is EdiWay DfE or Ofsted approved?

EdiWay should not claim DfE or Ofsted endorsement unless a specific formal approval exists and can be evidenced.

Does EdiWay preserve audit information?

The platform foundation is designed to record material actions, access, denials and lifecycle changes.

Are all announced EdiWay features necessarily available in every deployment?

No.

Some capabilities may be supported, controlled, configuration-dependent, in assurance or part of a later product stage.

EXPLORE TRUST AND GOVERNANCE

Go DeeperInto the Controls Behind the Platform.

Data Security and Governance

Explore platform access, security, audit and operational data controls.

Permissions, Consent and Information Sharing

Understand how relationships, purpose and information scope govern sharing.

AI Governance

See how EdiWay keeps AI permission-aware and human-reviewed.

Safeguarding Boundaries

Understand why safeguarding information requires separate, stronger controls.

Privacy and Data Protection

Read how privacy and organisational data responsibilities fit around the platform.

Data Retention and Subject Rights

Understand retention, account lifecycle and information rights.

Implementation, Migration and Product Assurance

See how EdiWay approaches migration, deployment and capability assurance.

TRUST AND GOVERNANCE

Build ConnectionWithout Losing Control.

Trust should not be an add-on to the platform.It should shape how the platform works.

Shopping Basket