A connected learner journey can involve teachers, SENCOs, safeguarding leads, parents and carers, learners, school leaders and authorised professionals.
They should not all see the same information.
EdiWay is designed around permission-aware, role-scoped and relationship-based access so information can be made available for a defined purpose without opening the learner's complete record.
Signing into EdiWay does not mean receiving unrestricted access to the platform. Access can depend on several connected factors.
Which school or organisation is the person acting for?
What responsibility does that person hold?
Why should they have access to this particular learner?
Do they require attendance, assessment, SEND, medical, safeguarding or another type of information?
Can they view, contribute, update, approve or share?
Is the relationship still current?
Does the information require more specific permission?
The result is a more precise question than: “Does this user have access?”
EdiWay can instead consider: “Does this person have permission to perform this action, for this learner, on this information, for this purpose, now?”
Different roles require different views of the same learner journey.
Access information needed for their current teaching responsibilities.
See appropriate information for the learners they support.
Access relevant SEND workflows and authorised learner-support information.
Access restricted safeguarding records according to safeguarding responsibility.
Work with appropriate pastoral and wellbeing information.
Receive suitable operational and leadership oversight.
Access workforce information without gaining learner-record authority unnecessarily.
See approved governance information rather than unrestricted operational records.
Access appropriate information through their relationship with the learner.
Use age-appropriate learner experiences.
Receive specifically scoped access through an approved professional relationship. A role provides a starting point. It should not automatically unlock every record within that role’s wider domain.
Sensitive information may require more precise controls than simple module-level access.
EdiWay’s permission model is designed to support more targeted access to the information required for the person’s responsibility.
Access can also depend on the person's relationship to the learner.
Is this person currently linked to this learner?
Does the teacher currently teach the learner?
Is the learner within their assigned responsibility?
Has an authorised learner-specific relationship been established?
Is the organisation currently involved in the learner’s provision?
Does the governance role require access to this information?
Is the approved access period still active? This helps prevent a common problem with broad role-based systems: A person may hold the right job title but still have no reason to access this particular learner.
Family relationships are not always identical. EdiWay can distinguish appropriate parent and carer relationships around the learner. Depending on the configured workflow, this can affect areas such as:
What information is available through the family experience?
Which communications should the person receive?
Can they complete a particular school form?
Are they authorised within the relevant consent workflow?
What support information can appropriately be shared?
Can the person provide the relevant permission where supported?
Can they contribute information about the learner?
Can they participate in an appropriate multi-agency workflow? A parent or carer account does not automatically mean unrestricted access to every record held about the learner.
Schools use consent and permission workflows in many different situations. EdiWay can maintain appropriate decisions where consent or permission is part of the configured process.
Who made the decision?
What is their relationship to the learner?
What exactly are they being asked to agree to?
Was permission granted, declined or withdrawn?
When was the decision made?
Which activity or information-sharing relationship does it relate to?
Preserve appropriate previous decisions.
Make the latest applicable decision clear. The platform should not treat every use of learner data as dependent on consent. Schools may process or share information under different lawful or statutory circumstances.
EdiWay can record the relevant workflow context, but the responsible organisation remains accountable for establishing the appropriate legal basis and information-sharing decision.
A parent or carer might give permission for a particular activity. That should not automatically create wider data access.
Relates to the specified trip or activity.
Relates to an authorised professional relationship and purpose.
Relates to the information approved for that sharing context.
Allows appropriate participation without making family users school administrators.
Allows access to a selected document without exposing unrelated records. Consent and system access should remain separate concepts.
Educational psychologists, speech and language therapists, occupational therapists, social workers and other authorised professionals may need to work with learner information. EdiWay can support a governed professional relationship around:
Which organisation does the professional represent?
Who is the individual professional?
Which learner does the relationship concern?
Why is access required?
Which information is relevant?
When does the relationship become active?
When should access end?
Can access be removed earlier?
What information may the professional add?
What access relationship has existed over time? This is designed to avoid creating a permanent external account with broad school access.
Some people only require access for a particular period.
EdiWay can support time-aware access relationships.
When does access apply?
When should it stop?
Is the relationship still active?
Has access been ended early?
What relationship previously existed?
Does a later purpose require a new access decision? An old professional relationship should not silently provide indefinite access to a learner.
Before information is shared, the intended purpose should be clear. A governed sharing workflow can consider:
Who needs the information?
Who are they acting for?
Which learner does the request concern?
Why is the information required?
What basis has the responsible organisation identified for the sharing activity?
Which information is necessary for that purpose?
How long should any ongoing access remain available?
Has an authorised person checked what will be shared?
Is the sharing decision appropriately preserved? This encourages information sharing to be deliberate rather than based on a broad assumption that an external professional should “see everything”.
Different purposes require different information. A recipient involved in one aspect of a learner's support may not require:
Where supported, EdiWay can help authorised users work with a selected information scope.
Choose the appropriate evidence.
Limit unnecessary detail where supported.
Respect additional permission requirements.
Consider what the recipient actually needs.
Check the disclosure before it is released.
Preserve what was authorised where the workflow supports it. Minimum necessary information should remain a practical design principle throughout sharing workflows.
Some collaborative workflows may involve family permission, objection or decline. Where supported, EdiWay can preserve that context alongside the relationship request.
What collaboration or sharing was proposed?
Which authorised family relationship responded?
Was the request accepted, declined or objected to?
Preserve an appropriate reason where the workflow supports it.
Keep previous decisions understandable.
Make the active relationship clear.
Allow the responsible professional or organisation to consider the next lawful and appropriate step. Recording an objection does not mean EdiWay determines the legal consequence of that objection. That remains a matter for the responsible organisation and the circumstances of the case.
Where an ongoing access relationship can be revoked, EdiWay can preserve the change.
Identify the access being ended.
Keep the affected user clear.
Maintain learner-specific scope.
Record appropriate revocation context.
Preserve when the access changed.Check the disclosure before it is released.
Prevent the old relationship from continuing to authorise access.
Retain an appropriate record that the relationship previously existed. Revocation should remove ongoing access without pretending that legitimate historical activity never occurred.
Governed information sharing needs more than a list of current users. EdiWay can support access and relationship history around:
Who was authorised to work with the learner?
When was access requested, activated, changed, expired or revoked?
Which authorised users participated?
Which governed sharing relationships existed?
Maintain appropriate evidence of relevant access activity where supported.
For sensitive controlled sharing, preserve appropriate recipient activity where enabled.
Support later authorised review. Access history supports accountability. It does not mean every technical event should become visible to every platform user.
Permissions should reflect the sensitivity and purpose of the information.
Restricted safeguarding access should follow safeguarding responsibility.
Practical alerts can be separated from wider health detail.
Classroom strategies can be made available without exposing every assessment.
Support information can remain distinct from confidential counselling records.
Staff records should remain separated from ordinary school operational access.
Sensitive family context should not become general staff information.
External contributions should retain their original source and visibility. Access to the learner’s general profile should not automatically provide access to every sensitive domain connected to that learner.
Safeguarding may require information to be shared in circumstances where ordinary consent workflows are not the governing mechanism. EdiWay should therefore keep safeguarding authority and family consent as separate concepts. Where controlled safeguarding sharing is enabled, the workflow can support context such as:
Identify the authorised professional or organisation.
Record why information is being shared.
Preserve the relevant basis recorded by the authorised user.
Define the information being disclosed.
Limit ongoing recipient access where appropriate.
Remove ongoing access when required.
Use specifically approved information.
Preserve appropriate recipient activity where supported. The platform supports the record and access controls. It does not decide whether safeguarding information must or must not be shared. That judgement remains with authorised safeguarding professionals and applicable procedures.
Sometimes the appropriate sharing model is not ongoing platform access. A recipient may instead need a reviewed evidence package or controlled snapshot. Where supported, EdiWay can help authorised users define:
Who is receiving the package?
Why is it being prepared?
What records have been selected?
What information should be minimised?
Who approved the disclosure?
How was the approved information made available?
What governed activity should be preserved? This approach is particularly relevant to transition, inspection evidence, safeguarding and multi-agency collaboration.
EdiWay's connected learner journey may contain information from several sources.
Remain school-authored information.
Remain family-origin evidence.
Remains identifiable as the learner’s contribution.
Retain the originating professional context.
Remains attributable to the provider.
Does not automatically change authorship because another user can view it.
Should retain appropriate source context where supported. Preserving provenance helps authorised users understand what they are actually reading.
Where supported, EdiWay can distinguish external or temporary users from ordinary staff accounts.
Access through the approved professional relationship.
Use a bounded access period.
End access when the authorised period finishes.
Restrict available actions.
Limit access to the appropriate learner or case.
Expose only the required information.
Reconsider access when the relationship changes. An external account should not become an informal route into the wider school platform.
Consent can also form part of ordinary school operational workflows. For supported trip and activity processes, the platform can preserve context such as:
Ensure the decision relates to the correct child.
Check that the responding user holds the relevant permission rights.
Keep the decision linked to the specific trip or request.
Record permission where provided.
Preserve a negative decision.
Allow an earlier decision to be changed where the workflow permits it.
Keep an appropriate decision record. This type of operational permission is separate from broader information-sharing authority.
Learners may participate in their own education record through age-appropriate workflows.
Access assignments, resources and feedback.
Contribute appropriate views.
Use suitable learner check-ins.
Participate in relevant support and annual-review activity.
Contribute priorities and aspirations.
Access or contribute appropriate learning evidence. Learner participation should remain appropriate to the workflow, age, circumstances and configured permissions. A learner account does not automatically provide access to every professional record held about them through ordinary platform workflows.
Governed AI should operate within the same permission boundaries as the person using it. Where enabled, this means AI assistance should consider:
Who is requesting assistance?
Which organisation are they acting within?
Are they authorised for this learner?
Can they access the relevant type of information?
Is the underlying information permitted?
Is the AI feature appropriate to the workflow?
Does the resulting draft require authorised checking? AI should not become a route around permissions. A user who cannot access a safeguarding, medical, SEND or HR record should not gain that information by asking AI to summarise it.
EdiWay can help organisations implement access controls, sharing workflows, consent records and auditability.
EdiWay supports those governed decisions. It does not replace them.
Confirm the user, organisation and relationship.
Record why access or sharing is required.
Record the relevant consent, permission, authority or lawful context required by the configured workflow.
Make only the necessary learner and information domains available.
Use expiry where access should be temporary.
Check sensitive information before controlled disclosure.
Allow the approved interaction.
Preserve suitable relationship, decision and access history.
End access when it is no longer required.
Keep appropriate historical evidence without continuing the old permission.
No.
Access can depend on organisation, role, learner relationship, information type and the action the person is authorised to perform.
No.
Teacher access should remain connected to current teaching responsibility and the permissions configured for the school.
Role-based and granular permission capabilities are represented within the platform.
Sensitive domains such as safeguarding, SEND and medical information can require more specific access.
Yes.
Family access can follow the person’s actual relationship and the rights configured for the relevant workflow.
Consent-management capabilities are represented for family, operational and information-sharing workflows.
The platform should not imply that consent is the legal basis for every school use of personal information.
Within EdiWay, permission describes what a user or relationship is technically allowed to access or do.
Consent is a recorded decision used in workflows where such a decision is relevant.
They are not interchangeable.
Supported workflows can preserve grant, decline, objection or withdrawal states where applicable.
The legal effect of a particular decision remains for the responsible organisation to determine.
Professional-account and relationship-based access capabilities are represented.
Access can be learner-specific, time-limited and revocable.
Access-expiry capabilities are represented within the user and relationship model.
Exact behaviour depends on the configured workflow.
Yes, supported professional-sharing workflows can preserve revocation and relationship history.
Professional collaboration workflows can retain purpose and relevant consent or lawful-context information.
The platform supports granular permissions and controlled sharing patterns.
Some advanced field-level minimisation and recipient-bound evidence workflows remain subject to runtime assurance.
Yes.
Different information domains can require separate permissions.
Access to one should not imply access to another.
The permission model is designed to allow practical information to be surfaced separately from more sensitive underlying records where supported.
Not automatically.
Professional access should be limited to the authorised learner, purpose and information scope.
No.
School, family, learner, provider and professional contributions should preserve their source.
Data-access, audit and professional relationship history capabilities are represented within the platform.
There are circumstances where safeguarding information-sharing decisions are not governed by ordinary parental-consent workflows.
EdiWay does not determine whether those circumstances apply.
That decision remains with appropriately authorised people following the organisation’s safeguarding and information-governance requirements.
No.
The platform can record relevant sharing context.
The responsible organisation remains accountable for determining the appropriate legal basis and decision.
No.
EdiWay AI should remain subject to the permissions of the authorised user and workflow.
No software automatically guarantees compliance.
EdiWay provides tools intended to support permission-aware access, information governance and auditable workflows.
The organisation remains responsible for its legal obligations, policies and operational practice.
Understand the wider technical and organisational controls around EdiWay information.
Understand how personal information, privacy rights and data-protection responsibilities are handled.
Use learner-specific, purpose-scoped professional relationships.
Apply more restrictive permissions to safeguarding records and controlled disclosure.
Surface practical care information without opening the complete health record.
Keep AI assistance within authorised data and human-review boundaries.
EdiWay is undergoing active development and live testing.
Role-based and granular permissions, parent and learner accounts, professional and temporary access, access expiry, consent records, information-sharing permissions and data-access history are represented within the platform capability set.
Professional-collaboration foundations include verified organisation and practitioner relationships, learner-specific access, time-limited and revocable relationships, consent or lawful-context recording, parent objection state and professional-access history.
Some all-role denial testing, cross-school isolation, advanced field-level minimisation, external delivery, recipient acknowledgement, access reconciliation and sensitive-domain assurance remain subject to further runtime testing or controlled rollout.
EdiWay should therefore be positioned as providing a permission-aware framework for governed education access and information sharing—not as deciding the lawful basis, statutory authority or professional judgement behind every sharing decision.