hello@ediway.co.uk

hello@ediway.co.uk

PERMISSIONS, CONSENT AND INFORMATION SHARING

Share What Is Needed.With the People Who Are Authorised to See It.

A connected learner journey can involve teachers, SENCOs, safeguarding leads, parents and carers, learners, school leaders and authorised professionals.

They should not all see the same information.

EdiWay is designed around permission-aware, role-scoped and relationship-based access so information can be made available for a defined purpose without opening the learner's complete record.

PERMISSION-AWARE BY DESIGN

Access Should Follow Responsibility.
Not Just a User Account.

Signing into EdiWay does not mean receiving unrestricted access to the platform. Access can depend on several connected factors.

Organisation

Which school or organisation is the person acting for?

Role

What responsibility does that person hold?

Learner Relationship

Why should they have access to this particular learner?

Information Domain

Do they require attendance, assessment, SEND, medical, safeguarding or another type of information?

Action

Can they view, contribute, update, approve or share?

Time

Is the relationship still current?

Additional Restrictions

Does the information require more specific permission?

The result is a more precise question than: “Does this user have access?”

EdiWay can instead consider: “Does this person have permission to perform this action, for this learner, on this information, for this purpose, now?”

ROLES AND PERMISSIONS

Start With the Role.Then Narrow the Access.

Different roles require different views of the same learner journey.

Teachers

Access information needed for their current teaching responsibilities.

Teaching Assistants

See appropriate information for the learners they support.

SENCOs

Access relevant SEND workflows and authorised learner-support information.

Safeguarding Leads

Access restricted safeguarding records according to safeguarding responsibility.

Pastoral Staff

Work with appropriate pastoral and wellbeing information.

School Leaders

Receive suitable operational and leadership oversight.

HR Staff

Access workforce information without gaining learner-record authority unnecessarily.

Governors

See approved governance information rather than unrestricted operational records.

Parents and Carers

Access appropriate information through their relationship with the learner.

Learners

Use age-appropriate learner experiences.

Authorised Professionals

Receive specifically scoped access through an approved professional relationship. A role provides a starting point. It should not automatically unlock every record within that role’s wider domain.

GRANULAR ACCESS

Sometimes the Right Permission
Is Smaller Than the Whole Record.

Sensitive information may require more precise controls than simple module-level access.

For example, a teacher may need to know:

That does not mean the teacher needs:

EdiWay’s permission model is designed to support more targeted access to the information required for the person’s responsibility.

RELATIONSHIPS MATTER

Who Someone IsIs Only Part of the Question.

Access can also depend on the person's relationship to the learner.

Parent or Carer

Is this person currently linked to this learner?

Teacher

Does the teacher currently teach the learner?

Support Staff

Is the learner within their assigned responsibility?

Professional

Has an authorised learner-specific relationship been established?

Provider

Is the organisation currently involved in the learner’s provision?

Governor

Does the governance role require access to this information?

Temporary User

Is the approved access period still active? This helps prevent a common problem with broad role-based systems: A person may hold the right job title but still have no reason to access this particular learner.

FAMILY RELATIONSHIPS

One Learner.Different Family Permissions.

Family relationships are not always identical. EdiWay can distinguish appropriate parent and carer relationships around the learner. Depending on the configured workflow, this can affect areas such as:

Learner Information

What information is available through the family experience?

Communication

Which communications should the person receive?

Forms

Can they complete a particular school form?

Consent

Are they authorised within the relevant consent workflow?

SEND Information

What support information can appropriately be shared?

Trips and Activities

Can the person provide the relevant permission where supported?

Evidence

Can they contribute information about the learner?

Professional Collaboration

Can they participate in an appropriate multi-agency workflow? A parent or carer account does not automatically mean unrestricted access to every record held about the learner.

CONSENT AND PERMISSION

Record the Decision.Keep Its Context Clear.

Schools use consent and permission workflows in many different situations. EdiWay can maintain appropriate decisions where consent or permission is part of the configured process.

Person

Who made the decision?

Learner Relationship

What is their relationship to the learner?

Request

What exactly are they being asked to agree to?

Decision

Was permission granted, declined or withdrawn?

Date

When was the decision made?

Context

Which activity or information-sharing relationship does it relate to?

History

Preserve appropriate previous decisions.

Current Position

Make the latest applicable decision clear. The platform should not treat every use of learner data as dependent on consent. Schools may process or share information under different lawful or statutory circumstances.

EdiWay can record the relevant workflow context, but the responsible organisation remains accountable for establishing the appropriate legal basis and information-sharing decision.

CONSENT IS NOT THE SAME AS ACCESS

Permission to Do One ThingDoes Not Open the Whole Record.

A parent or carer might give permission for a particular activity. That should not automatically create wider data access.

Trip Permission

Relates to the specified trip or activity.

Professional Involvement

Relates to an authorised professional relationship and purpose.

Evidence Sharing

Relates to the information approved for that sharing context.

Family Contribution

Allows appropriate participation without making family users school administrators.

Document Access

Allows access to a selected document without exposing unrelated records. Consent and system access should remain separate concepts.

PROFESSIONAL ACCESS

Connect the Professional.Define Why They Are There.

Educational psychologists, speech and language therapists, occupational therapists, social workers and other authorised professionals may need to work with learner information. EdiWay can support a governed professional relationship around:

Organisation

Which organisation does the professional represent?

Practitioner

Who is the individual professional?

Learner

Which learner does the relationship concern?

Purpose

Why is access required?

Information Scope

Which information is relevant?

Start

When does the relationship become active?

Expiry

When should access end?

Revocation

Can access be removed earlier?

Contributions

What information may the professional add?

History

What access relationship has existed over time? This is designed to avoid creating a permanent external account with broad school access.

TIME-LIMITED ACCESS

Access Should EndWhen the Relationship Ends.

Some people only require access for a particular period.

EdiWay can support time-aware access relationships.

Current Arrangement

When does access apply?

Expiry Date

When should it stop?

Current Status

Is the relationship still active?

Revocation

Has access been ended early?

History

What relationship previously existed?

New Request

Does a later purpose require a new access decision? An old professional relationship should not silently provide indefinite access to a learner.

PURPOSE-SCOPED INFORMATION SHARING

Start With Why.Then Decide What Is Needed.

Before information is shared, the intended purpose should be clear. A governed sharing workflow can consider:

Recipient

Who needs the information?

Organisation

Who are they acting for?

Learner

Which learner does the request concern?

Purpose

Why is the information required?

Authority or Lawful Context

What basis has the responsible organisation identified for the sharing activity?

Scope

Which information is necessary for that purpose?

Duration

How long should any ongoing access remain available?

Review

Has an authorised person checked what will be shared?

Record

Is the sharing decision appropriately preserved? This encourages information sharing to be deliberate rather than based on a broad assumption that an external professional should “see everything”.

DATA MINIMISATION

Share the Relevant Information.Not the Entire Learner Record.

Different purposes require different information. A recipient involved in one aspect of a learner's support may not require:

Where supported, EdiWay can help authorised users work with a selected information scope.

Record Selection

Choose the appropriate evidence.

Field-Level Context

Limit unnecessary detail where supported.

Sensitive Domains

Respect additional permission requirements.

Recipient View

Consider what the recipient actually needs.

Human Review

Check the disclosure before it is released.

Approved Snapshot

Preserve what was authorised where the workflow supports it. Minimum necessary information should remain a practical design principle throughout sharing workflows.

FAMILY OBJECTION AND DECLINE

Preserve the Response.Do Not Silently Override It.

Some collaborative workflows may involve family permission, objection or decline. Where supported, EdiWay can preserve that context alongside the relationship request.

Request

What collaboration or sharing was proposed?

Parent or Carer

Which authorised family relationship responded?

Response

Was the request accepted, declined or objected to?

Reason

Preserve an appropriate reason where the workflow supports it.

History

Keep previous decisions understandable.

Current State

Make the active relationship clear.

Review

Allow the responsible professional or organisation to consider the next lawful and appropriate step. Recording an objection does not mean EdiWay determines the legal consequence of that objection. That remains a matter for the responsible organisation and the circumstances of the case.

REVOCATION

Access Granted TodayDoes Not Have to Be Permanent.

Where an ongoing access relationship can be revoked, EdiWay can preserve the change.

Relationship

Identify the access being ended.

Person

Keep the affected user clear.

Learner

Maintain learner-specific scope.

Reason

Record appropriate revocation context.

Date

Preserve when the access changed.Check the disclosure before it is released.

Future Access

Prevent the old relationship from continuing to authorise access.

History

Retain an appropriate record that the relationship previously existed. Revocation should remove ongoing access without pretending that legitimate historical activity never occurred.

ACCESS HISTORY

Know Who Had Access.Preserve the Relationship Behind It.

Governed information sharing needs more than a list of current users. EdiWay can support access and relationship history around:

Professional Relationships

Who was authorised to work with the learner?

Relationship Lifecycle

When was access requested, activated, changed, expired or revoked?

Case Participation

Which authorised users participated?

Sharing Activity

Which governed sharing relationships existed?

Access Records

Maintain appropriate evidence of relevant access activity where supported.

Recipient Acknowledgement

For sensitive controlled sharing, preserve appropriate recipient activity where enabled.

Audit

Support later authorised review. Access history supports accountability. It does not mean every technical event should become visible to every platform user.

SENSITIVE INFORMATION

Some Records NeedStronger Boundaries.

Permissions should reflect the sensitivity and purpose of the information.

Safeguarding

Restricted safeguarding access should follow safeguarding responsibility.

Medical

Practical alerts can be separated from wider health detail.

SEND

Classroom strategies can be made available without exposing every assessment.

Wellbeing

Support information can remain distinct from confidential counselling records.

HR

Staff records should remain separated from ordinary school operational access.

Family Information

Sensitive family context should not become general staff information.

Professional Evidence

External contributions should retain their original source and visibility. Access to the learner’s general profile should not automatically provide access to every sensitive domain connected to that learner.

SAFEGUARDING INFORMATION SHARING

Share Carefully.Keep Safeguarding Authority Separate.

Safeguarding may require information to be shared in circumstances where ordinary consent workflows are not the governing mechanism. EdiWay should therefore keep safeguarding authority and family consent as separate concepts. Where controlled safeguarding sharing is enabled, the workflow can support context such as:

Verified Recipient

Identify the authorised professional or organisation.

Purpose

Record why information is being shared.

Lawful Context

Preserve the relevant basis recorded by the authorised user.

Explicit Scope

Define the information being disclosed.

Expiry

Limit ongoing recipient access where appropriate.

Revocation

Remove ongoing access when required.

Evidence Pack

Use specifically approved information.

Access Receipt

Preserve appropriate recipient activity where supported. The platform supports the record and access controls. It does not decide whether safeguarding information must or must not be shared. That judgement remains with authorised safeguarding professionals and applicable procedures.

SHARING EVIDENCE, NOT OPENING THE DATABASE

Give a Recipient What Was Approved.
Not a Window Into Everything Else.

Sometimes the appropriate sharing model is not ongoing platform access. A recipient may instead need a reviewed evidence package or controlled snapshot. Where supported, EdiWay can help authorised users define:

Recipient

Who is receiving the package?

Purpose

Why is it being prepared?

Evidence

What records have been selected?

Sensitive Detail

What information should be minimised?

Review

Who approved the disclosure?

Delivery

How was the approved information made available?

Audit

What governed activity should be preserved? This approach is particularly relevant to transition, inspection evidence, safeguarding and multi-agency collaboration.

SOURCE AND OWNERSHIP

Sharing InformationDoes Not Change Who Created It.

EdiWay's connected learner journey may contain information from several sources.

School-Owned Records

Remain school-authored information.

Parent and Carer Contributions

Remain family-origin evidence.

Learner Voice

Remains identifiable as the learner’s contribution.

Professional Reports

Retain the originating professional context.

Provider Information

Remains attributable to the provider.

Shared Evidence

Does not automatically change authorship because another user can view it.

Imported Information

Should retain appropriate source context where supported. Preserving provenance helps authorised users understand what they are actually reading.

TEMPORARY AND EXTERNAL ACCOUNTS

External AccessShould Not Behave Like Permanent Staff Access.

Where supported, EdiWay can distinguish external or temporary users from ordinary staff accounts.

External Professional

Access through the approved professional relationship.

Temporary User

Use a bounded access period.

Expiry

End access when the authorised period finishes.

Permissions

Restrict available actions.

Learner Scope

Limit access to the appropriate learner or case.

Information Scope

Expose only the required information.

Review

Reconsider access when the relationship changes. An external account should not become an informal route into the wider school platform.

CONSENT FOR TRIPS AND ACTIVITIES

Make the Decision Specific.Keep It Connected to the Activity.

Consent can also form part of ordinary school operational workflows. For supported trip and activity processes, the platform can preserve context such as:

Linked Learner

Ensure the decision relates to the correct child.

Family Relationship

Check that the responding user holds the relevant permission rights.

Activity

Keep the decision linked to the specific trip or request.

Grant

Record permission where provided.

Decline

Preserve a negative decision.

Withdrawal

Allow an earlier decision to be changed where the workflow permits it.

History

Keep an appropriate decision record. This type of operational permission is separate from broader information-sharing authority.

LEARNER PARTICIPATION

Include Learners Appropriately.
Do Not Treat Every Learner Account the Same.

Learners may participate in their own education record through age-appropriate workflows.

Learning

Access assignments, resources and feedback.

Voice

Contribute appropriate views.

Wellbeing

Use suitable learner check-ins.

SEND and Reviews

Participate in relevant support and annual-review activity.

Transition

Contribute priorities and aspirations.

Evidence

Access or contribute appropriate learning evidence. Learner participation should remain appropriate to the workflow, age, circumstances and configured permissions. A learner account does not automatically provide access to every professional record held about them through ordinary platform workflows.

PERMISSIONS AND AI

AI Should SeeNo More Than the User Is Allowed to See.

Governed AI should operate within the same permission boundaries as the person using it. Where enabled, this means AI assistance should consider:

User

Who is requesting assistance?

School

Which organisation are they acting within?

Learner

Are they authorised for this learner?

Domain

Can they access the relevant type of information?

Source

Is the underlying information permitted?

Purpose

Is the AI feature appropriate to the workflow?

Human Review

Does the resulting draft require authorised checking? AI should not become a route around permissions. A user who cannot access a safeguarding, medical, SEND or HR record should not gain that information by asking AI to summarise it.

PERMISSIONS ARE NOT THE SAME AS LEGAL AUTHORITY

Technology Can Enforce a Rule.
It Cannot Decide What the Rule Should Be.

EdiWay can help organisations implement access controls, sharing workflows, consent records and auditability.

Approved Snapshot

EdiWay supports those governed decisions. It does not replace them.

A GOVERNED INFORMATION-SHARING WORKFLOW

Identify. Authorise. Minimise. Review. End.

1. Identify the Person

Confirm the user, organisation and relationship.

2. Define the Purpose

Record why access or sharing is required.

3. Establish the Appropriate Context

Record the relevant consent, permission, authority or lawful context required by the configured workflow.

4. Limit the Scope

Make only the necessary learner and information domains available.

5. Set the Duration

Use expiry where access should be temporary.

6. Human Review

Check sensitive information before controlled disclosure.

7. Provide Access or Evidence

Allow the approved interaction.

8. Record Activity

Preserve suitable relationship, decision and access history.

9. Revoke or Expire

End access when it is no longer required.

10. Preserve the Audit Context

Keep appropriate historical evidence without continuing the old permission.

FREQUENTLY ASKED QUESTIONS

Permissions, Consent and Information Sharing

Does every EdiWay user see the same learner information?

No.

Access can depend on organisation, role, learner relationship, information type and the action the person is authorised to perform.

Does being a teacher provide access to every learner?

No.

Teacher access should remain connected to current teaching responsibility and the permissions configured for the school.

Can EdiWay restrict sensitive information?

Role-based and granular permission capabilities are represented within the platform.

Sensitive domains such as safeguarding, SEND and medical information can require more specific access.

Can parents and carers have different permissions?

Yes.

Family access can follow the person’s actual relationship and the rights configured for the relevant workflow.

Consent-management capabilities are represented for family, operational and information-sharing workflows.

The platform should not imply that consent is the legal basis for every school use of personal information.

Within EdiWay, permission describes what a user or relationship is technically allowed to access or do.

Consent is a recorded decision used in workflows where such a decision is relevant.

They are not interchangeable.

Can a parent decline or withdraw permission?

Supported workflows can preserve grant, decline, objection or withdrawal states where applicable.

The legal effect of a particular decision remains for the responsible organisation to determine.

Can external professionals access EdiWay?

Professional-account and relationship-based access capabilities are represented.

Access can be learner-specific, time-limited and revocable.

Can professional access expire automatically?

Access-expiry capabilities are represented within the user and relationship model.

Exact behaviour depends on the configured workflow.

Can professional access be revoked?

Yes, supported professional-sharing workflows can preserve revocation and relationship history.

Can EdiWay record why information is being shared?

Professional collaboration workflows can retain purpose and relevant consent or lawful-context information.

Can schools limit which information is shared?

The platform supports granular permissions and controlled sharing patterns.

Some advanced field-level minimisation and recipient-bound evidence workflows remain subject to runtime assurance.

Can someone have access to SEND but not safeguarding?

Yes.

Different information domains can require separate permissions.

Access to one should not imply access to another.

Can a teacher see a medical alert without seeing the full medical record?

The permission model is designed to allow practical information to be surfaced separately from more sensitive underlying records where supported.

Can a professional see the learner's complete record?

Not automatically.

Professional access should be limited to the authorised learner, purpose and information scope.

Does information sharing change who owns or authored the evidence?

No.

School, family, learner, provider and professional contributions should preserve their source.

Is there an access history?

Data-access, audit and professional relationship history capabilities are represented within the platform.

There are circumstances where safeguarding information-sharing decisions are not governed by ordinary parental-consent workflows.

EdiWay does not determine whether those circumstances apply.

That decision remains with appropriately authorised people following the organisation’s safeguarding and information-governance requirements.

Does EdiWay decide the lawful basis for sharing information?

No.

The platform can record relevant sharing context.

The responsible organisation remains accountable for determining the appropriate legal basis and decision.

Can AI bypass permissions?

No.

EdiWay AI should remain subject to the permissions of the authorised user and workflow.

Does EdiWay guarantee data-protection compliance?

No software automatically guarantees compliance.

EdiWay provides tools intended to support permission-aware access, information governance and auditable workflows.

The organisation remains responsible for its legal obligations, policies and operational practice.

CONNECTED WORKFLOWS

One Permission Model.Across the Connected Ecosystem.

Data Security and Governance

Understand the wider technical and organisational controls around EdiWay information.

Privacy and Data Protection

Understand how personal information, privacy rights and data-protection responsibilities are handled.

Professional Collaboration

Use learner-specific, purpose-scoped professional relationships.

Safeguarding Records and Chronology

Apply more restrictive permissions to safeguarding records and controlled disclosure.

Medical and Care Records

Surface practical care information without opening the complete health record.

AI Governance

Keep AI assistance within authorised data and human-review boundaries.

CURRENTLY IN LIVE TESTING

Help Shape Permission-Aware CollaborationAround Real Education Relationships.

EdiWay is undergoing active development and live testing.

Role-based and granular permissions, parent and learner accounts, professional and temporary access, access expiry, consent records, information-sharing permissions and data-access history are represented within the platform capability set.

Professional-collaboration foundations include verified organisation and practitioner relationships, learner-specific access, time-limited and revocable relationships, consent or lawful-context recording, parent objection state and professional-access history.

Some all-role denial testing, cross-school isolation, advanced field-level minimisation, external delivery, recipient acknowledgement, access reconciliation and sensitive-domain assurance remain subject to further runtime testing or controlled rollout.

EdiWay should therefore be positioned as providing a permission-aware framework for governed education access and information sharing—not as deciding the lawful basis, statutory authority or professional judgement behind every sharing decision.

Shopping Basket