User Roles & PermissionsAdmin
Creating and editing user roles, assigning permissions, and controlling access to each module.
AthenaStar uses a role-based access control system — each user is assigned exactly one role, and that role determines which modules and actions they can access. Admins can create custom roles to match their school's unique staffing structure.
1. Built-in Roles
AthenaStar ships with these standard roles:
- Admin — full access to everything
- Accountant — Finance, Payroll, Fees
- Teacher — own class results, attendance, timetable
- Head Teacher — all classes, results management, attendance
- HR Officer — staff HR, leave, appraisals
- Librarian — Library module
- Nurse — Infirmary module
- Secretary — Front Desk module
- Security — Visitor & Security module
- Parent — Parent Portal (read-only own children)
- Proprietor — read-only access to all modules (no edits)
2. Creating a Custom Role
- Go to Settings → Roles → New Role.
- Give the role a name (e.g. "Bursary Assistant").
- Tick the permissions this role needs (e.g. view_fees, manage_receipts but NOT delete_student).
- Save. The role is immediately available for assignment.
3. Assigning a Role
Go to Settings → User Accounts → Edit User. Change the Role dropdown to the desired role and save. The change takes effect on the user's next page load.
4. Per-User Permission Overrides
For fine-grained control, go to Settings → User Accounts → Edit Permissions for a specific user. You can grant or revoke individual permissions on top of their role's defaults — without changing the role itself.
5. Security Best Practice
- Give staff the minimum permissions needed for their job.
- Never share Admin accounts — give each person their own login.
- Review the Audit Log periodically to check for unexpected actions.
- Block departed staff accounts immediately from Settings → User Accounts.
Ready to get started with AthenaStar?
Apply for your school's private workspace — no sales call needed. Our team reviews every application and has you set up fast.