Security & Compliance

Access Control Policy

How Skoolfly provisions, manages and revokes access to its platform and systems.

1. Policy Statement

Skoolfly controls access to its platform and systems so that users can only access information they need to perform their role. This policy defines how accounts and permissions are provisioned, reviewed and revoked.

2. Purpose

The purpose of this policy is to prevent unauthorised access, reduce the risk of insider misuse, and ensure that access follows the principles of least privilege and need to know.

3. Scope

This policy applies to all access to Skoolfly systems, including employee and contractor accounts, school and user accounts, service accounts, integrations, remote access and administrative accounts.

4. Access Control Principles

Least privilege: users receive the minimum level of access needed to do their job.

Need to know: access to sensitive data is granted only where there is a legitimate reason.

Separation of duties: conflicting responsibilities are not combined in a single user where this could create risk.

Accountability: access actions are attributable to an identifiable user.

Default deny: access is denied by default and granted explicitly.

5. User Account Lifecycle

Accounts follow a defined lifecycle from request to termination.

Provisioning: accounts are created through an approved request, with appropriate role assigned.

Activation: access becomes effective only after verification of identity and adequate training where needed.

Use: access is used only for authorised purposes.

Change: role changes trigger a review and update of entitlements.

Revocation: access is removed promptly upon offboarding or where no longer required.

6. Roles, Permissions and Least Privilege

Access is organised around roles and permission sets (for example, School Owner, Administrator, Teacher, Student, Parent). Roles map to the minimum permissions required for the relevant function.

Privileges such as user management, data export, financial configuration and system administration are restricted to appropriately senior or technical roles and are subject to additional oversight.

7. Authentication

All accounts must be protected by credentials that meet the requirements of the Password Policy. Privileged and administrative accounts must use multi-factor authentication, and MFA is strongly encouraged for all users.

8. Privileged Access Management

Admin and infrastructure access is limited to a small set of named individuals.

Privileged actions are logged and reviewed.

Credentials for privileged accounts are managed securely and rotated.

Where feasible, privileged access is elevated only for the duration of a task rather than standing.

9. Access Reviews

Access rights are reviewed periodically to confirm they remain necessary and appropriate.

Reviews check that separated or departing personnel no longer retain access.

Findings from reviews are remediated within a reasonable period, with higher-risk items prioritised.

10. Remote Access

Remote access to Skoolfly systems is permitted where necessary and is subject to the same authentication, logging and least-privilege requirements. Personnel accessing systems remotely are expected to use approved and secured devices and connections.

11. Termination and Transfer

Upon termination of employment or contract, access is revoked promptly in accordance with the Employee Security Policy.

On role transfer, entitlements are adjusted to the new role rather than carried over.

Terminated users' credentials are disabled or rotated, and their access audited as appropriate.

12. Monitoring and Logging

Access and authentication events may be logged and monitored to detect misuse, anomalies and security incidents. Logs are protected from tampering and retained in accordance with the Data Retention Policy.

13. Compliance and Enforcement

Non-compliance may result in corrective action, including suspension of access, disciplinary measures or termination of contractual arrangements.

14. Review

This policy is reviewed at least annually or when significant changes to roles, systems or access practices occur.