Security architecture

Protected education workflows with accountable access

RLS combines institution context, membership and role checks, protected actions, auditable events, and governed file access. Security depends on the complete deployed configuration and the institution's own access-management practices.

Institution-scoped access

Protected workflows resolve institution context and scope reads and writes to the authorised institution.

Role-aware authorization

Server actions and operational workspaces apply membership and role checks before protected information or actions are made available.

Authenticated sessions

RLS uses authenticated session context to resolve the user, institution, and role used by protected platform workflows.

Audit and operational history

Important actions can create audit, operational-event, actor, timestamp, and chain-of-custody records for accountable review.

Protected file access

FileVault workflows use institution-aware storage paths and signed access mechanisms rather than exposing unrestricted storage objects.

Governed execution

Sensitive operational workflows use explicit permissions, reasons, previews, review states, and persisted outcomes where the domain requires them.

RLS platform responsibilities

  • Maintain protected request and server-action boundaries
  • Apply institution and role context to supported workflows
  • Record accountable operational events where implemented
  • Protect supported file and evidence access paths
  • Provide operational health and security visibility

Institution responsibilities

  • Maintain accurate user, role, and membership records
  • Review access when staff responsibilities change
  • Configure modules and integrations appropriately
  • Follow local policy and legal requirements
  • Report suspected security or privacy concerns promptly
Clear public claims

Security controls are described without claiming an external certification.

This page describes safeguards visible in the RLS implementation. It does not claim a formal external certification, legal-compliance determination, or absolute protection against every threat. Those assessments require the final deployment, configuration, operating environment, and independent review.