Isolated school tenants
Each school keeps its own sessions, classes, students, staff, finance settings, templates, and branding within its data boundary.
Checking permissions...
Designed around boundaries, not bolted on later
CampusPilot combines isolated school tenants, role-based permissions, and teacher assignment scopes so each protected operation retains the right operational context.
Permission boundaries
Security across the operation
Each school keeps its own sessions, classes, students, staff, finance settings, templates, and branding within its data boundary.
Administrators, managers, accountants, exam coordinators, and teachers receive access around their responsibilities.
Protected academic work can be limited to the classes and sections assigned to each teacher.
Student sessions are recognized independently and portal requests are restricted to the authenticated student’s own information.
Session authentication serves the application while API keys support authorized connected tools and services.
The application API and native MCP connection apply the same authorization boundaries to protected operations.
Users associated with more than one school can choose the campus they need, while local records, settings, and permissions remain separate.
Its operating system should be ready for it too.
Book a CampusPilot demo