Skip to content
School platform · Multi-tenant

One platform that runs a single school — or a whole group of them

A bilingual platform covering admissions, academics, finance, HR, transport and governance, which a single school can run on its own and a group can run across every branch from one place.

The same product at both ends of the market: one school switches on what it needs, a group adds branches without cloning anything, and five curricula run side by side in either.

Group console3 branches
Group
Branch ABritish
Main campusBritish
Branch BIB
Who owns which setting
Fee policyGroup-locked
Grading scaleBranch-owned
CurriculumPer grade level

A group adds branches without cloning anything, and decides who owns each setting.

Client
School operators, single-site and multi-branch
Industry
Education
Region
Oman
Year
2026
Languages
AR / EN, right to left
6parts of the school, from tenancy and admissions to governance
9roles, from super admin to librarian and accountant
4audiences, four products, each seeing only what belongs to it
3timetable conflicts prevented independently: teacher, room, section
2ways to sign off: a strict chain, or N-of-M voting
4package tiers, with per-module toggles for each school
The problem

School software breaks at the second branch.

It is usually built for one school and stretched to fit a group, or built for a group and far too heavy for a single site. Four things decide whether it fits both, and each one has to be designed in from the start.

Ownership

Every setting becomes a question of who owns it.

The moment an operator runs several branches, everything that was a single value, the fee policy, the curriculum, the grading scale, becomes a decision about who owns it. Build that in late and it never fits.

Curriculum

A branch does not run one curriculum.

British for the younger grades and IB for the older ones is an ordinary arrangement, and which curricula a branch offers varies branch to branch. Treat curriculum as a property of the school and that is impossible to express.

Language

Arabic is not a translation pass.

Layout direction, date handling and even a plain time range behave differently. A product that treats RTL as a stylesheet toggle breaks in ways nobody catches until a real user reports it.

Governance

Sign-off does not stop at school staff.

Fee waivers and policy exceptions need board members, group directors and per-school committees: people who are not employees and appear in no staff hierarchy.

Tenancy

Isolate tenants at the database, not the query.

Every row carries its tenant, and Postgres row-level security enforces it in the database rather than relying on every query being written correctly. A missed filter returns nothing instead of another school's data.

  • One hierarchy: group, branch and academic year, with isolation enforced by the database rather than by query discipline.
  • Nine roles, one permission layer: JWT with refresh tokens and permission middleware across super admin, group admin, branch admin, teacher, parent, student, staff, librarian and accountant.
  • A super admin console to create tenants, school groups and branches, with global search across the whole estate.
  • Packages, not forks: four tier presets with per-module, per-school toggles on top and a change log behind them.
Signed in · Branch A admin
Isolation enforced by
The query
select * from invoices  -- tenant filter forgotten
0 rowsRow-level security: nothing outside this tenant is visible, whatever the query says.

Sample rows. Try “Every query” with the filter missed, then switch back to the database.

Settings inheritance

Make ownership of a setting an explicit choice.

A generic lock-or-delegate framework lets a group either fix a setting for every branch or hand it down, while a single school simply owns all of them, with no group layer in the way.

Fee policy was the first consumer: fixed or percentage late fees, grace periods and an arrears ladder, owned at group level with an optional branch lock. Grading scales and approval chains now run on the same mechanism, and the framework has been proven live on both paths.

  • A group console for multi-campus consolidation and group-level settings, built on the same inheritance framework.
  • Branding per branch: logo and accent colour, or full white-label with a custom domain, automated SSL and platform branding hidden.
Group console · Settings inheritance
Fee policy
Late fees, grace periods, arrears ladder
Grading scale
Platform default per curriculum, or an override
Approval chain
How a request gets signed off

Lock a setting, then try changing it at a branch. Delegate it, and each branch sets its own.

Curriculum

Put curriculum where it actually lives.

A branch declares the curricula it offers, grade levels are created per curriculum, and sections inherit from their grade with a per-section override. Exams, grading scales and report cards resolve from the section, so a British section and an IB section in the same building are graded on their own terms.

BritishAmericanIBPakistani Federal BoardOman national
  • A curriculum-agnostic grading engine with platform defaults for all five, and a per-school override.
  • Exam sittings bundle subjects with per-subject maximum and passing marks, and the marks roster tells absent apart from a scored zero.
  • Report cards from weighted per-subject averages across a term, mapped through the school's scale, with GPA and IB points, per student or batched for a class.
Main campus · Classes, sections & curriculum
Curricula this branch offers
British
Grade 5
Grade 10
IB
Grade 5
Grade 10
Resolved from the section
IB Grade 10 · Section 10A
Curriculum
IBinherited from Grade 10
Exams
Sittings for this section, per-subject maximum and passing marks
Grading scale
IB platform default · per-school override available
Report card
Weighted per-subject averages, mapped through the IB scale, with IB points

Pick a section, add or drop a curriculum, or override one section. Grade and section names are samples.

AR / EN

Bilingual from the first screen, not bolted on after.

English and Arabic dictionaries ship in code with a database-backed override table, so any string, or a whole new language, changes without a redeploy.

Right-to-left is handled as layout, not translation: logical CSS properties throughout rather than left and right, and numeric ranges isolated by direction so a time range does not reverse itself in Arabic.

  • A translation console with locale tabs, an add-language flow, and a per-key editable table with default, customised and missing badges, plus revert.
  • A bilingual design system, RTL and LTR, light and dark, shared across web and mobile.
  • Notifications per language: a provider-agnostic email, SMS, WhatsApp and push adapter with per-language templates.
Timetable · Today
1
08:00 – 08:45
2
08:50 – 09:35
Direction-isolated08:00 – 08:45
Plain text08:00 – 08:45

Switch to right to left. Both ranges are real text, laid out by your browser.

Governance

Sign-off, inside the product instead of in email.

A generic approvals engine handles any request type, with either N-of-M voting or a strict sequential chain, accountant to principal to committee president to chairman, where each step unlocks only once the previous one signs and a rejection vetoes immediately.

  • A request-anything engine with three governance roles, and notifications when a request is created and when it is decided.
  • Nothing sits forever: auto-escalation for stale requests, and a needs-my-vote filter.
  • An audit log filterable by record, so an audit officer pulls the full history of a single invoice rather than scanning a feed.
Approvals · Needs my vote
Request
Fee waiver
  1. AccountantUnlocked: their turn
  2. PrincipalLocked until the step before signs
  3. Committee presidentLocked until the step before signs
  4. ChairmanLocked until the step before signs
Waiting on the accountant
Audit trail · this record

Request created. Voters notified.

Sign in order, or reject at any step. The 2-of-3 vote is a sample configuration.

Portals

Give every role its own product.

Four audiences, four products. Each sees only what belongs to them, checked on the server rather than hidden in the interface.

TTeacher

Lands on my classes, with attendance, exams and lesson plans pre-filtered to the sections they are actually assigned to.

PParent

One card per linked child, then enrolment, attendance, report cards and invoices, with an ownership check on every endpoint, verified with live negative tests.

SStudent

Timetable, homework, results and library access, on the web and in the mobile app.

AAdmin & operator

Admins see the school; the operator sees the group, with consolidated dashboards across every campus.

Around them: parent, teacher and admin messaging with admin oversight for safeguarding, announcements targeted by role, a month calendar with multi-day events, and teacher availability slots for in-person or virtual meetings.

The full scope

A school runs on more than a database.

The full scope, grouped by the part of the school it serves. Each school switches on only the modules its package includes.

Platform & tenancy

Admissions & student records

Teaching & assessment

Portals & communication

Finance & operations

Governance & analytics

In production

The details that decide whether it holds up on a real school day.

Admissions, open to the public

A no-login application flow with an opaque per-application token, a manually built tenant context and rate limiting. Entrance-test slots are row-locked, verified under a genuine two-request race for the last seat.

Offer letters as real PDFs

Generated without a headless-browser dependency to carry in production.

Today, in the branch's time

Per-branch timezones, so “today” resolves to the branch's calendar day and a school ahead of UTC never loses its own attendance.

Timetables that cannot clash

A weekly grid on the GCC school week. Teacher, room and section conflicts are each prevented independently, with an accurate error per axis rather than a parsed database error. Substitutions are date-specific and leave the recurring pattern intact.

Billing that survives a plan change

Plan changes append to a per-school history, so proration splits an invoice period across however many price changes fell inside it. Confirmed prices are frozen at contract time: a later rate-card edit never reprices an existing school.

One payment, several invoices

Invoices generated per structure and cycle, many-to-one allocation so one payment settles several overdue invoices, and late fees computed automatically.

Video that skips the servers

Uploaded browser-to-CDN, so files never touch the application servers, then reconciled by webhook-verified background jobs.

Access proved, not assumed

Server-side ownership checks on every parent-facing endpoint, verified with live negative tests rather than hidden in the interface. Library content a teacher creates is limited to the sections they teach.

How it's built

One codebase, three clients, and tenancy enforced below the code.

A monorepo sharing types and validation across an API, a web app and a mobile client, with tenancy enforced in the database and long-running work pushed to a queue.

Monorepo · shared TypeScript types & schema validation
WebNext.js web application
MobileReact Native mobile client
APINestJS APIJWT auth and permission middleware
DataPostgreSQLRow-level security policies per tenant
QueueRedis-backed job queueNotifications, webhooks and report generation
Containerised deployment, with build and typecheck on every push
NestJSNext.jsReact NativeTypeScriptPostgreSQLPrismaRow-level securityRedisBullMQZodTailwind CSSDocker

Services: Web Application Development · Mobile Application Development · Business Process Automation · ERP Services & Automation

Outcome

What changed.

47
Modules live
Across admissions, academics, finance, HR, operations and governance
5
Curricula supported
British, American, IB, Pakistani Federal Board and Oman national
AR / EN
Bilingual throughout
Full RTL, with any string overridable without a redeploy

A single school runs on it with no multi-branch overhead, and a group adds branches without cloning anything

British and IB grades coexist in the same branch, graded on their own scales

Fee policy is owned where the group wants it owned — locked centrally or delegated

Board and committee sign-off happens inside the product, with an audit trail per record

Arabic is a first-class interface, not a translated afterthought

Next

Related work.

Aufgaben Management — Task, project and deadline management for delivery teams

Aufgaben Management

Aufgaben ManagementEnterpriseGermany

Task, project and deadline management for delivery teams

Assignment, progress tracking and collaboration in one place, so teams know who owns what.

React NativeReactNode.js
Read case study
SCORA — Security assessments that end in proof, not a PDF
Flagship

SCORA

SCORAEnterpriseGlobal

Security assessments that end in proof, not a PDF

A security assessment and remediation platform: nine frameworks, every gap routed to an owner, evidence checked and read by AI, and an auditor-ready closure record — in English and Arabic.

Next.jsTypeScriptPostgreSQL
Read case studySee SCORA live
AI HR Assistant — Fifteen HR services, answered on WhatsApp, written back to Oracle EBS

AI HR Assistant

Saudi enterprise groupEnterpriseSaudi Arabia

Fifteen HR services, answered on WhatsApp, written back to Oracle EBS

A bilingual AI assistant that turns Oracle EBS HRMS into a conversation — leave, certificates, attendance, approvals — for around 10,000 employees, hosted inside the Kingdom.

Oracle EBS HRMSWhatsApp Business APILLMs
Read case study