Consent ledger
What a guardian or staff member has explicitly agreed to, when, and how the consent was obtained.
Open the page in SchoolOSWhat it is for
Some purposes need explicit consent: optional messages, publishing a pupil's photo, and health data. Every consent and every withdrawal is recorded here, with its source and the privacy notice version it rests on. Absence, lateness and early-leave messages rest on the enrolment contract, not on consent.
Who uses it
The page opens for whoever holds “View the consent ledger”, to look only, or “Manage tenant settings”, to work in it. In the built-in roles: Owner. A group grants these to any role under Settings → Roles and permissions, and everyone sees only what is within their own scope.
Step by step
- Press “+ Record a consent”, and search for the person by name in the filters first so they appear in the list.
- Choose the purpose, the decision and its date, type how the consent was obtained, then “Record”.
- To withdraw a consent or fix a mistake: record a new line; the latest date is the one that counts.
- To see everything recorded for a person and purpose: “Full history” on its row.
How it works
The ledger only grows: no line is changed or deleted, and a withdrawal is a new line. Each person's current decision for each purpose is the one with the latest decision date. Every line is tied to the privacy notice version shown on the day it is typed; a consent on an older version is still a consent, and the “On an older notice” counter counts it. Only optional messages read this ledger today: an optional message reaches only those whose latest decision is “Granted”, and someone never asked does not get it; photo publishing and health data are recorded only. The counters count people still linked to the school; a line whose owner is no longer linked stays as evidence. Erasing a person keeps their lines and clears their notes. The action log never records a consent's source or note. Only someone holding “Manage tenant settings” records consents.
On the page
- The purpose, and the search by the person's name or the pupil's code.
- Granted, withdrawn, and those on an older notice.
- Absence, lateness and early-leave messages need no consent.
- Each person's current decision for each purpose, how it was obtained, and the notice version. “Full history” shows everything recorded.
- “+ Record a consent”: the person, the purpose, the decision, its date, and how it was obtained.
Questions
- Does switching off “Receives messages” on a guardian's card withdraw consent?
- No. Record the withdrawal here.
- How do I fix a wrong line?
- Record a new line; the latest decision date is the one that counts.
- Do absence messages need consent?
- No; they rest on the enrolment contract.