Skip to content

Governance and platform connectivity

Access is explicit; integrations do not become back doors.

Built for administrators, it teams, and security reviewers.

Use scoped roles, deny rules, expiring API keys, device controls, MFA, audit evidence and tenant-safe search across REST, AI and MCP surfaces.

Already have a workspace? Log in

What changes

Extend Schoolbooks while keeping access explicit, observable, and revocable.

Use scoped roles, deny rules, expiring API keys, device controls, MFA, audit evidence and tenant-safe search across REST, AI and MCP surfaces. The workflow remains permission-aware, reviewable, and available to both people and governed Schoolbooks AI.

01

Precise authorization

Combine account, workspace, role, and record context for scoped access.

02

Safer integrations

Scope credentials, expire access, and audit API and MCP activity.

03

One policy surface

Apply the same server-owned rules to the UI, REST API, AI, and automation.

Schoolbooks / Security, roles & integrations Live workspace

Current outcome

Extend Schoolbooks while keeping access explicit, observable, and revocable.

Evidence connected Permissions respected

How the work moves

A complete path, not another disconnected tool.

Each stage carries context and responsibility forward, so the next person receives a decision-ready record.

  1. 01

    Set the context

    Start from the organization, workspace, period, people, and policies that govern the work.

  2. 02

    Capture once

    Record the source event and evidence where it happens instead of recreating it downstream.

  3. 03

    Review the exception

    Keep the routine path fast while routing conflicts and incomplete evidence to a person.

  4. 04

    Complete with history

    Advance the workflow without erasing the earlier state, approval, or responsible actor.

Friction removed

  • The same record is entered again when work moves between teams.
  • Important context lives in private spreadsheets, messages, or memory.
  • Managers can see a total but cannot follow it back to the decision.
  • Automation often removes the review point instead of improving it.

Controls retained

Scoped permissions

Read and action access follows the user’s account, workspace, role, and object context.

Durable evidence

Source records, comments, approvals, and reversals remain available after completion.

Shared capability

The interface, REST API, AI tools, and MCP use the same server-owned business rules.

The AI boundary

Useful automation makes accountability clearer.

AI may

  • Find permitted records and summarize the current state.
  • Prepare drafts and proposed next actions.
  • Explain exceptions and link the evidence used.

AI must not

  • Bypass the current user’s permission.
  • Approve its own restricted action.
  • Invent missing operational or financial facts.

Ready when you are

Start with security, roles & integrations. Expand without starting over.

Continue exploring

Fees & collections