Admin permissions — who can access which schools
Admin permissions — who can access which schools
Every admin in your trust can access every school by default. This page is where you see that at a glance across the whole trust, and reduce an individual admin to a subset of schools where you need to. It's in the MAT overview, under Users & Groups → Admin permissions.
The overview {#step-1}
The summary at the top tells you the shape immediately — how many admins there are, how many have full access, and how many are reduced. Reduced access is the exception worth noticing, so it's called out rather than buried.
The list shows every admin with their access at a glance: Full access, or Reduced — N of M schools. You can:
- Search by admin name or username.
- Filter by access level — show only full, or only reduced, admins.
- Filter by school — "who can access St Augustine's?" — to see every admin permitted for one school.
Reduce an admin's access {#step-2}
Select Manage access on an admin. You'll see every school in the trust, each ticked by default (everyone starts with full access). Untick the schools this admin should not reach.
Because a trust can have dozens of schools, the editor is built for it:
- Select all / Clear all for the schools currently shown.
- A search box to find schools by name within the list.
- A live count ("38 of 44 schools") so you always know where you stand.

The admin's own home school is always kept — it can't be removed here. Select Save access to apply.
This is a real boundary, not just a hidden menu {#step-3}
Reducing an admin genuinely restricts them, everywhere and on the server — not just in what they see:
- The school switcher only offers schools they're permitted; they can't switch to one they've been removed from.
- Every cross-trust view — the dashboard, user search, log trace, sync and MIS previews — only ever includes their permitted schools.
- No school-scoped query can return, or act on, a school outside their set. This matters for data protection: pupil information from other schools is never exposed to an admin who shouldn't see it.
To give someone full access back, open their editor and Select all, then save.
Who can change this, and what's recorded
Only a MAT admin can manage permissions, and only for admins within their own trust and for schools they can themselves reach — nobody can grant access beyond their own. Every change is logged and recorded in the audit trail (who changed whose access, to which schools).
The classic (v1) admin manages the same permissions from a user's own page, so both stay in step during the rollover.
Two axes: which schools, and what they can do
This page governs which schools an admin can reach. A separate control governs what they can do within a school — full access, or a reduced day-to-day set. Each admin row shows an access-level chip (Full / Reduced / Custom) for that second axis; to change it, open the admin's Access tab. See Reduced admin access. The two compose: an admin's real power is the schools they can reach and the capabilities they hold — both enforced server-side.