Dashboard

Roles & Permissions Reference

What each role can do in MITCON Skills. Server-side role: middleware in routes/api.php is authoritative — this page mirrors it.

Feature Admin HOD Div
Head
Section
Head
PC Course
In-charge
Couns-
ellor
Faculty T&P Accounts Student Employer
View own profile ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
Manage users ✅ ✅ 📌 📌 — — — — — — — —
Manage roles & access ✅ — — — — — — — — — — —
Master data — Centers ✅ ✅ 📌 👁️ — — — — — — — —
Master data — Sections ✅ ✅ 📌 📌 — — — — — — — —
Master data — Courses ✅ ✅ 📌 📌 — — — — — ✅ — —
Master data — Batches ✅ ✅ 📌 📌 — — — — — ✅ — —
Staff allotments ✅ ✅ 📌 📌 — — — — — — — —
All leads (read) ✅ ✅ 📌 📌 📌 📌 📌 — 📌 — — —
Leads — log calls, edit ✅ ✅ 📌 📌 📌 📌 📌 — — — — —
Bulk send (WhatsApp/Email) ✅ ✅ 📌 📌 📌 📌 📌 — — — — —
Meta Lead Ads — mapping ✅ ✅ 📌 — — — — — — — — —
Reports ✅ ✅ 📌 📌 📌 📌 📌 — 📌 📌 — —
Test messaging ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ — —
Reminders / follow-ups ✅ ✅ 📌 📌 📌 📌 📌 — — — — —
Payment / accounts ✅ ✅ — — — — — — — ✅ 📌 —
Placement / OJT ✅ ✅ 📌 📌 📌 📌 — — ✅ — 📌 📌
Phase IV additions
Interview & Enrolment (Admissions) ✅ ✅ ✅ 📌 ✅ — — — — ✅ — —
Enrolment detail — view ✅ ✅ ✅ 📌 ✅ ✅ — — — ✅ — —
Enrolment detail — actions (cancel/msg) ✅ ✅ ✅ 📌 ✅ ✅ — — — — — —
Verifications ✅ ✅ ✅ — — — — — — ✅ — —
ERP Receipts ✅ ✅ ✅ — — — — — — ✅ — —
Staff student profile — view / print ✅ ✅ ✅ ✅ ✅ ✅ — — — ✅ — —
Staff student profile — edit ✅ ✅ ✅ — ✅ — — — — — — —
Phase VI additions
AI Assignments (batch) — manage ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
AI Assignments — regenerate / publish ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
AI Assignments — reports & feedback ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
AI Assignments — attempt / submit — — — — — — — — — — 📌 —
Phase VII additions
Exams (batch) — create & edit details ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
Exams — upload questions (.xlsx) ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
Exams — publish / cancel / send reminder ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
Exams — publish results (post-window) ✅ ✅ ✅ ✅ ✅ ✅ — — — — — —
Exam reports & per-student drill-down ✅ ✅ ✅ ✅ ✅ ✅ — 📌 — — — —
Exams — attempt / autosave / submit — — — — — — — — — — 📌 —
Exams — view own result — — — — — — — — — — 📌 —
✅ full access 📌 scoped to allotments 👁️ read-only — no access

Accountant — Phase IV scope

Owns the payment lifecycle end-to-end. Nav trimmed to just the enrolment → verification → ERP receipt surface, plus Courses + Batches (creates them as part of enrolment setup).

  • Interview & Enrolment — read the admissions pipeline
  • Enrolment detail (view) — payments, consent, timeline before verifying
  • Verifications — approve / reject enrolments
  • ERP Receipts — monitor push/fetch, retry stuck pushes, download PDFs
  • Courses & Batches — create courses and batches
  • Staff student profile — view / print — read-only print/PDF export

View own profile

Every signed-in user sees their own profile page — accessible from the user dropdown in the top-right (👤 View my profile). Displays name, phone, email, roles, and recent login activity.

Name, phone, and email are locked on the self-profile page — these are login identifiers and audit-critical. Admins can update them via the Users management page.

ERP receipt notes

  • ERP receipts are created per successful payment — two payments on one enrolment produce two ERP receipts.
  • Zero-fee enrolments (CSR-sponsored, scholarship): no ERP receipt — nothing paid, nothing to receipt.
  • Push happens on accountant verification; retries every 15 min; PDFs fetched every 30 min from processedPayments.
  • Local receipt code (REC26-27/NNNN) is kept alongside the ERP receipt number.

Assignments & Exams — access notes

  • Faculty scope — Faculty see and manage only batches they're currently assigned to via batch_faculty_assignments. Admin-tier acts as fallback and sees all batches.
  • Lock on attempt — Once ANY student starts an exam attempt, the exam is locked from all content mutations (details, questions, publish, cancel) — even for admins. Send Reminder and Publish Results still work.
  • Publish exam results is the only exam action pure-faculty cannot do — reserved for admin-tier (admin / HOD / Division Head / Section Head / PC / Course In-charge).
  • Best-of-N attempts — When an exam allows multiple attempts, students see their best score; the authority sees every attempt in the reports drill-down with a ⭐ marker on the best one.
  • Immediate vs manual results — immediate_result=true auto-publishes when the window closes (via the exam:process-schedules cron); otherwise the exam moves to results_pending and waits for the authority's manual publish.
  • Student side — Students only ever see their own attempts, their own results, and only for batches they're actively enrolled in.

Discrepancies between this page and actual behaviour? The role: middleware in routes/api.php is authoritative — this page is a mirror.