Platform

Roles, limits and a full audit trail.

Multi-tenant governance: nine roles, per-account permissions, feature flags in a three-level cascade, and an audit log with diffs.

An illustration of users and rolesA schematic of the users and roles section: each user with their role and what that role may reach. Permissions are denied by default and enforced on the server. A drawing, not a screen capture.NORTHVALE INSTITUTE OF TECHNOLOGYDashboardReports & analyticsCandidatesQuestion bankAssessment librariesAssessmentsSessionsMonitoringReviewGroupsSettingsUsers & roles · 9 roles availableALLPLATFORMTENANTUSERROLECAN REACHA. DeshpandeACCOUNT_ADMINALLR. IyerEXAM_MANAGERASSESSMENTS · SESSIONSS. KhanREVIEW_MANAGERREVIEW · APPEALSM. BoseREVIEWERREVIEW ONLYP. NairINVIGILATORMONITORING ONLY
REVIEWER · what it may reach
Review queueVIEW AND DECIDE
Question bankNO ACCESS
EnforcedON THE SERVER
DENY BY DEFAULT — NOT HIDDEN IN THE INTERFACE
Interface illustration, not a screen capture. Drawn to show roles against what each one can actually reach.
01

Roles and permissions

Nine roles across platform and tenant scope, with per-account customisation of what each role may do. Deny by default, enforced on the server for every request — not hidden in the interface.

Nine roles, scoped permissionsRoles across platform and tenant scope, with per-account customisation of what each role may do.VIEWEDITDECIDEADMINExam managerReviewerReview managerAccount adminCUSTOMISABLE PER ACCOUNT
02

Plans, flags and limits

Feature flags resolve system → plan → account. Per-account limits cover users, candidates, assessments, concurrent sessions, storage and API rate.

Feature flags resolve in three levelsA feature flag resolves system, then plan, then account — three levels, in that order. Per-assessment settings are a separate configuration layer, not a fourth flag tier.Systemthe platform defaultPlanwhat the tier allowsAccountwhat you switch onTHREE LEVELS — NOT FOURPER-ASSESSMENT SETTINGS ARE A SEPARATE LAYER
03

Audit

Every significant action is recorded with a diff of what changed, who changed it and when.

Every change, with a diffEvery significant action is recorded with a diff of what changed, who changed it and when.Audit logAssessment publishedA. KUMARDetector weight 6 → 9S. RAORole permission addedA. KUMARSupport window grantedS. RAOWHO, WHAT, WHEN — AND WHAT CHANGED
04

Support access is granted, not assumed

A platform support engineer cannot enter your account unless you grant an explicit window, which expires on its own. Every impersonation is audited. Most vendors cannot offer you this.

Support access is granted, time-boxed and auditedA platform support engineer cannot enter an account until the institution grants an explicit window. The window expires by itself, and every action inside it is audited.SupportNO ACCESSYou grant a windowIT EXPIRES ON ITS OWNWhile it is openAUDITEDSCOPEDREVOCABLE
05

Your own portal address

Brand name and logo on candidate-facing screens, and a self-service vanity subdomain so your candidates sign in at your institution’s own address.

Your name on it, not oursBrand name and logo on candidate-facing screens, and a self-service vanity subdomain so candidates sign in at your institution’s own address.Candidates seeYOUR NAMEYOUR LOGOYOUR ADDRESSThey do not seeOUR BRANDOUR DOMAINA VANITY SUBDOMAIN, SET UP BY YOU

Bring one paper. We'll run it live.

Thirty minutes, your own exam, no slide deck.