In a coaching centre, each person should see exactly what they need to do their job and nothing more. Teachers need their batches, attendance and student progress; front-desk staff need enquiries and fee collection; the owner or manager needs revenue and reports. Setting this up with roles, rather than one shared login, protects student data, reduces mistakes and makes it clear who did what.
Why a shared login is a risk
Many centres begin with one admin account used by everyone. It feels convenient until something goes wrong. A fee entry is deleted and nobody knows who did it. A former employee still knows the password months after leaving. A part-time teacher can see every family's phone number and payment history, which they never needed.
Student and parent details are personal data, and families trust you to handle them carefully. Separate logins with defined access are the simplest way to honour that trust and to keep a clear record of every change.
Start from tasks, not job titles
Before creating roles, list the tasks each person actually performs in a normal week. Job titles vary between centres, and one person often wears several hats. Working from tasks avoids giving someone broad access just because their title sounds senior.
For each task, ask three questions:
- Does this person need to see this information?
- Do they need to change it, or only view it?
- Would it cause harm if they changed it by mistake?
The answers usually sort themselves into a small number of roles.
Pay particular attention to exports and deletions. Being able to view a student list is very different from being able to download the whole list or delete records. Downloads and deletions deserve the tightest control, because a single careless action can expose or lose information that took years to build. As a rule, only the owner and one trusted manager should be able to export full student or payment data.
A sensible starting set of roles
Most coaching centres can begin with roles along these lines and adjust from there:
- Owner or director. Full access, including revenue, payouts, settings and staff management. Keep this to as few people as possible.
- Centre manager. Day-to-day operations: batches, timetables, students, attendance and most reports, but not necessarily payout or business settings.
- Teacher. Their own batches and courses, attendance, lesson content, quiz results and student progress. Usually no access to fees or other teachers' batches.
- Front desk or office staff. Enquiries, admissions, recording cash and bank payments, issuing receipts. Limited or no access to revenue totals.
- Counsellor or admissions. The lead board, follow-ups, trial bookings and converting leads into students.
- Accounts. Payments, invoices, refunds and financial reports, without the ability to change course content.
Use per-person overrides sparingly
Real teams rarely fit neat boxes. A senior teacher may also handle admissions on weekends, or a manager may need one financial report but not the rest. Per-person overrides let you add or remove a specific permission for one individual without creating a new role for every exception.
The risk is that overrides pile up quietly. Review them every term and remove any that are no longer needed. If several people share the same override, that is a sign you need a new role instead.
Keep an activity log and read it
An activity log records who changed what and when. It settles disputes quickly, for example when a parent says a payment was recorded and the system shows otherwise. It also discourages careless changes, because everyone knows actions are recorded. The log is only useful if someone looks at it, so make a short review part of the owner's monthly routine, focusing on changes to fees, refunds, roles and permissions.
Protect accounts and handle departures
Permissions are only as strong as the accounts behind them. A few habits make a real difference:
- Turn on two-factor sign-in for anyone with access to payments or student data.
- Pay attention to login alerts that show sign-ins from unfamiliar places.
- Never share passwords between staff, even temporarily.
- When someone leaves, disable their login on their last day and reassign their leads and batches.
- When someone changes role, update their access rather than simply adding more.
Offboarding is where most centres slip. Put it on a written checklist alongside returning keys and handing over files.
Where MBSGuru fits
MBSGuru gives teachers and office staff their own logins with role-based access and per-person overrides, and writes every change to an activity log. Optional two-factor sign-in and login alerts are available for coach, staff and student accounts, and each academy's data is kept separate from every other business. Read more on the benefits page or start free to set up your team.


