The practical answer

Agree access around responsibilities and approved safeguarding procedures before an urgent situation.

A colleague needs information to respond to a concern, but the usual safeguarding lead is unavailable. Elsewhere, someone still has access from a role they left last term. These are different problems with the same underlying question: has the school thought through who needs sensitive information, for what purpose and under which arrangements?

Safeguarding record access needs careful planning before an urgent situation. The objective is to support appropriate action while keeping sensitive case information within the school's approved safeguarding and information-handling procedures.

Begin with responsibilities, not a list of names

Map the roles involved in the school's safeguarding arrangements. Distinguish between someone who reports a concern, someone who manages case work and someone who needs limited information to carry out an agreed action. Those responsibilities do not automatically require the same view of a record.

Ask what each role needs to do with information and why. A general statement that “senior staff need access” is too broad to explain the decision. Equally, an arrangement that depends entirely on one person being present may leave an avoidable gap.

The answer should come from the school's safeguarding leadership and applicable information governance arrangements. A software administrator can implement an agreed approach, but should not have to invent the policy while creating user accounts.

Plan for absence and changes in role

Consider what happens when the usual responsible person is away, leaves the school or moves to another role. Identify the approved cover arrangement and make sure the relevant people understand it. Do this through established safeguarding procedures rather than informal sharing of accounts or copies of case files.

Include access review in staff role changes. Ask whether the person still has the same responsibilities and whether existing access remains appropriate. Temporary responsibilities also need an end point; a short period of cover should not silently become indefinite access.

Test the administrative process using fictional records. That allows the team to identify confusion about roles without exposing a real child's information during a demonstration or training exercise.

Keep information sharing purposeful

Restricting access does not mean that relevant information should never be shared. For schools in England, the Department for Education's guidance on sharing personal data explains that appropriate information sharing supports safeguarding. Decisions must follow the applicable safeguarding framework and the circumstances, rather than a blanket assumption either for or against sharing.

Before creating a general report, consider whether the audience needs individual case details at all. A leadership discussion about process or outstanding work may be possible without circulating the underlying personal account. Where identifiable information is needed, use the approved channel and record the relevant decision in accordance with school procedures.

Avoid copying sensitive narratives into ordinary maintenance, inspection or general reporting records. A facilities action may require a practical instruction without requiring access to the safeguarding case that prompted it.

Look beyond the main system

Access decisions can be undermined by the copies created around a system. Think about exported documents, email attachments, printed notes and files left in shared folders. Include these in the school's handling arrangements rather than assuming the central workspace is the entire picture.

Ask staff where they turn when they cannot find something. If the answer is a private collection of old attachments, investigate why the approved route is difficult to use. Improving that route may be more effective than simply reminding everyone to avoid duplicate copies.

Retention, transfer and disposal should follow the school's approved policy and applicable requirements. Do not set a universal retention period based on a general article or on the default setting of a tool.

Bring concrete questions to a product discussion

Use fictional scenarios to discuss how a proposed system would support your school's approach. Ask the supplier to demonstrate the relevant access arrangements, explain administrative responsibilities and identify anything requiring configuration or separate confirmation.

Do not assume a feature exists because a screen looks restricted or a presentation uses a security label. Keep the requirements and the demonstrated answers together for the people making the decision.

CerthixED includes Safeguarding, described as sensitive case work within a restricted workspace. Discuss your school's specific requirements in a demonstration. For broader document organisation, see How to organise school compliance records, keeping the different access needs of those records clear.

← Back to the blog