Troubleshoot permissions and unavailable features
A hidden control or access-denied response can be correct. Identify the effective role and feature conditions before changing membership or plan settings.

Diagnose in order
Section titled “Diagnose in order”- Verify the active school.
- Verify the signed-in account and effective role.
- Check that the membership is active and its invitation was accepted.
- For a sheikh, verify assignment to the relevant halqa or learner.
- Confirm that the resource belongs to the current school and active context.
- Check the school’s effective plan, limit, and feature state.
- For controlled features, check whether separate rollout or platform eligibility is required.
Common cases
Section titled “Common cases”- School administration control missing: only a school administrator can perform it.
- Sheikh sees fewer learners: assigned-halqa boundaries apply.
- Parent sees no child: the invitation may not be accepted or linked in the active school.
- Feature is unavailable: plan, feature, limit, or rollout conditions are not all effective.
- API read works but write fails: write capability and scopes are separate.
- Limit reached: remove or archive only legitimate records, or use the approved plan-change process; never alter history to evade a limit.
Correct access safely
Section titled “Correct access safely”The school administrator should:
- identify the minimum correct role;
- update or re-invite the intended person;
- assign only required halqas;
- verify access using the person’s own account;
- remove stale membership when it is no longer needed.
Do not promote someone to administrator merely to fix one task. Do not reuse another user’s session.
Escalate with safe evidence
Section titled “Escalate with safe evidence”Provide the school, screen, approximate time, expected task, effective role, and visible error. Do not send passwords, invitation tokens, API keys, or another learner’s record.
See role permissions and feature availability.