A teacher needs current SEND information to support a pupil. That does not mean every teacher needs the full history, every professional report or permission to export the record.
Decide access by the job, the part of the record and the action a user can take. Viewing a classroom brief is different from editing or approving a plan. Exporting creates another risk again.
Key points: Give staff the least access that still lets them support the pupil properly. Separate current classroom information from the full working record and restricted material. Set view, edit, approve, export and sharing rights independently. Review permissions when roles change, and keep safeguarding records in the safeguarding process.
Why is one level of SEND access a bad fit?
A single permission usually causes overexposure or under-sharing. Staff either open years of sensitive reports when they only need current strategies, or lose access to the adjustments and communication guidance needed in class.
The SEND Code of Practice says agreed outcomes, actions and support should be recorded and shared with appropriate staff. It also says provision should be recorded accurately and kept current. The record must reach the people delivering support without becoming open to everyone.
The Department for Education's Cyber Security Hub recommends multi-factor authentication for safeguarding and SEND systems, regular permission reviews and removing access when staff leave or change roles. It also recommends least-privilege access, so users only reach what they need.
What are the four layers of a SEND record?
Begin with tasks, not job titles. Two teaching assistants may need different access because one works regularly with the pupil and the other provides occasional cover.
Layer 1: current classroom support
This is the short, usable information needed to teach or support the pupil. It may include:
- current adjustments and teaching strategies
- communication preferences
- relevant sensory or mobility guidance
- outcomes and provision the member of staff is delivering
- the current review date and route for raising concerns
Teachers should normally see this for pupils they teach. Support or pastoral staff may need a narrower, time-limited view.
Layer 2: the working SEND record
The working record can include support plans, review evidence, pupil and parent views, professional recommendations and previous versions. The SENCO needs broad access to manage it. Contributors may need relevant sections and a way to add evidence, without permission to change the approved plan or browse the full history.
Layer 3: restricted material
Some SEND records contain health information, family circumstances, legal advice or third-party information. Health and disability information may be special category data under the ICO's guidance. A teacher may need the agreed adjustment without the full clinical report behind it.
Safeguarding information also needs a firm boundary. Support documentation can explain communication needs or adjustments, but concerns and disclosures belong in the school's safeguarding process. The DfE's record-keeping guidance says child protection files should be stored separately or sealed within the pupil file and transferred separately from the main pupil file. KCSIE 2026 remains the statutory safeguarding reference for schools and colleges in England.
Layer 4: oversight and administration
Senior leaders, data protection staff and system administrators may need audit information: who can access the record, when it changed, which version is current and whether a review is overdue. They do not always need every pupil narrative.
Which permissions should schools separate?
"Has access" is too blunt. Test five actions for every role:
- View: What can this person read?
- Edit: Can they change evidence or propose amendments?
- Approve: Can they make a draft the current record?
- Export: Can they download, print or copy it outside the system?
- Share: Can they send it to another person or organisation, and is that decision recorded?
Someone may need to view a plan in school but have no reason to download it or forward it by email.
The ICO's security guidance says personal data should only be accessed, altered, disclosed or deleted by authorised people acting within the authority they have been given. A folder link that everybody keeps forever does not meet that standard well.
What should a practical SEND access matrix look like?
Adapt this starting point to the school's staffing, policies and risks.
Teachers, teaching assistants and pastoral staff
- View current support information for assigned pupils.
- Contribute observations without replacing the approved plan.
- Use time-limited access for temporary cover where possible.
SENCO and SEND team
- Manage evidence, reviews and approved versions.
- Control contributions, approval and secure sharing.
Leaders, data protection staff and governors
- Leaders and data protection staff check permissions, audit history and overdue work.
- Governors normally receive aggregated information rather than routine access to identifiable records.
External professionals and other schools
- Receive the minimum relevant information for the stated purpose.
- Confirm the recipient, reason, transfer method and intended use, then record the decision.
The DfE's guidance on sharing personal data tells schools to confirm who needs the data, what they need, what they will use it for and whether it can be shared securely.
When should permissions be reviewed?
Review access when staff join, leave or change roles, when a pupil changes class or setting, when temporary cover ends and when an external professional finishes their work.
Run a termly sample. Pick several pupils and test who can view, edit, approve, export and share each layer. Include one staff member who changed role.
MeritDocs keeps current SEND documents, access controls and audit logs together in the school's workspace. Staff can work from the approved document and visible review information without treating the full archive as a communal folder. Schools still set their roles, policies and lawful access.
What should schools ask a SEND software supplier?
Ask the supplier to show permissions in a real workflow, not a slide saying "role-based access".
- Can view, edit, approve and export rights be separated?
- Can access be limited to assigned pupils or groups?
- Can temporary access expire?
- Is multi-factor authentication available?
- Do audit logs support an investigation?
- Can leavers and role changes be handled quickly?
The answer should be visible in the product and supported by the contract and data protection checks.
FAQ
Should every teacher see every pupil's SEND plan?
No. Teachers should have current information for pupils they teach or support. School-wide access to every full plan is difficult to justify when assignment-based access can meet the teaching need with less exposure.
Can teaching assistants edit SEND plans?
That depends on the school's workflow. Teaching assistants often provide useful evidence and delivery records. A school can allow contributions without giving every contributor permission to replace or approve the current plan.
Should the SENCO have access to safeguarding records?
KCSIE requires close liaison between the DSL and SENCO when safeguarding concerns involve a child with SEND. That does not give the SENCO automatic, unrestricted access to the full child protection file. The DSL should control safeguarding information through the school's safeguarding process.
Do parents have a right to see SEND records?
Pupils have a right of access to their personal data. Parents have a separate right to access a child's educational record in maintained schools in England. The ICO explains the distinction. Schools also need to consider the child's competence, parental responsibility, third-party information and any applicable exemptions.
Is a password enough for a SEND system?
No. The DfE recommends multi-factor authentication for systems containing safeguarding and SEND records, alongside regular permission reviews. Passwords are one control, not the whole access model.
The decision to make this term
Choose one pupil record and map the real permissions around it. Who can view the classroom layer? Who can edit evidence? Who approves the current plan? Who can export it? Who can share it outside school?
If the answers depend on an inherited folder link or somebody remembering who should be included, fix the access model. MeritDocs keeps current SEND documents, permissions and audit history together so the right information reaches the right staff without opening the whole record to everyone.
Primary sources
- SEND Code of Practice: 0 to 25 years
- DfE Cyber Security Hub: what's at risk
- DfE data protection in schools: sharing personal data
- DfE data protection in schools: record keeping and management
- ICO guide to data security
- ICO education information and the right of access
- Keeping Children Safe in Education 2026