Four layers, one spine.
The reason the modules behave as one product is that they are not modules.
They are views onto a single record, governed by a single permission model, sitting on a single foundation.
Surfaces
One sign-in, one address. The public website, the staff app, the parent and student app, and scoped portals for governors, inspectors and hirers. One door, different buildings.
Permissions
Role times scope times restricted clearance times purpose. Four layers, not one. Read is a separate action from export, and every temporary grant carries an expiry date.
Domain
Admissions, students, staff and HR, curriculum, attendance, pastoral, inclusion, timetabling, operations, finance, marketing, parents, careers and governance. Fourteen areas, one schema.
Foundation
Group, then school, then person. Google Workspace for identity, Drive for documents, and one relational core underneath every department.
Some things refuse to belong to one department.
Safeguarding, inclusion, the skills framework, QR identity and notifications are not modules.
They run through everything, which is exactly why they cannot be bought separately and bolted on.
Every department, every dependency.
Each point is a workflow or a data entity.
Each line is a dependency the platform maintains, so a change in one department reaches every other one that depends on it.
A dependency is only worth having if it saves somebody an afternoon.
Lesson cover, solved before briefing
An absence is recorded, or a leave request is approved. Nobody presses anything else.
See it running on real data.
A working demonstration on a live database, walked through by the people who built it. Forty minutes, no slide deck.