Who can actually see this file
A folder permission has two settings. A safeguarding record needs more than two, and this is the one gap no amount of spreadsheet skill closes.
4 min read
First IMS
A shared drive grants access to a file. That is the whole model, and it is the problem.
Your designated safeguarding lead needs to see every incident logged about a child. A head of department needs to see their own department's submissions and nothing from anyone else's. A supply teacher covering Year 8 on Thursday needs the register and nothing else at all.
A file cannot express that. Somebody either has the link or does not.
This is a structural limit, not a discipline problem
It is worth being precise here, because most writing on this subject overstates the case and gets dismissed for it.
You can build something that looks like role-based access on a shared drive. Separate the safeguarding notes into their own folder, restrict it to two people, and link out to it from the student's row. Plenty of schools have done this and it works.
What it costs you is the thing you were trying to keep. You now have a child's record in two places, and the link between them is a URL that somebody has to maintain. Move the file, rename the folder, or let the safeguarding lead leave in July, and the connection breaks silently. Nobody notices until the next time it matters, which is the worst possible moment to find out.
Split the files and you get permissions but lose the single record. Keep one file and you get the record but lose the permissions. There is no third arrangement, and no amount of spreadsheet expertise produces one. This is the one claim in this whole subject that is genuinely about impossibility rather than about effort.
Reading is not the same as editing
The second gap is quieter and it matters more in a safeguarding context.
Version history tells you who changed a cell. It does not tell you who opened the file and read it.
Google Workspace does record view events, so this is not a flat impossibility either. It sits in Drive log events in the admin console, it needs the Audit and Investigation privilege, and it is only available on the paid editions such as Education Standard and Education Plus rather than the free tier. Which means the record exists, in a console your safeguarding lead almost certainly cannot open, in a search nobody runs unless something has already gone wrong, and never attached to the child it concerns.
A safeguarding lead asking "who has read this note about this child" is asking a reasonable question. On a shared drive the honest answer is that somebody could find out, eventually, if they had the right admin account and a reason to look.
The 72 hour question
The General Data Protection Regulation gives an organisation 72 hours to report a personal data breach to its regulator once it becomes aware of one. Most schools reading this are not under GDPR, and the deadline is not the useful part anyway.
The useful part is the question underneath it. If a file of safeguarding notes were shared with the wrong person this afternoon, how long would it take you to find out, and could you say afterwards exactly who had opened it?
Answer that honestly about what you run on today. The answer is the same whether or not a regulator is asking.
What we built, and what we did not
In First IMS, safeguarding lives in a module called NEST, and it is a module inside the system rather than a separate tool. An incident is logged against the student record, related incidents group into a case, alerts route by category to the role that should handle them, and every note records who has read it. The read record sits on the note, where the person responsible for the child can see it, rather than in an audit console.
Access is configurable per school. In practice the roles that matter are super admin, senior leadership, head of department scoped to their own department, and the designated safeguarding lead with full access to NEST.
What we have not built is a way to make this decision for you, and there is no AI anywhere in it. Safeguarding is the last place we would put a feature that guesses.
If you want to see what your own categories and roles would look like rather than a demo school's, ask and we will set it up that way.
Safeguarding · Permissions · Data protection
Read next
Beyond the spreadsheet
What three spreadsheets actually cost a school
The honest number is smaller than most software vendors claim. The real cost sits somewhere else, and it is harder to fix.
4 min read
Running a school
One record per student, not one per department
The test of a school system is not how many features it has. It is whether answering a parent's question takes one screen or four.
3 min read
Tell us what your school actually runs on
Send us the spreadsheet you dread opening and we will show you what it looks like once it stops being a spreadsheet. We reply within one working day.