Security & compliance

How Tuling protects institutional data — and how campuses run DPDP, POSH, statutory payroll, and NAAC SSR review inside the same ERP that already holds their operational records.

RBAC · PBAC · ABAC · RAdAC · JIT · SoD DPDP-ready workflows NAAC SSR workspace Dedicated tenant databases India-region hosting Audit trails

Most campus ERPs stop at role portals. Procurement teams rarely see attribute-based policy packs, risk-adaptive step-up, just-in-time grants, and separation of duties — plus a criterion-level NAAC Self-Study Report workspace — in a single education platform. This page summarises how Kinetixbase Lab Technologies operates Tuling. For a security questionnaire or vendor assessment, contact sales@tulingcreativehub.com.

Platform controls

Security by architecture

Controls built into multi-tenant campus ERP — not a slide deck added after the RFP.

  • Tenant isolation

    Each institution receives its own subdomain and dedicated PostgreSQL database — not shared-schema multi-tenancy. Campus data stays logically and physically separated from other tenants on the platform.

  • Data residency in India

    Production workloads are hosted in India-region cloud infrastructure. Institutional data — student records, payroll, fees, and documents — remains within India for residency expectations common in education procurement.

  • Backups & recovery

    Automated database backups with point-in-time recovery options. Backup retention and restore drills are part of platform operations — so examinations, payroll, and fee cycles are not held hostage to a single disk failure.

  • Layered access control

    Not just roles. Tuling ships RBAC, permission claims, ABAC policy packs, a PBAC decision point, risk-adaptive controls, just-in-time grants, separation of duties, and continuous session assurance — in one campus ERP stack.

  • Audit logs

    Sensitive actions — compensation changes, leave approvals, fee waivers, access grants, payroll runs, NAAC pack reviews, and configuration edits — leave an audit trail with who, what, and when.

  • Encryption & transport

    Data in transit is protected with TLS. Credentials and integration secrets are stored using platform secret management — not hard-coded in client bundles or shared config files.

Differentiation

Enterprise access control in one ERP

Industry stacks usually bolt one or two of these onto a product. Tuling evaluates them as a layered pipeline — below: what it is, why it helps a campus, and a concrete usage example.

  • RBAC

    Role-based access

    Staff map to role portals — HR, Accounting, Registrar, HOD, Dean, Principal, Library, and more — with hierarchical role expansion and module entitlements scoped to what the campus licensed.

    Why it helps
    New joiners get the right desk on day one; leavers lose portal access when their role is removed — without rewriting every screen.
    Where you use it
    An HOD opens leave approvals for their department; a junior accountant only sees fee counter — not full voucher posting.
  • Claims

    Permission claims

    Fine-grained permission claims cached per user and tenant. Endpoints enforce claims alongside roles — least privilege without hard-coding every check into a single role name.

    Why it helps
    One role can stay broad while sensitive buttons stay locked until IT grants a specific claim.
    Where you use it
    An HR officer can view the directory but cannot run payroll until they hold the payroll.run claim for that tenant.
  • ABAC

    Attribute-based policies

    Policy packs evaluate subject, resource, and environment attributes — same tenant, campus grants, ownership, risk band, device trust, network zone, and assurance level. Explicit deny wins; default deny when nothing matches.

    Why it helps
    Stops “same role, wrong campus / wrong record” mistakes that pure role lists cannot catch.
    Where you use it
    A Registrar on Campus A cannot open Campus B fee waivers even if both use the REGISTRAR role; a faculty member can edit only their own profile fields.
  • PBAC

    Policy decision point

    A thin PDP over ABAC: stable permission catalog, server-side resource resolvers, composed environment (risk + JIT + session), and decision audit. Clients send action + resource references only — never roles, risk scores, or JIT claims.

    Why it helps
    Procurement and IT get one decide API and an auditable trail — browsers cannot fake “I’m low risk” or “I have a JIT grant”.
    Where you use it
    Management desk asks “may this user approve NAAC pack X?” — the server loads the pack, risk, and session trust, then returns allow / deny with reasons.
  • RAdAC

    Risk-adaptive access

    Explainable risk scoring from signals like new device, new IP, failed logins, idle session, and sensitive actions. Bands map to obligations — audit, limit session, require step-up, or deny — not an opaque black box.

    Why it helps
    Normal campus Wi‑Fi work stays friction-light; unusual logins get challenged instead of trusting a password forever.
    Where you use it
    Payroll export from a new laptop after midnight triggers step-up; the same action from the accounts office on a known device proceeds with audit only.
  • JIT

    Just-in-time grants

    Time-boxed temporary access for a narrow action pattern and resource. Grants never mint permanent roles. Approval goes through SoD (requester ≠ approver). Break-glass paths get shorter duration and stronger audit.

    Why it helps
    Vendors, auditors, or IT can fix a live issue without leaving permanent ADMIN rights in the tenant.
    Where you use it
    An external consultant gets a 2-hour grant to view one NAAC criterion export; Principal approves; the grant expires automatically — no leftover role.
  • SoD

    Separation of duties

    Maker–checker workflows with immutable trails. Distinct actors across stages; last editor cannot self-review. Used for NAAC SSR packs, JIT approvals, and other dual-control paths — edit after approval resets to draft with a trail entry.

    Why it helps
    Blocks self-approval of money, accreditation packs, and elevated access — the control auditors ask for first.
    Where you use it
    IQAC reviews the SSR pack; Principal must approve. The Dean who last edited a metric cannot be the reviewer for that pack.
  • CA

    Continuous authentication

    Server-side session assurance with step-up challenges (e.g. TOTP) for sensitive or high-risk actions. Modes: off, audit-only, or enforce — so campuses can roll out without blocking day-one operations.

    Why it helps
    A stolen open browser tab cannot quietly approve payroll or NAAC without proving the user is still present.
    Where you use it
    After idle time, approving a compensation change asks for a TOTP step-up; browsing the dashboard does not.

How a request is decided

Session validation → continuous auth → tenant entitlement → PDP / ABAC (with RAdAC risk + JIT grants) → SoD when the action requires dual control.

  1. Session validation

    Authenticate the user and establish tenant context.

  2. Continuous auth

    Reassess session assurance; attach step-up obligations when needed.

  3. Tenant entitlement

    Confirm licensed modules and role portal access for the institution.

  4. PDP / ABAC

    Evaluate policy packs with RAdAC risk and active JIT grants in the environment.

  5. SoD when required

    Enforce dual-control stage order and conflict rules before the action completes.

Scope that matches campus reality

  • Campus-scoped access

    FULL or READ_ONLY grants per campus. Admins bypass; everyone else is filtered to campuses they can actually operate.

    Why: Multi-campus groups stop staff from editing the wrong institute’s HR or fees by accident.

    Example: HR for the Engineering campus has FULL there and READ_ONLY on the sister Arts campus directory.

  • Department & position scope

    Managed departments resolve from active staff positions — HOD, Dean, Principal — not hardcoded department lists in every module.

    Why: Approvals follow the org chart when someone becomes HOD — without a ticket to “add them to 12 modules”.

    Example: New CSE HOD automatically sees leave and inventory for CSE only; Dean of Management sees both MBA departments they hold positions for.

  • Ownership & tenancy

    Owner checks and same-tenant conditions keep personal records and cross-tenant resources from leaking across desks.

    Why: Personal ESS data and other colleges on the same platform stay out of reach.

    Example: An employee edits their own tax declaration; they cannot open a colleague’s. Tenant A policies never evaluate Tenant B resources.

  • Domain workflow policies

    Fee discounts, late-fee waivers, loan approvals, admissions transitions, and voucher thresholds — table-driven role and amount rules per tenant.

    Why: Finance and registrar set “who can waive what %” in policy tables — not buried in developer code.

    Example: Discount under 10% auto-paths differently than a 40% waiver that needs Registrar then Management review.

Regulatory fit

Compliance modules institutions use

Statutory, privacy, workplace, and accreditation — run from the same compliance hub as day-to-day HR and finance.

DPDP Act readiness

Why it helps
Procurement and data-protection officers can show consent, purpose, and DSAR handling — not a privacy policy PDF alone.
Where you use it
A parent or ex-employee requests correction of personal data; the institution logs a DSAR and Tuling supports fulfillment inside the tenant boundary.
  • Consent capture and purpose limitation for personal data processed in HR, admissions, and student services
  • Data subject access request (DSAR) workflow for correction, erasure, and portability where applicable
  • Retention controls aligned to institutional policy — not infinite hoarding of ex-student or ex-employee records
  • Processor agreements and sub-processor transparency for institutions evaluating vendor risk

POSH & ICC

Why it helps
ICC members work inside a restricted workflow instead of shared drives that anyone in HR can open.
Where you use it
A complaint is registered, inquiry steps are tracked, and only authorised ICC / HR roles see complainant and respondent details.
  • POSH case register and inquiry workflow within HCM employee relations
  • Internal Complaints Committee (ICC) support with confidential handling of complainant and respondent records
  • Restricted access and documentation trails institutions need for statutory reporting

India statutory payroll

Why it helps
Month-end PF/ESI/TDS stops depending on a fragile Excel that only one accountant understands.
Where you use it
Before payroll lock, HR sees who still lacks UAN/ESI; after run, accounts export ECR / contribution files and Form 16 packs from the same system.
  • PF, ESI, professional tax, and TDS calculations aligned to payroll configuration
  • UAN / ESI enrollment health across the workforce — not a month-end spreadsheet surprise
  • Income-tax FY policy, Form 16 / 24Q support, and regime calculator for employees
  • Payslip and statutory export formats finance teams expect at month-end, plus full & final settlement with audit history

UGC faculty & qualifications

Why it helps
Deans and IQAC spot faculty-norm and credential gaps before an inspection letter arrives.
Where you use it
Regulatory hub flags missing PhD / NET evidence for a programme; HR attaches verified documents for the faculty audit pack.
  • Regulatory hub for UGC / NAAC faculty norms and faculty audit packs
  • Qualifications and mandatory training compliance tracking for teaching staff
  • HR compliance audits and document verification logs for assessor-ready evidence

Accreditation

NAAC SSR review — built as a workspace

Affiliated / constituent college framework: Extended Profile + seven criteria, Key Indicators, quantitative and qualitative metrics, evidence, autofill from ERP, and dual-control pack approval. IQAC stops assembling the Self-Study Report from twelve spreadsheets the week before submission.

EP · Extended ProfileC1 · Curricular AspectsC2 · Teaching-Learning & EvaluationC3 · Research, Innovations & ExtensionC4 · Infrastructure & Learning ResourcesC5 · Student Support & ProgressionC6 · Governance, Leadership & ManagementC7 · Institutional Values & Best Practices
  • Full SSR workspace

    Extended Profile plus all seven NAAC criteria (Curricular through Values & Best Practices), with Key Indicators and QnM / QlM metrics — not a generic document folder labelled “NAAC”.

    Why it helps
    IQAC works criterion-by-criterion instead of hunting folders named Final_SSR_v7.
    Where you use it
    Coordinator opens C2 Teaching-Learning, sees KI 2.1–2.7 metrics, and assigns HODs to fill only their Key Indicators.
  • Metric catalog & responses

    Structured quantitative fields (including five-year series) and qualitative narratives with word limits. Responses stored per metric code and academic year so IQAC can iterate without rebuilding spreadsheets.

    Why it helps
    Year-on-year numbers stay comparable; narrative drafts do not overwrite last cycle’s answers.
    Where you use it
    Metric 2.1.1 stores five-year enrolment; QlM 7.2.1 keeps the best-practices write-up under the NAAC word limit.
  • ERP autofill

    Pull live figures from ERP services into metrics — programmes, enrolment, faculty strength, and other resolvers — so the SSR starts from operational truth instead of re-keyed AISHE extracts.

    Why it helps
    Cuts copy-paste errors that peer teams catch when SSR numbers disagree with the live system.
    Where you use it
    IQAC clicks autofill for programmes offered; the metric loads counts from SIS / admissions instead of a manual AISHE spreadsheet.
  • Evidence linked to DMS

    Upload or link supporting documents through Document Hub (versioned, hashed, category-tagged). Evidence attaches to the metric and year — ready for peer-team review, not a ZIP on a pen drive.

    Why it helps
    Every claim has a retrievable file; versions stay when someone uploads a corrected MoU.
    Where you use it
    For feedback system metrics, IQAC links the analysis report and action-taken PDF directly on the metric card.
  • Institution accreditation profile

    AISHE code, cycle, grade, validity window, intent, and lifecycle phase (draft through reaccreditation) live beside the SSR pack for IQAC and leadership.

    Why it helps
    Leadership always knows cycle status and when validity expires — without asking IQAC in WhatsApp.
    Where you use it
    Principal dashboard shows Cycle 3, grade, and “SSR draft” phase while the pack is still under review.
  • SoD review → approve

    IQAC reviews; Principal / Management approves. Same person cannot complete both stages; last editor cannot self-review. Edits after approval reopen the pack with an immutable trail.

    Why it helps
    SSR sign-off meets dual-control expectations; nobody can rubber-stamp their own draft.
    Where you use it
    After metrics freeze, IQAC marks review complete; Principal approves. If Dean edits a number later, the pack returns to draft with a trail entry.
  • ABAC-gated NAAC actions

    Contribute, review, and approve actions are policy-bound — sensitive pack actions can require continuous-auth step-up. Cross-tenant access is denied by design.

    Why it helps
    Only the right roles touch accreditation content; sensitive approve can demand step-up.
    Where you use it
    HOD contributes C2 narratives; only IQAC can review; only Principal/Management can approve — another college on the platform cannot see the pack.
  • Criterion export packs

    Export NAAC criterion packs for offline review and assessor handoff — structured JSON / CSV from live responses, not a last-minute Word merge.

    Why it helps
    Offline reviewers and peer-team prep get consistent extracts from the same source of truth.
    Where you use it
    IQAC exports Criterion 3 research pack as CSV for an external consultant the week before the visit.

Pack lifecycle

  1. Draft metrics

    IQAC / Deans / HODs fill QnM and QlM responses; autofill from ERP where available.

  2. Attach evidence

    Link Document Hub files to each metric — programme lists, SSS data, MoUs, IQAC minutes.

  3. IQAC review

    SoD stage one: IQAC Coordinator reviews the pack; last editor cannot self-review.

  4. Leadership approve

    Principal or Management finalises — a different actor from the reviewer — with an immutable trail.

Why this matters

Accreditation data from live operations

Faculty profiles, enrolment, research, infrastructure, and governance metrics already sit in HCM, SIS, Campus Ops, and Financials. The NAAC workspace connects those sources to criterion metrics, attaches Document Hub evidence, and gates final submission with the same SoD / ABAC engines used for sensitive access grants.

Result: fewer last-minute scrambles before peer-team visits — and an audit trail assessors and IQAC can both trust.

Book an NAAC workspace walkthrough →

DPDP

Data subject access requests

Under India's Digital Personal Data Protection Act, individuals may request access, correction, or erasure of personal data. Institutions remain the data fiduciary; Tuling acts as a data processor for tenant-hosted records. We support institutions in fulfilling DSARs within the tenant boundary.

Read our Privacy Policy →
  1. Request logged

    Institution submits a DSAR through the designated admin contact or support channel.

  2. Identity verified

    We verify the requestor is authorised to act on behalf of the data subject or institution.

  3. Scope & timeline

    We confirm data categories in scope and provide an estimated completion window per DPDP timelines.

  4. Fulfillment

    Export, correction, or erasure is executed within the tenant boundary and confirmed to the institution.

Operations

IT Admin desk

Campus IT teams manage tenants, entitlements, integrations, API keys, JIT grants, session assurance, and policy decision audit from the IT Admin desk — the control plane that complements the security architecture on this page.

For NAAC SSR, DPDP, POSH, and statutory desks in one place, see the Compliance hub.

Need a vendor security or NAAC review?

We provide architecture summaries, access-control walkthroughs, and compliance documentation for procurement committees and IQAC.

Talk to our team