Executive Summary & Vision
NexusOne is a unified K-12 School Operating System delivered as a multi-tenant SaaS platform — managing every operational, academic, administrative, financial, and developmental activity within a school from a single integrated system.
Part I — Functional Documentation
1. Overview
Unlike traditional School ERPs that focus narrowly on student records and fee management, NexusOne provides a complete digital ecosystem connecting school management, learning management, admissions, parent engagement, student development, institutional operations, analytics, and AI-assisted teaching under one roof.
The platform is built around five foundational principles and is intended to become the central digital infrastructure for private K-12 schools across India and beyond.
2. Strategic Objectives
| # | Objective | Key Success Metrics |
|---|---|---|
| 1 | Digitize school operations | 90% reduction in manual paperwork; 80% digital adoption |
| 2 | Increase parent engagement | Monthly active parents; notification open rate; WhatsApp interaction rate |
| 3 | Improve teacher productivity | Reduced administrative effort; faster grading; faster report generation |
| 4 | Improve admissions conversion | Lead conversion rate; enrollment growth |
| 5 | Build student portfolios | Achievement tracking; participation tracking |
Platform-level health is also tracked through schools onboarded, monthly active schools, and retention rate.
3. Product Philosophy — Five Principles
Principle 1
One Platform
Schools need no separate ERP, LMS, CRM, communication, or analytics tools — NexusOne consolidates everything.
Principle 2
Mobile First
Every critical workflow must function through the mobile app and WhatsApp. Desktop is secondary.
Principle 3
Data Ownership
Schools own their data. NexusOne acts only as a platform provider — not a data custodian with rights over school content.
Principle 4
Identity First
Every person receives a permanent NexusOne ID that follows them across school transfers, role changes, and alumni status.
Principle 5
Growth Beyond Academics
Student success is measured holistically — academics, sports, leadership, creativity, competitions, and community service all count.
Long-Term Vision
NexusOne Lifelong Educational Identity
NexusOne creates a lifelong educational identity for every learner through the NexusOne ID. A student should be able to join a school, transfer schools, participate in activities, build achievements, graduate, and become alumni — all while retaining a continuous digital profile.
4. User Roles & Permissions
Platform Admin
PlatformNexusOne team members — platform governance, tenant management, billing, monitoring.
Super Admin
SchoolSchool owner, trust, or group administrator — school creation, strategic oversight, subscription management.
Admin
SchoolDaily operations, admissions, student and teacher management.
Teacher
SchoolTeaching, assessment, and student engagement.
Accountant
SchoolFee collection and financial reporting.
Librarian
SchoolLibrary operations — catalogue, issue, return, overdue tracking.
Facilities Manager
SchoolAsset management and maintenance.
Driver
SchoolTransport operations — trips, pickups, dropoffs, SOS.
Parent
SchoolProgress monitoring, fee payment, transport tracking.
Student
SchoolLearning participation — courses, quizzes, assignments.
5. Core Workflows
School Onboarding
- 1Super Admin registers school on the platform
- 2Platform Admin verifies and approves school
- 3School selects a subscription plan
- 4School completes configuration (campus, academic year, classes, subjects)
- 5School goes live
Daily Academic Workflow
- 1Teachers mark attendance for assigned sections
- 2Students access assignments and course content via LMS
- 3Parents receive real-time notifications via app or WhatsApp
- 4Admins manage operations from a central dashboard
Admissions Workflow
- 1Leads captured via CRM or inquiry forms
- 2Counselors follow up and schedule assessments
- 3Successful applicants are enrolled and issued NexusOne IDs
- 4Parent and student accounts are activated
6. Business Rules & Constraints
- Every school's data is logically isolated — no cross-tenant visibility is permitted.
- Platform Admin has visibility across all tenants but cannot alter academic records without audit logging.
- Every person on the platform receives exactly one NexusOne ID that never changes.
- Schools must be approved by Platform Admin before going live.
- A school must have an active subscription to access protected modules.
- Schools can be in one of: Draft, Pending Approval, Active, Suspended, Closed.
7. External Integrations
| Integration | Purpose | Status |
|---|---|---|
| Google Generative AI | AI insights, lesson generation, essay grading | Active |
| Cloudinary | Media storage — logos, documents, profile photos | Active |
| Dodo Payments | Subscription billing | Active |
| Judge0 | Code execution in Programming Lab | Active |
| Socket.io | Real-time messaging and notifications | Active |
| VAPID / Web Push | Browser push notifications | Active |
| Resend / SendGrid | Transactional email delivery | Active |
| Parent and student engagement via WhatsApp | Active |
Part II — Technical Documentation
8. Core Data Models
| Entity | Collection | Key Fields |
|---|---|---|
| User | users | _id · nexusOneId · name · email · role · school · schools[] |
| School | schools | _id · name · slug · status · subscription · createdBy |
| Student | students | _id · user(ref) · school(ref) · admissionNumber · class · section |
| Class | classes | _id · school · name · section · academicYear · teacher(ref) |
| Course | courses | _id · school · title · subject · teacher(ref) · enrollments[] |
| Attendance | attendances | _id · school · class · date · records[{student, status}] |
| Fee | fees | _id · school · student(ref) · amount · dueDate · paidAt · status |
| Notification | notifications | _id · school · recipient(ref) · type · title · read · createdAt |
All school-scoped entities carry a school field used by middleware to enforce tenant isolation. The nexusOneId on User is globally unique and never changes across school transfers.
9. API Endpoints
Health & System
/api/healthPlatform health status, version, environment/api/test-cloudinaryTests Cloudinary media storage connectivityAuthentication
/api/auth/loginEmail/password login — returns JWT tokens/api/auth/registerRegister a new user account/api/auth/forgot-passwordTrigger password reset email/api/auth/reset-passwordReset password via token/api/auth/refreshRefresh access token using refresh token/api/auth/logoutRevoke tokens and end sessionPlatform Admin
/api/platform-admin/dashboardPlatform-level statistics/api/platform-admin/schoolsList all schools across all tenants/api/platform-admin/schools/:id/verifyApprove or reject a school/api/platform-admin/subscriptionsView all subscriptionsSchool Registration (Public)
/api/school-registrationSubmit school registration/api/schools/public/:idPublic school info for admission forms10. Backend Services
| Service | File | Purpose |
|---|---|---|
| Trial Reminders | services/trialReminderCron.js | Scheduled reminders before trial expiry |
| Admission Follow-ups | services/admissionFollowUpCron.js | Cron for CRM follow-up actions |
| Overdue Reminders | services/overdueReminderService.js | Fee overdue notifications |
| Fee Reminders | services/feeReminderCron.js | Scheduled fee reminder emails |
| Data Retention | services/dataRetentionService.js | GDPR-compliant data retention scheduling |
| Hardware Consent | services/hardwareConsentCron.js | Annual consent renewal reminders |
Middleware Stack (order of application)
- 1Helmet — HTTP security headers with cross-origin resource policy
- 2CORS — Origin whitelist; production allows nexus-one.in only
- 3Morgan — HTTP request logging (development only, errors only)
- 4Payment webhook bypass — /api/payments registered before body parser
- 5JSON body parser — 1 MB limit
- 6MongoDB operator injection sanitizer — strips $-prefixed keys from req.body
- 7resolveActiveSchool — resolves school context from token
- 8Rate limiters — authLimiter (10 req/15 min), apiLimiter (120 req/min)
- 9Route handlers
14. Security & Access Control
Authentication
- JWT-based stateless authentication (access + refresh token)
- Token revocation via RevokedToken model for logout
- Password hashing with bcryptjs (salt rounds: 12)
- Password reset via crypto-generated tokens (1-hour expiry)
Transport Security
- Helmet middleware enforces strict HTTP security headers
- CORS whitelist — production restricts to nexus-one.in
- MongoDB operator injection sanitization
- Tenant isolation via school-scoped queries on all protected routes
Rate Limiting
| Limiter | Window | Max Requests | Applied To |
|---|---|---|---|
| Auth Limiter | 15 min | 10 | /api/auth |
| API Limiter | 1 min | 120 | All /api routes |
| Forgot Password Limiter | 60 min | 3 | Password reset endpoint |
| Signal Batch Limiter | 1 min | 5 | AI signal ingest (per device token) |
| Webhook Limiter | 1 min | 200 | Payment webhooks |
| Magic Link Limiter | 15 min | 5 | Magic link endpoints |
11. Frontend Route Groups
| Route Group | Path Pattern | Roles |
|---|---|---|
| Auth | /(auth)/* | Public (unauthenticated) |
| Student Dashboard | /dashboard/student/* | student |
| Parent Dashboard | /dashboard/parent/* | parent |
| Teacher Dashboard | /dashboard/teacher/* | teacher |
| Admin | /dashboard/admin/* | admin — accountant and facilities_admin also use nested admin sub-routes (e.g. /dashboard/admin/fees, /dashboard/admin/facilities) |
| Super Admin | /dashboard/super-admin/* | super_admin |
| Platform Admin | /dashboard/platform-admin/* | platform_admin |
| Librarian | /dashboard/librarian/* | librarian |
| Driver | /dashboard/driver/* | driver |
| Profile & Account | /dashboard/profile/* | All authenticated roles |
| Documentation | /documentation/* | Public |
Role-based routing is enforced by the root index.tsx entry screen — on cold start, the stored user role determines which route group the app navigates to. On the web, Next.js middleware gates protected segments.
12. Mobile Screens
Login
ActiveEmail/password login with biometric (Face ID / fingerprint) support
Student Dashboard
ActiveCourse list, attendance summary, quick actions
Parent Dashboard
ActiveChild progress, fee reminders, transport tracking
Teacher Dashboard
ActiveAttendance marking, courses, assignments
Notification Center
ActiveAll in-app notifications with read/unread state
Growth Passport Viewer
ActiveStudent achievement portfolio, timeline, goals, projects
13. Integration Points
| Provider | Purpose | Direction | Status |
|---|---|---|---|
| Google Generative AI | AI lesson generation, essay grading, insights | Outbound API | Active |
| Cloudinary | Media upload/delivery — logos, photos, documents | Outbound API | Active |
| Dodo Payments | Subscription billing and payment processing | Outbound + Webhook | Active |
| Judge0 | Sandboxed code execution for Programming Lab | Outbound API | Active |
| Socket.io | Real-time bi-directional messaging and notifications | In-process | Active |
| VAPID / Web Push | Browser push notification delivery | Outbound push | Active |
| Resend / SendGrid | Transactional email delivery | Outbound SMTP/API | Active |
| WhatsApp API | Parent and student engagement via WhatsApp messages | Outbound API | Active |
| CSV / Excel Export | Bulk data exports for reports, fee lists, student data | In-process | Active |
15. Performance & Scalability
MongoDB Indexing Strategy
- Compound index on (school, createdAt DESC) for all school-scoped queries
- Unique index on users.nexusOneId for global identity lookups
- Index on (school, student, date) for attendance queries
- Index on (school, dueDate, status) for fee collection queries
- TTL index on revokedTokens.expiresAt for automatic cleanup
Scalability Path
- Lean queries (.lean()) on read-heavy endpoints to return plain objects
- select() projection to limit returned fields on large collections
- Socket.io horizontal scaling via Redis adapter (planned)
- Cloudinary CDN eliminates media bandwidth from origin server
- Rate limiters (120 req/min per IP) protect against traffic spikes
- School-scoped indexes ensure queries never scan cross-tenant data