Chapter 01/Executive Summary & Vision

Executive Summary & Vision

NexusOne is a unified K-12 School Operating System delivered as a multi-tenant SaaS platform — managing every operational, academic, administrative, financial, and developmental activity within a school from a single integrated system.

Chapter 1 of 25v1.0Specification

Part I — Functional Documentation

1. Overview

Unlike traditional School ERPs that focus narrowly on student records and fee management, NexusOne provides a complete digital ecosystem connecting school management, learning management, admissions, parent engagement, student development, institutional operations, analytics, and AI-assisted teaching under one roof.

The platform is built around five foundational principles and is intended to become the central digital infrastructure for private K-12 schools across India and beyond.

2. Strategic Objectives

#ObjectiveKey Success Metrics
1Digitize school operations90% reduction in manual paperwork; 80% digital adoption
2Increase parent engagementMonthly active parents; notification open rate; WhatsApp interaction rate
3Improve teacher productivityReduced administrative effort; faster grading; faster report generation
4Improve admissions conversionLead conversion rate; enrollment growth
5Build student portfoliosAchievement tracking; participation tracking

Platform-level health is also tracked through schools onboarded, monthly active schools, and retention rate.

3. Product Philosophy — Five Principles

Principle 1

One Platform

Schools need no separate ERP, LMS, CRM, communication, or analytics tools — NexusOne consolidates everything.

Principle 2

Mobile First

Every critical workflow must function through the mobile app and WhatsApp. Desktop is secondary.

Principle 3

Data Ownership

Schools own their data. NexusOne acts only as a platform provider — not a data custodian with rights over school content.

Principle 4

Identity First

Every person receives a permanent NexusOne ID that follows them across school transfers, role changes, and alumni status.

Principle 5

Growth Beyond Academics

Student success is measured holistically — academics, sports, leadership, creativity, competitions, and community service all count.

Long-Term Vision

NexusOne Lifelong Educational Identity

NexusOne creates a lifelong educational identity for every learner through the NexusOne ID. A student should be able to join a school, transfer schools, participate in activities, build achievements, graduate, and become alumni — all while retaining a continuous digital profile.

4. User Roles & Permissions

Platform Admin

Platform

NexusOne team members — platform governance, tenant management, billing, monitoring.

Super Admin

School

School owner, trust, or group administrator — school creation, strategic oversight, subscription management.

Admin

School

Daily operations, admissions, student and teacher management.

Teacher

School

Teaching, assessment, and student engagement.

Accountant

School

Fee collection and financial reporting.

Librarian

School

Library operations — catalogue, issue, return, overdue tracking.

Facilities Manager

School

Asset management and maintenance.

Driver

School

Transport operations — trips, pickups, dropoffs, SOS.

Parent

School

Progress monitoring, fee payment, transport tracking.

Student

School

Learning participation — courses, quizzes, assignments.

5. Core Workflows

School Onboarding

  1. 1Super Admin registers school on the platform
  2. 2Platform Admin verifies and approves school
  3. 3School selects a subscription plan
  4. 4School completes configuration (campus, academic year, classes, subjects)
  5. 5School goes live

Daily Academic Workflow

  1. 1Teachers mark attendance for assigned sections
  2. 2Students access assignments and course content via LMS
  3. 3Parents receive real-time notifications via app or WhatsApp
  4. 4Admins manage operations from a central dashboard

Admissions Workflow

  1. 1Leads captured via CRM or inquiry forms
  2. 2Counselors follow up and schedule assessments
  3. 3Successful applicants are enrolled and issued NexusOne IDs
  4. 4Parent and student accounts are activated

6. Business Rules & Constraints

  • Every school's data is logically isolated — no cross-tenant visibility is permitted.
  • Platform Admin has visibility across all tenants but cannot alter academic records without audit logging.
  • Every person on the platform receives exactly one NexusOne ID that never changes.
  • Schools must be approved by Platform Admin before going live.
  • A school must have an active subscription to access protected modules.
  • Schools can be in one of: Draft, Pending Approval, Active, Suspended, Closed.

7. External Integrations

IntegrationPurposeStatus
Google Generative AIAI insights, lesson generation, essay gradingActive
CloudinaryMedia storage — logos, documents, profile photosActive
Dodo PaymentsSubscription billingActive
Judge0Code execution in Programming LabActive
Socket.ioReal-time messaging and notificationsActive
VAPID / Web PushBrowser push notificationsActive
Resend / SendGridTransactional email deliveryActive
WhatsAppParent and student engagement via WhatsAppActive

Part II — Technical Documentation

8. Core Data Models

EntityCollectionKey Fields
Userusers_id · nexusOneId · name · email · role · school · schools[]
Schoolschools_id · name · slug · status · subscription · createdBy
Studentstudents_id · user(ref) · school(ref) · admissionNumber · class · section
Classclasses_id · school · name · section · academicYear · teacher(ref)
Coursecourses_id · school · title · subject · teacher(ref) · enrollments[]
Attendanceattendances_id · school · class · date · records[{student, status}]
Feefees_id · school · student(ref) · amount · dueDate · paidAt · status
Notificationnotifications_id · school · recipient(ref) · type · title · read · createdAt

All school-scoped entities carry a school field used by middleware to enforce tenant isolation. The nexusOneId on User is globally unique and never changes across school transfers.

9. API Endpoints

Health & System

GET/api/healthPlatform health status, version, environment
GET/api/test-cloudinaryTests Cloudinary media storage connectivity

Authentication

POST/api/auth/loginEmail/password login — returns JWT tokens
POST/api/auth/registerRegister a new user account
POST/api/auth/forgot-passwordTrigger password reset email
POST/api/auth/reset-passwordReset password via token
POST/api/auth/refreshRefresh access token using refresh token
POST/api/auth/logoutRevoke tokens and end session

Platform Admin

GET/api/platform-admin/dashboardPlatform-level statistics
GET/api/platform-admin/schoolsList all schools across all tenants
PUT/api/platform-admin/schools/:id/verifyApprove or reject a school
GET/api/platform-admin/subscriptionsView all subscriptions

School Registration (Public)

POST/api/school-registrationSubmit school registration
GET/api/schools/public/:idPublic school info for admission forms

10. Backend Services

ServiceFilePurpose
Trial Remindersservices/trialReminderCron.jsScheduled reminders before trial expiry
Admission Follow-upsservices/admissionFollowUpCron.jsCron for CRM follow-up actions
Overdue Remindersservices/overdueReminderService.jsFee overdue notifications
Fee Remindersservices/feeReminderCron.jsScheduled fee reminder emails
Data Retentionservices/dataRetentionService.jsGDPR-compliant data retention scheduling
Hardware Consentservices/hardwareConsentCron.jsAnnual consent renewal reminders

Middleware Stack (order of application)

  1. 1Helmet — HTTP security headers with cross-origin resource policy
  2. 2CORS — Origin whitelist; production allows nexus-one.in only
  3. 3Morgan — HTTP request logging (development only, errors only)
  4. 4Payment webhook bypass — /api/payments registered before body parser
  5. 5JSON body parser — 1 MB limit
  6. 6MongoDB operator injection sanitizer — strips $-prefixed keys from req.body
  7. 7resolveActiveSchool — resolves school context from token
  8. 8Rate limiters — authLimiter (10 req/15 min), apiLimiter (120 req/min)
  9. 9Route handlers

14. Security & Access Control

Authentication

  • JWT-based stateless authentication (access + refresh token)
  • Token revocation via RevokedToken model for logout
  • Password hashing with bcryptjs (salt rounds: 12)
  • Password reset via crypto-generated tokens (1-hour expiry)

Transport Security

  • Helmet middleware enforces strict HTTP security headers
  • CORS whitelist — production restricts to nexus-one.in
  • MongoDB operator injection sanitization
  • Tenant isolation via school-scoped queries on all protected routes

Rate Limiting

LimiterWindowMax RequestsApplied To
Auth Limiter15 min10/api/auth
API Limiter1 min120All /api routes
Forgot Password Limiter60 min3Password reset endpoint
Signal Batch Limiter1 min5AI signal ingest (per device token)
Webhook Limiter1 min200Payment webhooks
Magic Link Limiter15 min5Magic link endpoints

11. Frontend Route Groups

Route GroupPath PatternRoles
Auth/(auth)/*Public (unauthenticated)
Student Dashboard/dashboard/student/*student
Parent Dashboard/dashboard/parent/*parent
Teacher Dashboard/dashboard/teacher/*teacher
Admin/dashboard/admin/*admin — accountant and facilities_admin also use nested admin sub-routes (e.g. /dashboard/admin/fees, /dashboard/admin/facilities)
Super Admin/dashboard/super-admin/*super_admin
Platform Admin/dashboard/platform-admin/*platform_admin
Librarian/dashboard/librarian/*librarian
Driver/dashboard/driver/*driver
Profile & Account/dashboard/profile/*All authenticated roles
Documentation/documentation/*Public

Role-based routing is enforced by the root index.tsx entry screen — on cold start, the stored user role determines which route group the app navigates to. On the web, Next.js middleware gates protected segments.

12. Mobile Screens

Platform: React Native / Expo — single codebase for Android and iOS.

Login

Active

Email/password login with biometric (Face ID / fingerprint) support

Student Dashboard

Active

Course list, attendance summary, quick actions

Parent Dashboard

Active

Child progress, fee reminders, transport tracking

Teacher Dashboard

Active

Attendance marking, courses, assignments

Notification Center

Active

All in-app notifications with read/unread state

Growth Passport Viewer

Active

Student achievement portfolio, timeline, goals, projects

13. Integration Points

ProviderPurposeDirectionStatus
Google Generative AIAI lesson generation, essay grading, insightsOutbound APIActive
CloudinaryMedia upload/delivery — logos, photos, documentsOutbound APIActive
Dodo PaymentsSubscription billing and payment processingOutbound + WebhookActive
Judge0Sandboxed code execution for Programming LabOutbound APIActive
Socket.ioReal-time bi-directional messaging and notificationsIn-processActive
VAPID / Web PushBrowser push notification deliveryOutbound pushActive
Resend / SendGridTransactional email deliveryOutbound SMTP/APIActive
WhatsApp APIParent and student engagement via WhatsApp messagesOutbound APIActive
CSV / Excel ExportBulk data exports for reports, fee lists, student dataIn-processActive

15. Performance & Scalability

MongoDB Indexing Strategy

  • Compound index on (school, createdAt DESC) for all school-scoped queries
  • Unique index on users.nexusOneId for global identity lookups
  • Index on (school, student, date) for attendance queries
  • Index on (school, dueDate, status) for fee collection queries
  • TTL index on revokedTokens.expiresAt for automatic cleanup

Scalability Path

  • Lean queries (.lean()) on read-heavy endpoints to return plain objects
  • select() projection to limit returned fields on large collections
  • Socket.io horizontal scaling via Redis adapter (planned)
  • Cloudinary CDN eliminates media bandwidth from origin server
  • Rate limiters (120 req/min per IP) protect against traffic spikes
  • School-scoped indexes ensure queries never scan cross-tenant data