Business Architecture
NexusOne is a shared-database, school-scoped multi-tenant SaaS platform. This chapter covers the seven-level platform hierarchy, the permanent NexusOne identity every person receives, the school verification and subscription lifecycle (including the Basic/Elite tier gate used across the whole product), and how Platform Admins and Super Admins oversee schools. All features below are available on the Basic tier — there is no separate Elite tier at the business-architecture layer itself.
Basic Tier Features
BasicPlatform Hierarchy
- Seven-level tree: Platform → Super Admin → School → Campus → Academic Year → Class/Section → Student
- Platform Admin has cross-tenant visibility; every other role is scoped to its own school(s)
- A Super Admin can own and operate multiple School documents, each independently verified and subscribed
- Multi-campus support: reporting is available at campus, school, and group level
Multi-Tenant School Model
- Shared-database, school-scoped isolation — every document in every collection carries a school (ObjectId) field
- getSchoolFilter(req) returns {} for platform_admin, { school: { $in: user.schools } } for super_admin, and { school: user.school } for everyone else
- School lifecycle: verificationStatus pending → verified → rejected, set by Platform Admin
- registrationType tracks whether a school was self_registered or admin_created
NexusOne ID
- Implemented — every user gets a permanent, sequential nexusOneId (format NX-000000001) from the NexusIdCounter model
- Assigned automatically in the User pre('save') hook on first creation; never reused, never editable
- Follows the person across school transfers, role changes, and future alumni conversion
Multi-School & Multi-Role Users
- school (active/primary) and schools[] (full history) are kept in sync by a pre-save hook
- belongsToSchool() and validateSchoolAccess() middleware enforce that a user only touches schools in their schools[] array
- A single user account can hold roles across school history (e.g. teacher who transferred schools) while keeping one NexusOne ID
Subscription & Billing
- One Subscription document per school: plan (monthly/quarterly/yearly), tier (basic/elite), status, and a Dodo Payments transaction history
- 90-day free trial via Subscription.activateTrial() — access remains open until trialEndsAt even if the user cancels mid-trial
- checkSubscriptionAccess middleware gates every protected route: school must be verified and the subscription must be active, cancelled-but-in-period, or trialing
- checkEliteTier middleware (runs after checkSubscriptionAccess) additionally requires subscription.tier === 'elite' — this is the actual Basic/Elite gate used across the whole platform
- Dodo Payments webhook listener is registered at /api/payments before the JSON body parser so signatures can be verified on the raw body
School Branding
- Per-school logo, favicon, brand name, color palette (primary/secondary/accent/sidebar), and heading/body fonts stored on School.branding
- Branding routes require authentication only (no subscription check) so the UI can render correctly even before a school is verified or subscribed
Platform & Super Admin Oversight
- Platform Admin dashboard aggregates schools, users, students, teachers, courses, enrollments, and 30-day growth — via a single aggregation pipeline, not per-school queries
- Platform Admin creates Super Admin accounts and grants/revokes which schools each Super Admin can access
- Super Admin dashboard: owned schools, school admins, cross-school users, analytics, and school creation
- Every school verification, role change, and multi-school grant is written to AuditLog / ActivityLog
API Reference — Chapter 2
School Registration & Management
/api/school-registration/registerSubmit a school for platform verification (public)
/api/school-registration/pendingList schools awaiting verification (super_admin, platform_admin)
/api/school-registration/approve/:schoolIdApprove a pending school
/api/school-registration/reject/:schoolIdReject a pending school
/api/schools/public/:idPublic school info for admission forms
/api/schoolsList schools (scoped to requesting user)
/api/schools/:idUpdate school profile (admin)
Subscription & Billing
/api/subscriptionsGet subscription status for the current school
/api/subscriptions/trialStart the 90-day free trial
/api/subscriptions/cancel-trialCancel trial — retains access until trialEndsAt
/api/subscriptions/checkoutInitiate a Dodo Payments checkout session
/api/paymentsDodo Payments webhook handler (mounted before the body parser)
Super Admin
/api/super-admin/dashboard/statsAggregated stats across owned schools
/api/super-admin/schools/overviewOwned schools with per-school user counts
/api/super-admin/school-adminsList school admins across owned schools
/api/super-admin/school-adminsCreate a school admin account
/api/super-admin/usersList users across owned schools
Platform Admin
/api/platform-admin/dashboardPlatform-wide aggregate statistics
/api/platform-admin/schoolsList all schools across all tenants
/api/platform-admin/schools/:id/verifyApprove or reject a school
/api/platform-admin/school-verificationsList schools pending verification
/api/platform-admin/super-adminsCreate a Super Admin account
/api/platform-admin/super-admins/:id/schoolsGrant a Super Admin access to a school
/api/platform-admin/super-admins/:id/schools/:schoolIdRevoke a Super Admin's access to a school
/api/platform-admin/subscriptionsView all subscriptions across all schools
Branding
/api/schools/:id/brandingGet school branding (logo, colors, fonts) — no subscription check
/api/schools/:id/brandingUpdate school branding
Frontend Pages
| Path | Role | Description | Tier |
|---|---|---|---|
| /register-school | Public | Informational — self-registration is disabled; directs to Super Admin | Basic |
| /register-platform-admin | Public | One-time bootstrap: creates the platform_admin account when the database has no users yet | Basic |
| /subscription | Admin / Super Admin | Plan selection, trial start, checkout | Basic |
| /subscription/success | Admin / Super Admin | Post-checkout confirmation | Basic |
| /subscription/trial-success | Admin / Super Admin | Trial activation confirmation | Basic |
| /subscription/cancel | Admin / Super Admin | Checkout cancelled screen | Basic |
| /dashboard/super-admin | Super Admin | Multi-school overview, recent activity | Basic |
| /dashboard/super-admin/schools | Super Admin | List / create / edit owned schools | Basic |
| /dashboard/super-admin/school-admins | Super Admin | Create and manage school admin accounts | Basic |
| /dashboard/super-admin/school-verifications | Super Admin | Track verification status of owned schools | Basic |
| /dashboard/super-admin/users | Super Admin | Users across all owned schools | Basic |
| /dashboard/super-admin/settings | Super Admin | Group-level settings | Basic |
| /dashboard/platform-admin | Platform Admin | Platform-wide statistics and health | Basic |
| /dashboard/platform-admin/schools | Platform Admin | All schools across all tenants | Basic |
| /dashboard/platform-admin/school-verifications | Platform Admin | Approve or reject pending schools | Basic |
| /dashboard/platform-admin/super-admins | Platform Admin | Create Super Admins, grant/revoke school access | Basic |
| /dashboard/admin/branding | Admin | School logo, colors, fonts | Basic |
Mobile Screens
(platform-admin)/index(platform-admin)/schools(platform-admin)/super-admins(platform-admin)/school-assignment(platform-admin)/subscriptions(admin)/subscription-status