CH 23Basic

Document Management, Records & Digital Credentials

The centralized, role-controlled repository for every document, record and digital credential in NexusOne — with QR-verified certificates, transcripts and badges. Entirely Basic tier: none of this chapter's functionality is AI-powered, so it ships to every subscribed school regardless of plan.

Implementation note: the LMS course-completion Certificate lifecycle (Chapter 14) was already implemented and is reused as-is. This chapter adds the broader Document, DocumentRequest, DigitalBadge, Transcript and DocumentShare models plus their controllers/routes. Bulk document generation is intentionally kept simple (sequential, not queued) for this pass — see Chapter 22's pattern for a background-job conversion if volume grows. Camera-based QR scanning on mobile is deferred (manual code entry works today) since it would require adding a new native camera dependency not yet present in the app. Digital badges carry an optional Growth Passport track reference but are not yet surfaced inside the Chapter 21 Portfolio/Growth Passport pages themselves — today they're only visible in the Chapter 23 document wallet; cross-linking into the portfolio view is a fast-follow. Document versioning fields exist on the schema, but there's no re-upload/new-version endpoint yet — every upload is version 1.

Features

Document Repository

Basic
  • Six ownership categories: identity, academic, medical, financial, employment, operational, certificate, contract, compliance
  • Full lifecycle: draft → pending review → approved → issued → archived / expired / rejected
  • Cloudinary-backed upload with type/size validation, versioning, and expiry tracking
  • Web UI: /dashboard/documents (self-service wallet) and /dashboard/admin/documents (repository hub)

Document Requests

Basic
  • Students, parents (on behalf of a linked child) and employees submit requests with a reason
  • Admin approval auto-generates the document (bonafide, TC, conduct, study, enrollment, graduation, experience certificates) with merge fields, school branding and an embedded QR code
  • Full notification trail: submitted → reviewed → approved/rejected → issued
  • Web UI: /dashboard/documents/request, /dashboard/admin/documents/requests

QR Verification & Digital Credentials

Basic
  • Every certificate, transcript, document and badge gets a unique 12-char verification code (XXXX-XXXX-XXXX)
  • Public verification portal at nexus-one.in/verify/{code} — no login required, checks all four credential types
  • Revocation returns verified: false with the revocation reason and timestamp, permanently
  • Mobile: manual code-entry verification screen (camera QR scan intentionally deferred — no camera dependency in this app yet)

Digital Badges & Transcripts

Basic
  • Badges: skill, achievement, competency, leadership, certification, with an optional passportTrack field to note the intended Growth Passport (Chapter 21) track
  • Transcripts compiled from ReportCard (Chapter 12) data, rendered to a branded PDF with QR verification
  • Web UI: badges & transcripts shown in /dashboard/documents; Mobile: badge-showcase.tsx

Secure Document Sharing

Basic
  • Time-limited, optionally password-protected share links (max 90 days per business rule)
  • University Sharing Package: bundles transcripts, certificates and documents into one read-only viewer link
  • Admin notified when a share link is accessed; access count and last-accessed timestamp tracked

Document Analytics

Basic
  • Total volume, breakdown by status and category, pending approval queue, expiring-soon count
  • Nightly cron scans for 30/60/90-day expiry windows and auto-marks past-due documents as expired
  • Web UI: /dashboard/admin/documents/analytics

API Reference — Chapter 23

Documents (Basic)

GET/api/documents

List documents — own for self-service roles, child's for parents, school-wide filterable for admins

POST/api/documents/upload

Upload an identity/academic document (Cloudinary)

GET/api/documents/:documentId

Get a single document

GET/api/documents/:documentId/download

Get the download URL

PATCH/api/documents/:documentId/verify

Admin verifies or rejects an uploaded document

PATCH/api/documents/:documentId/archive

Archive a document

POST/api/documents/generate

Admin generates a system document (bonafide, TC, etc.) with QR + merge fields

GET/api/documents/analytics

Volume, status/category breakdown, expiring-soon count

GET/api/documents/verify/:code

Public — verify a document by its code

Document Requests (Basic)

GET/POST/api/document-requests

List / submit a document request

PATCH/api/document-requests/:requestId/approve

Approve — auto-generates the document

PATCH/api/document-requests/:requestId/reject

Reject with a reason

PATCH/api/document-requests/:requestId/cancel

Requester cancels their own pending request

Transcripts & Badges (Basic)

POST/api/transcripts/generate

Compile a term/annual/official transcript from ReportCard data

GET/api/transcripts/:studentId

List a student's transcripts

GET/api/transcripts/verify/:code

Public — verify a transcript

GET/api/badges

List school badges (admin/teacher)

POST/api/badges/issue

Issue a new badge

GET/api/badges/student/:studentId

A student's badges (self, parent of, or staff)

PUT/api/badges/:badgeId/revoke

Revoke a badge

GET/api/badges/verify/:code

Public — verify a badge

Secure Sharing (Basic)

GET/POST/api/documents/share-link

List / create a time-limited (optionally password-protected) share link

PATCH/api/documents/share-link/:id/revoke

Revoke a share link

GET/api/documents/shared/:token

Public — access a shared document package

Certificates — Chapter 14 (Basic, pre-existing)

POST/api/certificates/generate

Student self-generates a course-completion certificate

GET/api/certificates/verify/:verificationCode

Public — verify a certificate

PUT/api/certificates/:certificateId/revoke

Revoke a certificate

Frontend Pages

PathRoleDescriptionTier
/dashboard/documentsStudent / Parent / All StaffDocument wallet — upload, view, badges, my requests, secure sharing (role-adaptive)Basic
/dashboard/documents/requestStudent / Parent / All StaffSubmit a document requestBasic
/dashboard/admin/documentsAdmin / Super AdminRepository hub — verify, archive, generate, issue badgesBasic
/dashboard/admin/documents/requestsAdmin / Super AdminRequest approval queueBasic
/dashboard/admin/documents/analyticsAdmin / Super AdminVolume, issuance & verification trendsBasic
/verify/{code}Public — no loginCredential verification portal (certificate, transcript, document, badge)Basic
/documents/shared/{token}Public — no loginRead-only shared document package viewer (optionally password-protected)Basic

Mobile

Under app/(student)/:documents.tsx (wallet + upload),document-request.tsx,badge-showcase.tsx, andverify-credential.tsx(manual code-entry verification). Under app/(parent)/: a new document-request.tsx to request generated documents for a linked child, alongside the pre-existing documents.tsx(identity-document submission, a separate Chapter-2-era feature built on the StudentDocument model).