Running a School

How School Records Get Quietly Changed, and How to Catch It

A changed grade, a deleted payment, a discount nobody approved. Most school record disputes cannot be resolved because nothing recorded who did what. An audit trail settles them in seconds.

Shepherd Yaw Morttey
7 min read

A parent arrives at the office in November holding a receipt. They paid GHS 1,200 in September. The system says they owe it.

Somebody eventually works out what happened: the payment was entered against a sibling, noticed a week later, deleted, and re-entered. Except only the deletion happened. Nobody can prove any of this, because there is no record of the deletion, of who did it, or of the original entry. The school refunds a payment it may or may not have received, and quietly stops trusting one of its staff.

This is the ordinary version of a school records problem. It is not dramatic and it is not usually theft. It is that nobody can reconstruct what happened, so the dispute is settled by whoever is more insistent.

The three changes that cause trouble

School data has thousands of legitimate changes a term. Three categories cause nearly all the disputes.

Marks

A grade changes between the teacher entering it and the report card printing. Usually for a good reason: a marking error, a missed script, a late submission the teacher agreed to accept.

Occasionally not. A child's mark improves after a conversation with a parent. A borderline aggregate moves just far enough. These are rare and they are exactly the cases where the school needs to be able to demonstrate what happened, both to defend a teacher who did nothing wrong and to establish what did occur when something was.

Without a record, every version of the story is equally credible.

Money

Payments entered, edited, deleted. Discounts applied that nobody remembers approving. A bill amount changed after it went out.

The specific pattern worth understanding is the deleted payment. A member of staff takes a cash payment, enters it so the parent sees a receipt on their phone, then deletes the entry once the parent has left. The money is gone, the parent believes they have paid, and the school's records show an outstanding balance. It surfaces months later as a dispute the school assumes the parent is confused about.

This is the single most common form of school finance fraud in this market, and it is entirely dependent on deletion being possible.

Student records

A class changed, an exit reversed, a guardian phone number replaced. Individually mundane, occasionally consequential. A guardian contact quietly changed to a different number is how a child ends up collected by someone the school never authorised.

What an audit trail actually needs to do

"We have logs" is not the same as having an audit trail. Four properties separate one from the other.

It records changes, not just logins. Knowing that a user signed in at 9:04am is nearly useless. Knowing that they changed a mark from 58 to 72 at 9:11am is the whole point.

It records the before and the after. A log saying "grade updated" tells you nothing. A record showing the old value and the new one settles the question immediately.

It is attributable to a person. Not to a role, not to "admin", but to a named user account. Which in turn means shared logins destroy the value of the entire system, and are worth eliminating before anything else.

It cannot be edited by the people it records. If an administrator can delete log entries, the log documents only the changes nobody wanted to hide. This is the property most often missing.

To those four, add a fifth that is specific to money: destructive actions should not exist. A payment should be voided rather than deleted, with the original preserved alongside the void, the reason and the person responsible. A trail that faithfully records a deletion is better than nothing, but a system where the deletion is impossible is better still. We cover the finance side of this in where school money quietly goes missing.

The argument against, and why it is wrong

School owners often hesitate here, and the hesitation is usually some version of "my staff will feel I do not trust them."

It is worth turning that around, because the effect in practice is the reverse.

When something goes wrong in a school with no records, suspicion does not land nowhere. It lands on whoever had access, which usually means the bursar and the secretary, who are also usually the longest-serving and most trusted people in the building. They have no way to demonstrate they did nothing, because nothing was recorded either way. Plenty of good staff have left schools over an unresolvable accusation.

An audit trail resolves those in seconds and almost always in the staff member's favour, because the overwhelming majority of the time the change was legitimate and the trail shows it. The honest bursar is the main beneficiary.

The deterrent effect is real too, and it is worth being straightforward about with staff rather than quiet. A team that knows changes are recorded behaves differently from one that assumes they are not, and saying so openly is more respectful than surveillance nobody mentioned.

Making it useful rather than decorative

Most audit trails are never read. A log that exists but is never opened provides evidence after a crisis and no deterrent before one. Three habits change that.

Review voids monthly. Not looking for fraud, just looking. Ten minutes on the list of voided payments and applied discounts. The review being known to happen is most of the value.

Check the trail during disputes, first. Before phoning the parent, before asking the staff member. It is usually faster and it means the conversation starts from facts.

Filter rather than scroll. A useful trail can be narrowed by what was changed, what kind of change it was, and who did it. Scrolling a chronological feed of every change in a school is how audit trails become decorative.

Support access is part of this

One gap worth closing deliberately. When a software vendor's support staff log in to investigate a problem, they frequently do so as the school's user, which means their actions appear in the record as the school's staff member.

That is a real hole. Actions taken during support should be attributable to the person who actually took them, recorded as support access rather than disguised as the school. Ask any vendor how they handle it, because most do not.

How SwiftSapp handles it

Changes to students, bills, payments, marks, report cards, discounts, credits, staff profiles and payroll are versioned, keeping the previous and new values along with the user responsible and the time.

Alongside that, a separate event log records actions that are not simple field changes: logins, support access, exports and administrative operations. Both feed one audit view, filtered by resource type, action, source and user, so a question about one bill does not mean reading a term of history.

Money cannot be destroyed. Payments, refunds, credits and credit applications are voided rather than deleted, keeping the original, the void reason and the person responsible. Approved payroll runs lock, so a month that has been paid cannot be quietly rewritten afterwards.

Support access is recorded as itself, so anything done while assisting your school is attributable rather than appearing as one of your staff.

If you have an unresolved dispute in your school right now, it is probably unresolvable because nothing recorded what happened. Book a demo and we will look at how the trail would have answered it.

Written by
Shepherd Yaw Morttey

Builds SwiftSapp, a school management system for Ghanaian schools.

Frequently asked questions

What is an audit trail in a school management system?

A record of every change to a mark, a bill, a payment or a student record, showing what changed, when, and which user made the change. It turns disputes into a lookup instead of an argument.

Does an audit trail mean we do not trust our staff?

It means the opposite in practice. Without a record, suspicion falls on whoever had access. A trail protects the honest staff member far more often than it catches a dishonest one.

Can an administrator delete the audit trail?

They should not be able to. If the log can be edited by the people it records, it is documentation rather than evidence. The same applies to deleting payments instead of voiding them.

How does this help when a parent disputes a payment?

You can show exactly what was recorded, when, by whom, and whether anything was later voided or reallocated. Most disputes end there, because the parent is usually right about paying and wrong about which bill it went to.

What about staff logging in as someone else to check something?

Support access should be recorded as itself rather than disguised as the user being helped, so actions taken while assisting are attributable to the person who actually took them.

See SwiftSapp in action.

Fully partner-subsidised for Ghanaian schools — GHS 0, no locked features, free assisted onboarding.