>_ ./launch_os.sh --multi-tenant --nodes=campuses

The Intelligent Cloud Operating System for Modern School Networks.

Unify student records, automated fee billing, CBC and board grading, teacher payroll, and parent engagement across all your campuses — powered by ironclad database-kernel data isolation and built-in AI copilots.

session: root@lmsyncd.cloud // active_campus: nairobi-west
[ RLS KERNEL: ENFORCED ]
GROUP DIRECTORS COCKPIT
8 Campuses • 4,820 Students
Zero sync latency • Materialized hierarchical tree
COLLECTIONS RECOVERY
96.8% Settled
Automated waterfall clearing against aged debt
CURRICULUM COMPLIANCE
100% CBC & KNEC Ready
Grades 7–9 KJSEA longitudinal SBA storage active
[ SCREENSHOT PLACEHOLDER — MULTI_CAMPUS_TOPOLOGY.PNG ] Centralized multi-campus dashboard view with instant branch-switching dropdown, consolidated revenue analytics, and cross-campus staff roster.
Multi-Campus Governance: Live branch switcher with zero background database sync.
STANDARDS_&_CURRICULA:
>_ ./diagnose_architecture.sh --audit-school

Traditional school software breaks under real-world operations.

School networks do not fail because of lack of effort — they fail because legacy ERPs force fragile multi-branch sync scripts, allow financial balance drift, and lack national curriculum compliance.

// THE LEGACY SCHOOL SOFTWARE TRAP

  • Multi-Branch Database Trap: Separate databases per campus require fragile background sync scripts that fail silently, stranding student records.
  • Financial Leakage & Stored Balance Discrepancies: Mutable ‘balance’ columns drift out of sync during manual edits, partial payments, or bank reversals.
  • Rigid Western Grading Assumptions: Percentage-only systems fail to model Kenya’s 4-tier ordinal CBC descriptors (EE, ME, AE, BE) and lose 3-year Grade 7–9 KJSEA SBA exam records.
  • Fragile Multi-Tenancy Leaks: Generic SaaS apps rely on Python filters (.filter(school=...)) where one missing query parameter leaks private student data.
  • Disconnected Operational Sprawl: Separate subscriptions for school store inventory, bus routes, teacher payroll, and parent messaging create chaotic reconciliation.

// THE LMSYNCD OPERATING SYSTEM

  • Single Tenant Tree with Zero Sync: All branches operate on one shared database with hierarchical materialized paths, instant campus switching, and zero sync code.
  • Zero-Leakage Computed Balances: Balances are strictly calculated on-the-fly from immutable invoice lines and receipt records with automated waterfall settlement.
  • Native Multi-Board Academic Engine: Built specifically for Kenyan CBC, KNEC 1–7, Pakistani Matric/FSc, and Cambridge with permanent multi-year SBA retention.
  • PostgreSQL Kernel-Level Isolation (RLS): Security sits below the application layer. Every query is scoped by SET LOCAL app.current_tenant_id — a buggy query returns zero rows, never another school’s data.
  • Integrated All-in-One Operations: Built-in School Store POS, Transport Fleet manifests, 1-click Teacher Payroll, and 128-bit cryptographic QR document verification.
>_ ls -la ./modules/core_engine

Engineered for complete administrative relief.

Six production-grade modules designed specifically for school directors, principals, bursars, and teachers.

MODULE_01 // MULTI_CAMPUS

Multi-Campus Governance

Manage single academies or 8+ campus networks under one tenant tree. Group directors switch branches via a live top-bar dropdown. Student transfers preserve full longitudinal academic and billing history with one click.

[ SCREENSHOT: CAMPUS_SWITCHER.PNG ] Live branch selector • Consolidated cross-campus roster • Zero sync code
Multi-Campus Tree: Instant campus switching with zero background sync.
MODULE_02 // BURSAR_FINANCE

Zero-Leakage Bursar Operations

Automated term invoicing, student-specific discounts, and instalment schedules. Bursars close daily drawers in 1 click using the automated Cash-Up sheet (split across M-Pesa, Cash, JazzCash, and Bank) with anti-fraud QR receipts.

[ SCREENSHOT: CASHUP_DRAWER.PNG ] Automated waterfall clearing • 1-click cash-up sheet • 128-bit QR verification
Bursar Cash-Up: Reconcile daily takings across payment channels in seconds.
MODULE_03 // CBC_GRADING

CBC & Multi-Board Grading

Native support for Kenya CBC (EE, ME, AE, BE), KNEC 1–7 scale, Pakistani Matric/FSc percentages, Cambridge O/A Levels, and IB. Preserves multi-year School-Based Assessment (SBA) records across Grades 7–9 for the KJSEA composite exam.

[ SCREENSHOT: CBC_REPORT_STUDIO.PNG ] Data-driven grade scales • Immutable JSON snapshot report cards • Versioned reissues
Grading Studio: Immutable report card snapshots with full historical versioning.
MODULE_04 // AI_STUDIO

AI Copilots & Early-Warning Radar

Empower staff with an AI Remarks Studio generating report card narratives in three distinct tones (Encouraging, Strict, Academic), an Early-Warning Dropout Radar detecting grade/attendance drops, and a Curriculum Homework Generator.

[ SCREENSHOT: AI_COPILOT_STUDIO.PNG ] Tone-controlled remarks • Dropout anomaly radar • Zero reseller API markup
AI Remarks Studio: Three distinct tones with bring-your-own Gemini API key.
MODULE_05 // DAILY_OPS

School Store POS, Fleet & Payroll

Eliminate standalone third-party software. Built-in high-speed Point-of-Sale for uniforms and textbooks with barcode and thermal receipt printing, bus route passenger manifests, and 1-click teacher monthly payroll runs.

[ SCREENSHOT: STORE_POS_PAYROLL.PNG ] Uniforms & books inventory • Bus route manifests • Branded teacher payslips
Operational Suite: Store inventory POS, fleet manifests, and staff payroll runs.
MODULE_06 // PUBLIC_PORTAL

Public Admissions & QR Verification

Prospective parents submit admission requests via a dedicated intake portal at <school>.lmsyncd.com/apply. Review queues allow 1-click student conversion, while 128-bit cryptographic tokens verify all printed certificates.

[ SCREENSHOT: ADMISSIONS_QR.PNG ] Public applicant review • 1-click enrolment conversion • Anti-tamper verification
Admissions & QR: Public parent intake and instant tamper-proof verification.
>_ ./test_ai_studio.py --tone=interactive

AI Remarks Studio: Zero Reseller Markup.

Teachers spend hours handwriting repetitive report card comments. LMSyncd evaluates specific competency rubrics and synthesizes personalized, human narrative remarks across three distinctive tones in seconds.

01 // BYOK
Bring Your Own Key Schools input their own Google Gemini API key or use the built-in heuristic engine with zero external API reseller markup.
02 // RUBRIC
Curriculum Rubric Aware Synthesizes specific competency outcomes (CBC strands, algebra, scientific method) rather than generic report card platitudes.
03 // RADAR
Early-Warning Dropout Radar Automated anomaly detection alerts headteachers when attendance drops or grade slips cross critical statistical thresholds.
[ TRY THE INTERACTIVE TONE SWITCHER → ]
studio_ai_synthesizer.tsx
GEMINI-1.5-FLASH 210ms
FC
Faith Chebet Adm #2026-0412
CBC Grade 8 • Junior School • KJSEA Candidate Track
Attendance: 98.4% KNEC Band: ME
🔬 Science: EE (Exceeding) 📐 Maths: AE (Approaching) 📖 English: ME (Meeting)
Select Narrative Tone: 3 Models Active
“Faith has exhibited tremendous curiosity in Integrated Science this term, consistently Exceeding Expectation (EE) in hands-on apparatus assembly and collaborative inquiry. While her algebraic problem-solving is Approaching Expectation (AE), her perseverance and positive attitude indicate that targeted focus during morning prep will unlock her full mastery.”
Verified against KNEC Curriculum Descriptors
>_ cat /etc/postgresql/rls_tenancy_policy.sql

The safety net sits below the application, where bugs cannot reach it.

Most educational SaaS relies on application-level filtering where a single forgotten query argument leaks student PII. LMSyncd locks down data isolation at the PostgreSQL database kernel.

postgresql_18_rls.sql
-- 1. Isolated Session Variable set per HTTP Request
SET LOCAL app.current_tenant_id = 'tenant-uuid-here';

-- 2. Kernel-Enforced Row Level Security Policy
CREATE POLICY tenant_isolation ON people_student
  USING (tenant_id = NULLIF(current_setting('app.current_tenant_id', true), '')::uuid);

-- 3. Force RLS Even For Table Owner
ALTER TABLE people_student FORCE ROW LEVEL SECURITY;

// A forgotten filter in Python returns 0 rows, never another school’s records.
[ 01 // TWO_ID_RULE ] KERNEL ENFORCED
The Two-ID Architecture Rule

Every domain model (Student, Attendance, Invoice, AssessmentResult) carries both tenant_id (for kernel RLS) and org_unit_id (for campus scoping), eliminating costly recursive SQL joins.

tenant_id::uuid + org_unit_id::uuid
[ 02 // ZERO_DRIFT ] IMMUTABLE MATH
Zero-Drift Dynamic Balances

Student balances are never stored as mutable columns prone to drift. Balances are computed dynamically from immutable double-entry ledger lines with automated waterfall allocation.

Balance = Σ Invoices + Charges − Σ Payments
[ 03 // CI_HARNESS ] 100% COVERAGE
Automated Isolation CI Test Harness

Every Git push and deployment pipeline executes strict isolation tests. An automated scanner verifies that 100% of tenant tables have active RLS policies with zero leaky filters.

pytest tests/test_tenant_isolation.py
[ 04 // SOVEREIGN_STACK ] ~$50/MO VPS
Lean & Sovereign Stack

Django 5.2 LTS + ninja, React 18 SPA, Celery 5.6, Caddy On-Demand TLS on Hetzner VPS (~$50/month operational infrastructure cost across 100+ schools with zero cloud lock-in).

Django 5.2 LTS • React 18 • Caddy TLS • Hetzner
[ 01 // ZERO_SYNC ] REALTIME
0 Sync
Database sync scripts required across campuses — single shared PostgreSQL tree with zero drift.
[ 02 // RLS_KERNEL ] POSTGRES 18
100%
RLS kernel isolation coverage across all tenant tables — enforced at database kernel layer.
[ 03 // 3YR_SBA ] CBC / KJSEA
3 Years
Longitudinal SBA retention for Kenya KJSEA composite exam across Grades 7, 8, and 9.
[ 04 // 128BIT_QR ] CRYPTOGRAPHIC
128-Bit
Cryptographic verification tokens on all QR documents — tamper-proof receipts & reports.
>_ cat ./stakeholders.json

Built for every stakeholder across your institution.

From network directors managing multimillion-shilling budgets to classroom teachers taking morning roll-call.

DIRECTOR // OWNER

School Owner / Director

Primary Relief: Eliminates revenue leakage and blind spots across campuses. Provides a unified multi-branch financial cockpit, real-time collection metrics, and centralized licensing.

ACADEMIC // PRINCIPAL

Principal & Head Teacher

Primary Relief: Replaces frantic end-of-term grading bottlenecks with automated report card assembly, AI Remarks Studio, and the Early-Warning Dropout Radar.

FINANCE // BURSAR

Bursar & Accountant

Primary Relief: Ends manual paper receipt books and missing cash. Generates automated waterfall payments, 1-click Cash-Up sheets across M-Pesa & cash, and QR verification.

CLASSROOM // TEACHER

Classroom Teacher

Primary Relief: Reduces administrative workload from hours to minutes with 1-tap morning roll-call attendance, quick mark sheets, and automated homework generators.

FAMILY // PARENT

Parent & Guardian

Primary Relief: Replaces crumpled paper fee notes with a responsive, mobile-ready parent portal, WhatsApp magic-link logins, and transparent multi-child grade tracking.

COMPLIANCE // REGISTRAR

Registrar & Admissions

Primary Relief: Public intake page at /apply, bulletproof spreadsheet bulk importer with dry-run syntax previews, and KEMIS UPI / B-Form government ID tracking.

>_ ./show_tiers.sh --currency=kes

Modular SaaS packaging for single schools & networks.

Start with our core academic engine and unlock specialized operational modules as your campuses expand.

TIER_01 // FOUNDATION

Starter Plan

Everything needed to manage a single school campus with rigorous academic and financial control.

  • PostgreSQL Kernel RLS Isolation
  • Student Demographics & 1-Per-Term Enrolment
  • 1-Tap Daily Attendance Registers
  • Term Fee Invoicing & Waterfall Settlement
  • Data-Driven Grade Scales & Report Cards
  • Timetable Clash Detection Matrix
TIER_02 // RECOMMENDED

Professional Suite

The complete operational powerhouse for growing private schools and modern academies.

  • Everything in Starter Plan, plus:
  • AI Remarks Studio & Dropout Radar
  • School Store & Uniforms POS Register
  • Transport Fleet & Passenger Manifests
  • Staff Payroll Engine with Branded Payslips
  • Public Admissions Intake Portal (/apply)
  • 128-Bit Cryptographic QR Verification
TIER_03 // NETWORK

Enterprise Group

For multi-campus school chains, dioceses, and educational foundations requiring centralized governance.

  • Everything in Professional Suite, plus:
  • Multi-Campus Materialized Organizational Trees
  • Live Top-Bar Campus Switcher Dropdown
  • One-Click Longitudinal Student Campus Transfers
  • Cross-Campus Staff Assignments & Rostering
  • Consolidated Multi-Branch Executive Reporting
  • Dedicated Deployment & Custom On-Demand SLAs
>_ ls -la ./product_screens

Production screen showcase.

Designed with clean contrast, zero visual clutter, and accessible ergonomics for busy administrators and teachers.

[ SCREEN: MULTI_BRANCH_SWITCHER.PNG ] Top-bar branch switcher dropdown with campus metrics
Multi-Branch Campus Switcher
[ SCREEN: CASHUP_DRAWER_SHEET.PNG ] End-of-day teller reconciliation with M-Pesa splits
Daily Cash-Up Sheet & Reconciliations
[ SCREEN: CBC_RUBRIC_MARKSHEET.PNG ] Ordinal band descriptors & learning outcome tracker
Kenya CBC Assessment Marksheet
[ SCREEN: AI_REMARKS_STUDIO_MODAL.PNG ] 3-tone AI remarks synthesis modal with Gemini API
AI Remarks Studio & Tone Controls
[ SCREEN: POS_STORE_REGISTER.PNG ] Uniforms & textbooks barcode dispensary register
School Store POS & Inventory Tracker
[ SCREEN: QR_VERIFICATION_PORTAL.PNG ] Public document verification portal at /verify/<token>
Universal 128-Bit QR Document Verification
>_ ./schedule_school_demo.sh

Ready to unify your school operations under one cloud OS?

Book a live 15-minute walkthrough tailored to your campus or network. Bring your current fee structure and student enrolment, and we’ll show you a live run.

[ Book a 15-Minute Live Demo ] [ Talk to an Architecture Specialist ]
gsyncd_shell.sh (v1.0.4)
>_