Demo environment — all course content is synthetic. No school children's records and no clinical patient data are stored here.

Build status

An honest map of this build: which flows actually persist data, which content is synthetic, and what has not been built.

Accounts and sign-in
real

Email and password accounts stored in the platform database.

Organization-scoped roles
real

admin, faculty and learner roles live in a separate roles table with row-level security. The first member can claim admin; after that only an admin can grant roles.

Course catalog, modules, lessons
real

Read from the database, not hardcoded.

Enrollment and lesson progress
real

Written per learner and enforced by row-level security.

Assignment submission and grading
real

Learners submit, faculty grade, learners see grades.

Grading rubrics and written feedback
real

Faculty score each rubric criterion and write feedback; learners see the breakdown on the course and My learning pages.

AI study assistant
real

Enrolled learners ask questions; answers are generated only from that course's lessons and cite lesson references. Not professional advice.

Quizzes
real

Attempts are scored server-side of the browser and stored per learner.

Publishing intake
real

Admin uploads a JSON package, it is validated, previewed, then explicitly approved. Publication writes real courses and records history.

Course content itself
demo

All seeded and sample content is synthetic. No school children's records and no clinical patient data.

Video assets
demo

Lesson videos point at a public sample clip; transcripts are synthetic placeholders.

Live MUYIZZI Publishing Command integration
not built

MUYIZZI Publishing Command has not been configured to call this LMS. No delivery from it has been received; the shared secret has not been handed over yet.

Signed webhook transport
real

POST /api/public/publishing-webhook verifies an HMAC-SHA256 signature, a 5-minute timestamp window and a unique delivery id, then runs the same validation and publish logic as manual intake. The secret is server-only.

Next integration step

  1. Agree the package schema v1 with the publishing side as a versioned contract.
  2. Add a backend endpoint POST /api/public/hooks/content-package that verifies an HMAC signature against a secret stored only in backend configuration.
  3. Have that endpoint call the same validation and publish routine the admin screen uses today.
  4. Keep explicit admin approval as the default; allow auto-publish only for an allow-listed content set.

Standing constraints