Plans, accommodations, related services, annual goals with progress
monitoring, meetings/team, and signed documents — plus a compliance
list and dashboard alerts for annual-review and triennial re-evaluation
dates (overdue in red, due-within-30-days in amber).
Access is tiered because special-education records are need-to-know
under FERPA:
FULL admin, the plan's case manager, the student's parents
IMPL the above, plus any teacher of the student — accommodations
and services only, never eligibility or meeting notes
RLS is row-level and every app role is the same Postgres role
(`authenticated`), so column grants cannot separate the tiers. The
split is therefore physical: confidential fields live in plan_details,
plan_goals, plan_meetings and plan_documents rather than as columns on
student_plans.
The UI asks the database which tier applies via the same predicates the
policies use (can_view_plan_full / can_edit_plan) instead of re-deriving
the rules client-side.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Routes
TanStack Start uses file-based routing. Every .tsx file in this directory
defines a route. Do not create src/pages/, src/routes/_app/index.tsx, or
app/layout.tsx — those are Next.js / Remix conventions. The only root layout
is src/routes/__root.tsx.
Conventions
| File | URL |
|---|---|
index.tsx |
/ |
about.tsx |
/about |
users/index.tsx |
/users |
users/$id.tsx |
/users/:id (dynamic — bare $, no curly braces) |
posts/{-$category}.tsx |
/posts/:category? (optional segment) |
files/$.tsx |
/files/* (splat — read via _splat param, never *) |
_layout.tsx |
layout route (renders children via <Outlet />) |
__root.tsx |
app shell — wraps every page; preserve <Outlet /> |
routeTree.gen.ts is auto-generated. Don't edit it by hand.