FOR FLIGHT SCHOOLS & ATOs

IN PRODUCTION A flight school runs its ATPL theory programme on this platform today, and further schools are in conversation.

Your theory programme, on one set of rails.

Provision accounts, group them into classrooms, build progress tests from the ATPL bank, open the gate when your instructor says so, and read the results as a cohort — not as thirty separate PDFs.

Every school is its own tenant. A request that crosses a school boundary does not return the wrong data — it returns nothing.

WHAT’S ACTUALLY THERE

Four things it enforces, not four things it promises.

13 SUBJECTS TRACKED

Every student carries a 13-subject authority record, whether or not they’ve sat any of them yet.

4 ATTEMPTS PER SUBJECT

The per-subject attempt ceiling is enforced in the database transaction, not in a form.

6 SITTINGS

Sittings per student are counted and capped, across all subjects — a sitting being the authority’s exam session, however many days it spans.

1 TENANT PER SCHOOL

Isolation is a guard on every route, not a filter someone remembered to add.

OVERSIGHT

Read the cohort, then read the attempt.

Eight dashboard views, from a school-wide KPI with a period-over-period delta down to a single question in a single sitting.

The cohort view

A pass-trend line over rolling windows up to a year, a first-time-pass figure, average sittings to pass, a per-subject outcome breakdown, and a classroom-by-classroom rollup.

The attention queue

A standing list of who needs looking at, derived from the same data as the dashboard rather than from someone’s spreadsheet.

The attempt report

Per-question outcome, learning-objective gap analysis banded by severity against that test’s own threshold, trend against the previous attempt, and flags for rushed or borderline work.

STRUCTURE

Accounts, classrooms, and a gate that starts closed.

Three school roles and twenty-eight named permissions, so the person who can price a contract is not automatically the person who can open an exam.

Provisioning

A chief instructor creates student and instructor accounts directly. Each one gets an identity, a one-time password it must change, and a welcome email. Resending or resetting rotates the credential.

Classrooms

Create, rename and delete classrooms; add and remove members. A student belongs to exactly one classroom — enforced by a database index, not by a warning dialog. Instructors can span several.

The gate

An assignment has a canonical time window, and a separate switch that starts off. Inside a valid window a student still cannot begin until staff open it. Start, resume and complete all refuse once it closes.

CONTENT

Your test, drawn from the shared bank.

Build progress tests down to sub-lesson level with live counts of how many questions actually exist in each pool.

Build it precisely

Subject, lesson, sub-lesson, a question count per pool, a pass threshold and a duration. The builder tells you how many questions exist before you commit to a number.

Scope it to your authority

A template can restrict which authorities’ questions are drawn. Leave it empty for all of them.

Freeze it on start

The template version and the authority selection are stamped onto each student’s test at the moment they start, so editing the template later cannot retroactively change a sitting that already happened.

EXAM VALIDITY

Seven rules, enforced in the transaction.

Not validated in a form and not checked afterwards. Every authority result is written under a row lock, so two people filing at once cannot slip past the counter.

  1. Six sittings per student Sittings are counted across all subjects and capped at six. A sitting is the examination session defined by the authority — it may span several consecutive days, and every subject taken within that session counts as one sitting. Today the platform treats each distinct exam date as one sitting; multi-day sittings are configured with your authority.
  2. Four attempts per subject The ceiling is per subject, not global, and it is checked before the sitting rules — so a pass on the last attempt is still a pass.
  3. A passed subject is closed Once a subject is passed, no further result can be filed against it. Ever.
  4. A failed set is terminal If one subject burns all four attempts without a pass, the whole set is failed: the record freezes read-only and every further write is refused. FCL.025 fails the set on two further grounds — the six sittings used up, or the 18 months elapsed — and requires the complete set to be retaken after further training. The platform refuses a seventh sitting, but it does not close a record on those two grounds by itself, and the fresh record a retaken set needs is scoped with you.
  5. One attempt per subject per sitting A second attempt at the same subject within the same sitting is refused.
  6. A subject’s sittings run forward A new result cannot be dated before that subject’s most recent one. Scoped per subject, so entering an older sitting for a different subject stays legal.
  7. All subjects within 18 months The window runs from the end of the calendar month of the student’s first attempt (FCL.025(b)(1)). The platform does not enforce it automatically yet: the first-attempt date and every sitting date are on the record, so the window is visible to the chief instructor, but no filing is refused on that ground today.

Pass or fail is derived from the score against the 75% threshold, attempt numbers are derived per subject, and the count of passed subjects is derived from the results. None of them can be typed in by hand.

ISOLATION

A school boundary is a wall, not a filter.

TENANT

Every route is scoped

School scope is a guard in a fixed chain on every controller, ahead of any ownership check. A request that reaches across a school boundary gets nothing back, not somebody else’s data.

OWNERSHIP

Instructors own their classrooms

A separate guard checks classroom ownership after school scope, so a valid instructor in the right school still cannot act on a classroom that isn’t theirs.

IDENTITY

Accounts are provisioned, not self-signed

School accounts are created by the school. A school user cannot buy a licence for themselves — the server refuses the checkout before it starts.

HISTORY

Records outlive the roster

Deleting a template or a classroom retains history. Authority exam results are never purged; the record is the point.

ROLLOUT

How your first month runs.

  1. A walkthrough

    We walk the live admin surface with your own subject list in front of us.

  2. Your school, set up

    Your tenant, your authority, your chief instructor account. You provision the rest.

  3. One classroom first

    Build one template, assign it to one classroom, open the gate, read the report — then scale it across the school.

  4. The full cohort

    Roll out to every classroom with the templates you’ve already proven.

COMMERCIALS

Priced per school, by a person.

School licensing isn’t a checkout. Terms are agreed per school — a contract price, per-seat rates for students, instructors and chief instructors, an included-seat allowance, and invoices issued against the seats actually used. Your students never see a payment screen; the platform refuses to sell them one.

Ask for terms

Bring your own cohort.

One call, your subject list, and the live admin surface.

PILOT 100 · FOR TRAINING ORGANISATIONS