Governance
What a timetable reveals about people
It is a grid of rooms and hours until you read it sideways, at which point it is a record of where several thousand named people are required to be, every hour of every week.
Read it sideways
A timetable answers when is this module taught. Turned ninety degrees it answers where is this named person, on which days, for the next six months — and it answers it for every member of teaching staff and, through group membership, for a large share of students.
That is a different kind of document from the one most institutions think they are publishing, and it is worth saying out loud before deciding who may see what. The grid itself is unremarkable. The inversions of it are not.
The things that are more revealing than they look
- A lecturer's whole week. Browsing by staff member turns the timetable into an attendance pattern. Some institutions are entirely relaxed about this; others treat teaching engagements as confidential, and both positions are defensible. What is not defensible is not having taken one.
- Absences, by subtraction. A colleague who normally teaches Tuesdays and does not this term is visible to anybody watching, and the reason is nobody's business.
- Free text on a booking. A room booking carries a description and a note, and people write real things in them — a disciplinary meeting, an occupational-health appointment, a named student. A booking title is displayed far more widely than the person typing it imagines.
- Room membership as group membership. Publishing which group attends which session can disclose who is on a support programme, a resit route or a small specialist option, simply because the cohort is small enough to identify.
- Small groups generally. A session with four students is effectively a list of four names to anybody who knows the cohort.
Controls worth insisting on
Whatever system you use. These are questions to put to a vendor, not a description of one product.
- Separate public and internal views, so that what a visitor sees and what a member of staff sees are two decisions rather than one.
- The ability to switch off browsing by lecturer for the public view, without switching off the lecturer's own access to their own timetable.
- A private field on a booking that is genuinely private — distinct from the line that appears on the published timetable — so nobody has to choose between recording why a room is held and keeping it to themselves.
- Rooms that can be hidden from public lists without their lessons disappearing from the timetables of the people who attend them.
- Credentials scoped to what they may read, so an integration built for one faculty cannot read another's.
- A named list of the sites permitted to embed the timetable, rather than a wildcard that lets any page on the internet read it using a visitor's session.
- A published retention position: how long historical timetables are kept, and who can still read a schedule from four years ago.
How Wise Timetable handles these
Each institution decides what a client application may offer, and the decision is published to the app rather than hard-coded: an institution that treats staff engagements as confidential switches off browse-by-lecturer and the picker disappears from every portal and every mobile app pointing at it, without anyone rebuilding anything.
A room booking carries two separate texts — the line that appears on the published timetable, and an internal note that does not. Rooms an institution does not publish are marked as such and stay off public lists while their lessons continue to appear to the people who attend them.
Integration credentials are issued by us, scoped to the institutions they may read, and exchanged for a token that expires; a browser application is admitted by an explicit list of permitted origins rather than by a wildcard. And the part of the API that writes — room bookings — cannot be reached with an application credential at all: it requires a person to sign in as themselves, because a booking records who made it.
The management system behind all of this is certified to ISO/IEC 27001:2022, and the certificate is published alongside every other document we produce on the security page.
One caveat, meant seriously
This is a description of what a timetable discloses and what controls exist to limit it. It is not legal advice, and what your institution is obliged to do depends on where it is and on decisions that are properly your data protection officer's. The useful thing to take from it is the inventory: know what your timetable reveals before you decide who may see it, rather than discovering the list after publication.
Want to see this working?
Book a 45-minute online presentation and we will walk through it against your institution's own scheduling problem.