Digital transformation in Islamic boarding schools (pesantren) presents a distinctive information-governance challenge because parental demands for access to students' academic information must coexist with institutional policies, teacher verification processes, and restricted student use of personal mobile devices. Existing educational information systems generally provide either role-based access without approval workflows or fragmented monitoring services, while structured authorization mechanisms incorporating professional human judgment remain insufficiently explored in this context. This study proposes a mobile-based Smart School Information System that introduces a Human-in-the-Loop Request–Response access control mechanism to regulate parental access to sensitive academic information while preserving institutional governance. The system was developed using a Research and Development (R&D) approach integrated with a prototyping methodology, employing Flutter as the cross-platform mobile framework and Laravel as the REST API backend with Laravel Sanctum token-based authentication. Functional performance was evaluated through Black Box Testing comprising 45 role-based scenarios, with seven critical scenarios reported in detail, while user acceptance was assessed using the Technology Acceptance Model (TAM) involving 59 respondents representing parents, teachers, homeroom teachers, ustadz, and school administrators. The 45 role-based functional test scenarios achieved a 100% success rate, indicating that the implemented functions operated according to their specified requirements. TAM analysis revealed that Perceived Usefulness (β = 0.390, p < 0.001), Perceived Ease of Use (β = 0.324, p < 0.001), and Attitude Toward Using (β = 0.308, p = 0.002) significantly influenced Behavioral Intention to Use, with a coefficient of determination (R²) of 0.734. These findings demonstrate positive user acceptance of the implemented system and confirm that the Request–Response authorization workflow operated according to its specified functional rules. The results provide functional and user-acceptance evidence for the implementation of the proposed mechanism in the studied pesantren context, rather than establishing the broader effectiveness of the mechanism in balancing information privacy and institutional governance. This study contributes a Human-in-the-Loop Request–Response authorization framework that extends conventional Role-Based Access Control (RBAC) by incorporating structured human decision-making into educational information systems. Keywords: Flutter; Human-in-the-Loop; Request–Response Access Control; Smart School; Technology Acceptance Model
Copyrights © 2026