guide
Sections

Start here

Signing in

How a staff member gets into MySentinel for the first time and every time after — the invitation, the password rules, the two-step setup some roles are now asked for at the door, the security check some browsers block, and why there is no self-service sign-up.

Nobody signs themselves up for MySentinel. There is no create-an-account button anywhere in the app, and that is the first thing to understand about staff access: an account exists because somebody at your school made one for you.

A school-safety system that let people register themselves would be a school-safety system that could not answer who its users are. So the only way in is an invitation, and the only way out is somebody removing your access.

Your first time: the invitation

An administrator adds you to the school and MySentinel emails you an invitation. The link in that email opens a page headed Accept invitation, which asks you to set a password to activate the account.

The page shows you what you have been invited as — your role, and the school — so you can tell straight away if something is wrong before you commit to it.

You fill in four things:

  • the email address the invitation was sent to. It has to match. This is not a formality: it is what proves the person setting the password is the person the invitation was for, and not somebody who was forwarded the email.
  • your name, which is often filled in already from the invitation.
  • a password, twice.

Your password must be at least twelve characters and must contain at least one letter and one number. Twelve is longer than most systems ask for, and it is deliberate — these accounts can see where children are.

Then Activate account, and you are signed in immediately. There is no separate first login.

Four things can stop an invitation, and the page names which one it is rather than failing vaguely: the address you typed does not match the invitation, the invitation has already been used, it was withdrawn, or it expired.

None of them are fixable from your side. Each one means going back to whoever invited you and asking for a fresh invitation — which is the honest answer, because an invitation that could be revived by the person holding the link would not be much of a control.

Every time after: signing in

The sign-in screen is headed Staff login and asks for your email and password.

Above the sign-in panel there is a row of three buttons — English, Afrikaans, isiZulu — under a label written in all three languages at once. Press one and the whole app changes language immediately, before you have signed in or typed anything.

It is written in three languages deliberately. Somebody who has not chosen yet is reading whatever the app guessed, so a label in one language is unreadable to exactly the people who need it most, and each option is named in its own language rather than translated into the current one — an isiZulu speaker looks for “isiZulu”, not for whatever English calls it.

This matters more than it sounds. The language choice used to live only inside the signed-in app, which meant a device that had never been signed in could not reach Afrikaans or isiZulu at all: you had to read an English screen to get past the English screen. A gate phone that is set up once and shared by a shift now gets its language set at the door.

The choice is remembered on that device, so the next person to pick up the same phone finds it as they left it. Once you are signed in, the menu under your own name carries a language setting too — that one belongs to your account rather than the device, and follows you to whichever phone or laptop you sign in on.

Next to the password box is a Show password control. It is there because typing a long password one-handed, in the sun, at a gate, at quarter to seven in the morning, is a genuine cause of lockouts — and a password you cannot check is the reason people choose weak ones.

Underneath is Remember this device, with a line telling you to use it only on a trusted staff device. Leave it off on anything shared. Tick it on the phone that lives in the gate house and never leaves the school.

Below the sign-in button there is a second route in: Sign in with passkey, which needs no email and no password — your phone or laptop proves who you are with the same face, fingerprint or PIN it uses to unlock itself. Setting one up is covered in Your devices.

If your account already has a passkey, your password alone will not finish the job. After the password is accepted, your device asks for the passkey before you are let in. That is the point of having one.

Being asked to set up two-step verification

If you are an administrator, a class teacher or one of our platform staff and you have not set up two-step verification yet, you will be asked to do it right after your password. Not on some future date, and not as a reminder you can dismiss: the screen swaps the password form for a short setup, there and then.

Nobody is turned away and nothing is taken from you. You are signed in the moment it is done — there is no second sign-in afterwards, and no waiting for anyone to approve anything.

The setup asks you two things. First, how you would like to get your six-digit number: an app on your phone works one out on its own with no signal needed, or the number can be emailed to you if you have no smartphone. Then it asks you to type that first number back, which is what proves the setup actually reached you. Two-step verification explains both methods, why the app is the better of the two, and everything the numbers do afterwards.

Your ten recovery codes appear on the very next screen — the sign-in screen calls them backup codes, and they are the same ten. They are your way back in on the day the phone is lost, flat, or wiped and handed to somebody new, and they are shown exactly once. Nobody can look them up for you later, not an administrator and not the people who built the system, so the only copy that will ever exist is the one you make while they are on the screen.

So give yourself a few minutes for this, and have somewhere to write the codes down before you begin. You may need to install an authenticator app first, and the codes are the part you do not want to be rushing.

The screen allows fifteen minutes, and running out of time costs you nothing. If it expires — a phone that would not scan, somebody arriving at your door, an app that turned out to need downloading — you type your email and password again and start over. Nothing is left half-finished and nothing is lost. You are simply in the same position you were in before: not set up yet, and asked again next time.

If your account already has a passkey, the passkey comes first. You prove it exactly as you always do, and only afterwards are you asked to set the second check up. That order is deliberate. A passkey is already a second check, so allowing a new one to be set up on the password alone would be a way straight past it — the step meant to add a protection would have removed one instead.

A security officer’s sign-in has not changed

If you are a security officer, none of the above applies to you. Same screen, same two things to type, no number asked for.

That is a decision rather than an oversight. A gate phone is shared between officers across a day, and an authenticator app on a shared phone would end up holding everybody’s numbers on one device — which is worse than not having one at all, because the whole point of the second check is to prove that this particular person is the one signing in. An emailed number is worse still at a gate: it means opening a mailbox with a queue of learners in front of you.

What protects a gate phone instead is a passkey. It belongs to one person on one device, it cannot be handed round with the phone, and any account that has one is asked for it at every sign-in. That is the right second check for shared hardware, and it is why the passkey option on the sign-in screen is staying. An officer who wants two-step verification as well is free to set it up.

The security check, and the browsers that break it

Before your password is even sent, the sign-in screen quietly runs a check that you are a person rather than a script. Normally you never see it happen.

Some privacy browsers, and some tracker-blocking extensions, block that check. When that happens the screen tells you plainly that your browser blocked the security check, and asks you to turn shields or tracker blocking off for this site and try again.

This is worth knowing because the message sounds like an accusation and is not. The check is a standard anti-abuse control on a login page. The advice is literal — allow it for this site, sign in, and carry on.

The check also cannot hang the gate. If it stalls, it gives up on its own and lets the sign-in proceed, because an officer with a queue of children in front of them must never be blocked by an anti-abuse widget.

Forgot your password

There is a Forgot your password? link on the sign-in screen. It opens a page headed Reset your password that asks for one thing: the email address you sign in with. Press Email me a link and a link to set a new password is sent to that address.

The confirmation you get back is worth explaining, because it deliberately does not tell you whether it worked. It says that if the address belongs to a staff account, a link is on its way. It never claims the message has actually gone, and it never says the address is unknown.

That is not vagueness for its own sake. Anyone at all can open this page, and a screen that answered differently for a real address than for an invented one would be a way to find out who works at your school, one address at a time. That is precisely the list somebody would want before sending a convincing fake email to your staff. So the page gives the same answer to everybody, and the person who actually owns the address is the only one who learns anything, because they are the only one who receives the mail.

Two consequences follow from that, and both are normal:

  • If nothing arrives, check the spam folder before assuming anything is broken. The page cannot tell you the address was wrong, so a typo looks exactly like a successful request.
  • Asking twice in quick succession does not send a second email. A short pause is enforced between links for the same account, so that the form cannot be used to bury somebody’s inbox. The first link is still perfectly good — use that one.

An administrator can still start a reset for you from the staff list, and an operator can do the same for an administrator. Nothing about those has changed; the difference is that you no longer have to find one of them first.

If you no longer have access to that mailbox, the reset cannot help you and no amount of trying will change that. Ask an administrator at your school, who can issue you a new invitation.

Choosing the new password

The reset link opens a page headed Reset your password, where you choose a new one. The link is single-use and time-limited: once you have set a password with it, or once it has expired, opening it again does nothing useful and you have to ask for another.

Setting a new password does not disturb anything else about your account. Your role, your school and your passkeys are untouched.

One phone, several officers

A gate phone is usually shared. The morning officer signs in, the afternoon officer takes over, and the honest question is whose name ends up on each check-in — because every scan is recorded under whichever account is signed in when it happens.

So the account menu carries a Switch account entry. It opens a screen listing everyone who has signed in on that phone before — names and schools only; the phone remembers who, never anything that could sign in by itself. Tap your name, and the phone asks for your passkey the same way it unlocks: your fingerprint, your face, or its PIN. The moment the passkey is accepted, the previous account is signed out and the phone is yours — scans from then on carry your name.

A few deliberate honesty rules sit behind that moment. If check-ins are still waiting to send from the previous officer’s shift, the switch waits until they have gone — they belong under the name of the person who recorded them, and handing the phone over must never rewrite that. If the passkey check does not finish — a cancelled prompt, a finger the sensor did not like — nothing changes: the previous account stays signed in, because a gate must never be left with nobody signed in at all. And because the passkey itself decides who you are, picking a colleague’s name and proving a different finger simply signs in the account the passkey belongs to, and the screen says so plainly.

The first time on a new phone is still the ordinary sign-in with email and password — that is what puts your name on the list for every time after. A phone handed over mid-shift without switching keeps recording under the signed-in name; that is a known limitation of sharing a device, and schools in the pilot are asked to make switching part of the handover.

Your school’s own sign-in page

Some schools are given their own sign-in address. It is the same screen and the same account — the only difference is that it arrives already wearing the school’s colours and logo, rather than MySentinel’s.

There is no difference in what you can do, and no separate account to remember. If your school has given you an address like that, use it; if it has not, the ordinary sign-in page is the same door.