Start here
Who does what
The five kinds of people MySentinel serves, and exactly where each one's reach stops.
MySentinel serves five kinds of people. Four of them sign in. The fifth — the parent — never does, and that is a design decision rather than an omission.
The boundaries below are not guidance or convention. The app enforces them: a person who opens a screen outside their role is returned to their own home screen, and the school a staff member belongs to comes from their sign-in, never from anything a browser can be persuaded to claim. Staff at one school cannot reach another school’s learners.
The officer at the gate
The officer works from a small, deliberate set of screens: the gate itself, a badge-checking screen that identifies a badge without recording anything, the visitor register, the list of scans still waiting to send, and an offline pack of the school’s data for a device that will lose signal during a shift.
That is the whole surface, and its smallness is the point: the gate is worked one-handed, at speed, in the sun, by someone who should never hunt for the right screen.
Where it stops. An officer cannot reach the school workspace — none of it. Not the dashboard, not learner records, not settings, not reports, not the audit trail. An officer who follows a link into it is returned to the gate.
The school administrator
The administrator has the full school workspace, which is four kinds of work: the daily picture (live dashboard, learners, classes, attendance, absences, day close); the queues that need a human decision (pickup requests, guardian approvals and verification, late pickups, parent messages, and the parents the school could not reach); the school’s setup (staff, settings, roster imports); and the record (reports, gate history, the audit trail, notification templates, the visitor register and ban list). Emergency broadcasts and safety mode sit here too.
An administrator can also do everything an officer can, including scanning at the gate. They rarely need to — but a school where exactly one person can operate the gate has a single point of failure, so the app does not create one.
Where it stops. An administrator cannot reach the class teacher’s workspace, nor MySentinel’s own console. Separately, the most consequential actions — declaring a lockdown, exporting or erasing a person’s data, changing how long records are kept, overwriting school settings, rolling back an import — need a passkey at the moment of the action, not merely at sign-in.
The class teacher
The class teacher has four screens, all about their own classes: Dashboard, Register, Learners, and Late pickups. The dashboard states its own limit: You see only your assigned classes. Reassignments are handled by the school admin.
From the dashboard a teacher sees their learners’ live status — a line such as 18 of 24 of your learners are on-site — reads who is absent and why, acknowledges the sick notes parents have sent in, and approves or declines pickup requests for their class, with a Raise a concern button always in reach for a worry about a learner. Register is the separate screen where the day’s roll is actually taken: the learners the gate checked in that morning arrive as one line the teacher confirms in a single act, everyone else is marked one at a time — by tapping their name or, on an Android phone running Chrome, by scanning their badge — and a filed register is final. Learners is the searchable roster of every child across their classes. Late pickups is their own queue of children still waiting past the school’s collection time, where they can log a contact attempt or mark a child collected.
Where it stops, precisely. This is the boundary most often assumed wrongly, so it is worth stating flatly. A class teacher cannot open the visitor register, the gate, the school dashboard, or any part of the administrator’s workspace — the app admits a class teacher to their own class workspace and their own profile, and nothing else; anything further returns them to their dashboard. Within their own late-pickup queue, two actions stay the administrator’s alone: escalating an unresolved wait to the office, and resolving one manually. Both are refused by the same authority that scopes the whole queue to a teacher’s own classes — the contract accepts them only from an admin — so the row simply does not offer either, and names who does instead. No action on a class teacher’s own screens ever costs a passkey step-up.
Two of those boundaries are drawn differently, and it matters if you are ever reading a log. The visitor register and the gate refuse a class teacher outright — the request is turned away wherever it comes from. Late pickups is not: it is a screen that is genuinely hers, built from the same reads that already fed her dashboard, and only the two administrator-only actions inside it are refused. A school’s records showing her account logging a contact or marking a child collected are the app working as designed, not someone getting past it.
The parent or guardian — no login
A guardian never creates an account, never chooses a password, and is never required to install an app. They receive a private link that belongs to them, and it opens their own view: their children, whether each is at school right now, the day’s check-ins and check-outs, attendance, the sick notes and messages they have sent, and their notification settings. The account page tells them how long the link stays active.
The link itself is the boundary. It reaches their children and nobody else’s. Within it a guardian can switch alerts on or off per child and per channel, set quiet hours, send a sick note, ask for an early pickup, and authorise another adult to collect. They cannot see a class list, another family, any staff screen, or anything about how the school is run.
One thing they cannot switch off, and are told so: Emergency, safety and late-pickup alerts are always sent, whatever your settings.
MySentinel’s own staff
Our platform staff work from a separate console for running the service across every school — setting a new school up, watching platform health, handling support, following message delivery, preparing billing figures, and carrying schools into a new academic year. Their sign-in carries no school, so by construction it opens no school’s workspace.
There is one deliberate exception, built to be uncomfortable to use casually. A staff member can open an audited, read-only, time-boxed view of a single school, so that a support question can be answered by looking at what the school is looking at. It requires their passkey, every attempt to change anything is refused for its duration, and it is written into that school’s own audit trail, not only into ours. A school can see when we looked.
Why the lines fall where they do
Each boundary answers a question about consequence, not seniority. An officer is trusted with the most safety-critical action in the product and kept away from the settings that could quietly change it. A class teacher is trusted with the children they teach and no others. A parent gets everything about their own child and nothing about anyone else’s.