guide
Sections

The school workspace

The staff who use MySentinel

Inviting officers, administrators and class teachers, and the four different ways of taking access away — from a one-tap pause to ending a relationship for good.

Staff, under Manage, is the list of everyone with access to your school — officers, administrators and class teachers — plus anybody you have invited who has not signed in yet. It is a short screen with more consequence per button than almost anything else in the workspace, because everything on it is about who can open your gate.

The three roles

An officer works the gate. That is their whole app: scan a badge, record who came and went, sign a visitor in.

An administrator has the workspace you are reading about — the roster, the queues, the settings, the evidence screens, and the safety controls.

A teacher sees their own classes and subject groups: the registers, the learners in them, and the approvals that belong to those learners. They do not get the rest of this workspace, with one deliberate exception — the late-pickup queue.

Give the smallest role that does the job. It is not a matter of trust; it is that a person who cannot reach a screen cannot be talked into using it by somebody on the phone claiming to be from head office.

One person, more than one role

Some people wear two hats — a deputy principal who runs the office and teaches Life Skills, an officer who also takes a register. They still have one account and sign in once. You give them the second role with Roles on their row.

The window shows the role their invitation gave them, the one they sign in as, and under Also works as the other roles, each with a line saying what it is for. Tick the ones they also do and choose Save roles. Saving asks for your passkey, like every other change on a colleague’s row, because giving somebody the administrator role widens everything their sign-in can reach.

Taking a role away signs that person out on every device at once, and they sign back in with the roles they still hold. A phone still carrying a role the school has just removed should not keep it until it happens to expire.

Somebody who holds more than one role sees Working as where their role used to be shown, with a button for each. One tap moves them between the teacher’s screens and the office’s without signing out. Only one role is active at a time and every screen decides what it shows from that role alone, so holding two roles never mixes two workspaces into one. If any role a person holds needs two-step verification, their account needs it, whichever role they are working as — the window warns you when a role you are adding brings that requirement.

Invitations still carry one role; add the others once the person has signed in. And as with everything else on this screen, you cannot change your own roles.

Adding somebody

Add staff takes an email address, an optional name, and a role, and the screen says what happens next: they will get an email invitation to set their password and sign in. You never type a colleague’s password, and no password ever travels through you.

Creating that invitation asks for your passkey. It is the only kind of write on this screen that creates access rather than removing it, and a credential for a new person is exactly what somebody who briefly borrowed your laptop would want to mint.

Until they accept, the person shows in the list with an amber Invited chip and the date the invitation expires. Revoke cancels it — the activation link stops working, and you can invite them again later. That, too, asks for your passkey.

Two refusals you may meet: an active invitation already exists for that address, or that address is already a staff member. Both mean the same practical thing — look at the list before inviting again.

Once somebody has signed in and registered a passkey of their own, their password stops being enough on its own; the app asks for the passkey as well. That is why passkeys are worth encouraging early rather than during an incident.

Helping somebody back in

Two buttons on each row exist for the ordinary bad mornings.

Reset password sends that person a reset email and tells you whether it went. It asks for your passkey, because reaching into another person’s ability to sign in is the same class of act as ending it.

Clear sign-in lock is the one worth understanding before you need it. The app’s sign-in throttle counts the address somebody types, before it looks up any account at all. That means anyone who knows a staff email address can hold that person out of the app without ever knowing a password — and the person that hurts most is your gate officer, whose address is the easiest to guess and whose absence stops the gate. This button is the way back in, and it asks for your passkey too.

It is also honest when it changes nothing: if the person was not locked out, it says so and tells you the cause is something else, rather than reporting a rescue that did not happen.

The devices somebody is signed in on

Signed-in devices, on each person’s row, is the finer instrument beside the two below — and the one you will actually reach for most.

A teacher leaves her phone in a taxi on a Tuesday. She still works here on Wednesday, so ending her access is the wrong answer and suspending her stops her teaching. What you want is to kill the one handset, and that is this screen: every device she is currently signed in on, when each was last used, and a button against each.

It shows the names people give their own devices. Without one, every Windows laptop in a school shows up as “Windows” and every gate handset as “Android”, which is no help at all when you are choosing which one to end. Encourage staff to name theirs — it takes a moment on their own Sessions screen, it survives signing out, and it is what turns this list from four identical rows into a decision you can make.

Signing a device out removes the school’s learner information from it. This is the half of the control that matters most and it is easy to miss. A gate phone carries a copy of your whole roster — every learner, their guardians, their custody flags and their photographs — so that scanning keeps working when the signal does not. Ending the session is what takes that copy off the phone.

It happens the next time that device connects, and the wording says so rather than promising something it cannot deliver. A handset switched off in a drawer is not reachable by anything we can do from here; what we can promise is that the moment it comes back, it comes back empty, and that it cannot be used to scan or to look anybody up in the meantime. If a device is genuinely gone for good, this is a complement to your own phone policy, not a replacement for it.

The button asks for your passkey. Ending somebody’s session mid-shift and wiping the roster off a working handset is not something to do by mis-tapping. The list itself does not — you cannot choose the right row without seeing it first, and “revoke something, anything” is exactly the failure this screen exists to end.

Your own row does not offer this. Your devices are on your own Sessions screen, which knows which one you are holding and says so; an administrator who ended the session she was using would be signed out in the middle of doing it and told about it on a page she could no longer load.

Taking access away

There are two ways, and the difference between them is the point.

Suspend stops somebody signing in, immediately, in one tap, with no passkey ceremony. Sessions they already hold are cut, so it takes effect now rather than whenever their login next expires. Let them sign in again puts it back from the same row.

That looks like the weaker control and it is the deliberate one. The moment a suspension is needed is a head at twenty to eight with the gate about to open. A pause that is hard to reach is a pause nobody uses in the moment it matters, so this one is reversible, obvious and instant.

End access is the other direction — the end of the relationship. It asks for your passkey and confirms in plain words: they will be signed out everywhere and will not be able to sign in to this school again; their record and everything they did stays. You can add a reason, which is kept in the school activity log.

Nothing is deleted by ending access. The check-ins that officer recorded remain exactly as they were, attributed to them. A school’s evidence of what happened at its gate cannot depend on who still works there.

Every one of these actions lands in the school activity log with your name, the person you did it to, and the time.

The one thing you cannot do

You cannot suspend, revoke or otherwise reach your own account from this screen — the app refuses by name rather than letting you discover it. An administrator who revokes her own membership locks the school out of its own workspace, and the only person who could undo it is the one who just lost the ability to.

For the same reason, keep more than one administrator. A single administrator on leave with a broken phone is a school that cannot change a setting, approve a pickup, or clear a lockdown.