School admin integration guide
For the IT lead or administrator connecting a school to EduSpaze. Everything below is done from School Settings, Staff & Access and Students in the school portal, in the order a new school usually needs it. Last updated 2026-09-02.
1. Before you start
| You will need | Where it is used |
|---|---|
| Your tenant id (School Settings → Integrations) | Vendor telemetry, support requests |
| Your school email domain(s) | Single sign-on gating |
| A roster export from your student information system (CSV) | Student import |
| An admin account on Google Workspace or Microsoft Entra ID (optional) | Single sign-on |
Your EduSpaze subscription must be valid for staff single sign-on to work; password sign-in for the admin account always works so you can reach these pages.
2. Staff accounts and roles
Staff & Access → Add staff member. Roles:
| Role | Can |
|---|---|
| School admin | Everything below, plus settings, staff, audit log, anonymisation |
| Teacher | Students, classes and groups, engagement, parent questions |
| Staff | Read-only marketplace access |
Each account gets a temporary password shown once. Staff can also sign in with the school's identity provider once SSO is switched on (section 4); passwords keep working alongside it.
3. Students, classes and groups
Students → Import CSV. Download the template first; the importer maps common header names automatically, validates every line before writing anything, and *upserts* by external id, so re-importing an updated export updates pupils in place and re-enrols them in their current class. Fields: external id, first name, last name, date of birth, year group, class, optional start and end dates.
Alternatively, Batch generate creates placeholder pupils for a class, and Issue accounts gives selected pupils a launcher username and PIN (usernames follow <prefix>-<class>-<sequence>).
Classes & Groups: teachers can be assigned to classes and can move pupils between classes and groups themselves. Start and end dates on pupils, classes and groups control what counts as active today.
4. Single sign-on (Google Workspace / Microsoft Entra ID)
School Settings → Domains & identity provider.
- Enter your verified email domains. Only accounts on these domains are accepted.
- Choose the provider; optionally restrict to a directory/tenant id.
- Run test sign-in with your own admin account. This verifies the configuration.
- Switch on for staff.
Sign-in is refused, with one neutral message, whenever the domain is unknown, SSO is not yet verified, the subscription has lapsed, or the account is inactive. Provider credentials (client id/secret) are configured by EduSpaze; the built-in demo provider lets you rehearse the flow without them.
5. Connecting apps for pupils
Before a pilot starts, read the roster mapping protocol with your vendor: it sets out who does what at each stage, and the one obligation everything rests on — a pupil's external id must come from your SIS and never be renumbered.
Staff who teach a class can open a connected vendor app from Connected Apps. The vendor is told a code for them (STF-0003), your school id, their role and the ids of the classes they teach — never a name or an email, the same treatment pupils get.
Vendors receive pupils under a pseudonymous id (the external id from your roster), never a name. Vendor-hosted apps get a signed launch; listed apps open inside the EduSpaze app frame. Revoking a connection removes the vendor's access and its data about that pupil.
6. Engagement measurement
School Settings → Engagement measurement sets three parameters:
| Setting | Default | What it does |
|---|---|---|
| Inactivity cutoff | 10 min | A gap longer than this ends a session. Repeat sign-ins inside it continue the same session, so nothing is counted twice. |
| Launch-only minutes | 2 | Time assumed for an app opened with no further signal. |
| Heartbeat interval | 60 s | How often an open app page reports presence. |
School → Engagement shows minutes, sessions, opens, confidence and last-active per pupil per app. Confidence tells you whether the number came from the app itself, from EduSpaze's own presence signal, or is a launch-only minimum. How it works: Engagement tracking.
7. Parent access (optional module)
School Settings (when enabled by EduSpaze): switch parent access on, set the age of transition, the usage bands for the timeline (no defaults are supplied — set them deliberately) and the timeline retention. Parents are created by the school; there is no self-registration. Parent questions and objections arrive under Parent Questions.
8. Audit log and data-subject requests
School → Audit Log shows every change to your school's data with who, when, before and after values, filterable by pupil id, event type and date. Records live on a separate, tamper-evident audit platform.
Anonymise (typed confirmation) tokenises a pupil, guardian or staff member everywhere, including free text that mentions them, and shreds the encryption key protecting their historic audit values. It is irreversible by design; the pseudonymous id is kept so history still links. Use it for subject-access "erase" requests after the retention period, or on request.
9. Support checklist for EduSpaze
When raising a request, include: tenant id, the page, the time (with timezone), and the pupil's external id rather than their name.
