Skip to main content

Security requirement — MFA until SSO

Password sign-in requires MFA (authenticator app) until DOE Single Sign-On is available. This applies to all roles unless an Admin has disabled MFA for that specific account (testing/QA). After sign-in without MFA, you are sent to Profile to enroll before using the rest of the app. Admins can reset MFA so a locked-out user can re-enroll, or disable MFA so a test account can sign in without an authenticator code.
Set up MFA from Profile after your first sign-in. Sessions last up to 12 hours. After 8 failed password/MFA attempts, the account locks for about 30 minutes (an Admin can unlock sooner). Contact an Admin if you lose your authenticator device. Full details: Security.

Admin

Scope: All schools Full access including user management, Admin → Security (failed logins, lockouts), MFA recovery, school and agency ID configuration, all cabinets and students, enrollment dashboard, email validation, MotherDuck analytics, school year rollover, archive boxes, reports, cleanup, and migration tools.

Data Lead

Scope: Assigned school Manage school data, cabinets (including Active / Archived tabs and Restore), bulk imports, duplicate review (with address comparison), NYC address verification on All Students, sibling confirmation, unassigned queue, bulk move, enrollment dashboard, school settings (including intake session time windows), school year rollover, archive boxes, Generate ISRF, and cleanup tools.
Email Validation (/admin/validation) and MotherDuck Analytics (/admin/motherduck-analytics) are Admin-only. Data Leads use in-app Analytics (/admin/analytics) for school-scoped metrics.

Data Member

Scope: Assigned school Add, edit, search, print, and export student records for their assigned school. Open Intake from the sidebar when covering the front desk. Fill the FY2027 ISRF from Daily → Generate ISRF. On Find & print, use Needs label to show only students who have never been printed. Print Avery 5163 or 94205 labels in batches via Download Word Doc (Letter, 100%), then confirm Yes — mark as printed. Uses the same left sidebar as Data Leads, with fewer admin links.

Intake Member

Scope: Assigned school Access only the Intake Form (full-screen — no left sidebar). Register new and returning students, capture ISRF demographics on NEW (employment, race/ethnicity, barriers), verify addresses (NEW), run live duplicate checks (name + address), notify Data Leads with Copy alert message / Email with alert, enforce session hours, flag potential siblings, and review a success summary after save. Labels are printed later from the Dashboard. Cannot access the main dashboard or admin tools.
Intake Members are limited to /intake and their assigned intake sessions. Admins and Data Leads can open Intake for testing.
Sidebar groups: Daily, Students, Storage, Print, Admin, Help. Links are filtered by role.

Role comparison