Skip to main content

Security requirement — MFA until SSO

Everyone using the system must enable MFA (authenticator app) until DOE Single Sign-On is available. This applies to all roles. Admins may disable MFA only to unlock an account; the user must turn MFA back on afterward.
Set up MFA from Profile after your first sign-in. Contact an Admin if you lose your authenticator device.

Admin

Scope: All schools Full access including user management, security recovery, school and agency ID configuration, all cabinets and students, enrollment dashboard, email validation, school year rollover, archive boxes, reports, cleanup, and migration tools.

Data Lead

Scope: Assigned school Manage school data, cabinets, bulk imports, duplicate review (with address comparison), NYC address verification on All Students, sibling confirmation, unassigned queue, bulk move, enrollment dashboard, email validation, school settings (including intake session time windows), school year rollover, archive boxes, and cleanup tools.

Data Member

Scope: Assigned school Add, edit, search, print, and export student records for their assigned school. Print Avery 5163 or 94205 labels in batches via Download Word Doc (Letter, 100%). Uses the same left sidebar as Data Leads, with fewer admin links.

Intake Member

Scope: Assigned school Access only the Intake Form (full-screen — no left sidebar). Register new and returning students, capture and verify addresses (NEW), run live duplicate checks (name + address), enforce session hours, flag potential siblings, and review a success summary after save. Labels are printed later from the Dashboard. Cannot access the main dashboard or admin tools.
Intake Members are limited to /intake and their assigned intake sessions. Admins and Data Leads can open Intake for testing.
Sidebar groups: Daily, Students, Storage, Print, Admin, Help. Links are filtered by role.

Role comparison