> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nycadultedlabels.nyc/llms.txt
> Use this file to discover all available pages before exploring further.

# User roles

> Permissions for Admin, Data Lead, Data Member, and Intake Member.

## Security requirement — MFA until SSO

<Warning>
  **Everyone using the system must enable MFA** (authenticator app) until DOE Single Sign-On is available. This applies to all roles. Admins may disable MFA only to unlock an account; the user must turn MFA back on afterward.
</Warning>

Set up MFA from **Profile** after your first sign-in. Contact an Admin if you lose your authenticator device.

## Admin

**Scope:** All schools

Full access including user management, security recovery, school and agency ID configuration, all cabinets and students, enrollment dashboard, email validation, school year rollover, archive boxes, reports, cleanup, and migration tools.

## Data Lead

**Scope:** Assigned school

Manage school data, cabinets, bulk imports, duplicate review (with address comparison), NYC address verification on All Students, sibling confirmation, unassigned queue, bulk move, enrollment dashboard, email validation, school settings (including **intake session time windows**), school year rollover, archive boxes, and cleanup tools.

## Data Member

**Scope:** Assigned school

Add, edit, search, print, and export student records for their assigned school. Print Avery **5163** or **94205** labels in batches via **Download Word Doc** (Letter, 100%). Uses the same **left sidebar** as Data Leads, with fewer admin links.

## Intake Member

**Scope:** Assigned school

Access only the **Intake Form** (full-screen — no left sidebar). Register new and returning students, capture and verify addresses (NEW), run live duplicate checks (name + address), enforce session hours, flag potential siblings, and review a success summary after save. Labels are printed later from the Dashboard. Cannot access the main dashboard or admin tools.

<Warning>
  Intake Members are limited to `/intake` and their assigned intake sessions. Admins and Data Leads can open Intake for testing.
</Warning>

## Navigation

| Role                            | Chrome                                                  |
| ------------------------------- | ------------------------------------------------------- |
| Admin / Data Lead / Data Member | Left sidebar + top bar (school, dark mode, profile, ⌘K) |
| Intake Member                   | Intake-only header (Translate, Reset, Sign out)         |

Sidebar groups: **Daily**, **Students**, **Storage**, **Print**, **Admin**, **Help**. Links are filtered by role.

## Role comparison

| Capability                      | Intake Member | Data Member | Data Lead | Admin |
| ------------------------------- | ------------- | ----------- | --------- | ----- |
| Register / log visits on Intake | ✓             | —           | ✓         | ✓     |
| Search & edit students          | —             | ✓           | ✓         | ✓     |
| Print label batches             | —             | ✓           | ✓         | ✓     |
| Cabinets & archive              | —             | —           | ✓         | ✓     |
| Duplicates / enrollment issues  | —             | —           | ✓         | ✓     |
| Users & all schools             | —             | —           | —         | ✓     |
