Open Admin → Users & Privileges and create or edit the staff user. For a new school login, choose the person's active HRM employee first, then enter their login details. In Employee & Account when creating, or Profile & Role when editing, review Designation, Role, Mark as Account Owner and Mobile Application Access before saving.
Designation suggests access; the administrator decides
Selecting a designation suggests a role and mobile applications. Principal, Admin and similar administrative designations suggest the standard administrator role (role 2); Teacher and Parent suggest the standard user role (role 3). Review the suggested role and each selected app, then adjust them for the person's work. A designation never automatically grants the Super Admin role or marks someone as Account Owner.
The account's designation is a login/access setting. It is separate from the linked HRM employee's employment record and does not change their HRM identity. A person cannot grant themselves ownership or app access by typing a designation during sign-in. Existing screen privileges and campus access still need their own review.
Mark as Account Owner
Tick Mark as Account Owner only for the person who should have universal application permission. It selects Owner App, Admin App, Teacher App and Parent App, then locks all four checkboxes. The helper says: Account Owners receive universal access to all applications.
Untick the owner checkbox to make the app choices editable again. Review the selections and save the intended access. The owner flag controls application permission; it does not itself change the selected role, grant every web screen privilege or bypass account and employment status checks.
Choose individual applications
For a user who is not an Account Owner, tick or untick Owner App, Admin App, Teacher App and Parent App individually. The Admin App carries a Beta / In Development badge. Permission to that app does not promise that its unfinished features are available.
Changing the designation fills its suggestions again, so review any manual changes before saving. To keep a custom combination, select the designation first and then adjust the role and app checkboxes.
App permission still needs the correct login identity
- An inactive user remains blocked. A school login linked to an inactive or Left employee in HRM also remains blocked, including when it is marked Account Owner.
- Native Teacher App employee credentials are managed through HRM → Manage Employees → Teacher App Credentials. Selecting Teacher App access on a web user does not create those credentials or connect the user to another employee.
- Native Parent App sign-in still requires verified family identity. Selecting Parent App access, choosing Parent as a designation or marking someone as owner does not create a parent login or grant access to another family's children.
- Older accounts with no saved per-app configuration keep the earlier mobile sign-in rules until an administrator saves their app choices. Do not assume that a blank legacy configuration means either universal access or no access.
If sign-in fails, check the account's saved app choices, Active status and linked HRM status. Report the institute code, username, app name and exact error; never send a password. Do not create another account to avoid an inactive employee block.
