Appearance
Admin users
Who this is for: Tenant owner, Admin
What you'll achieve: Invite people, review roles, point staff to MFA, and read the change history
Requires role
user.invite / audit.view. Tenant owner or Admin (SSO configure is owner-only)

Admin is split into short tabs so everyday work stays on one screen:
| Tab | What it is for |
|---|---|
| People (default) | Invite logins, link staff, MFA reminders |
| School | Name, colour, school type, location, extra schools, calendar subscribe, optional calendar write-back and hosted teaching CSV pull |
| Cover rules | When a day can go live, class cover, duty headcount |
| Billing | Plan, seats, and (for the owner) cancel date if the subscription is ending |
| Change history | Who changed what |
Optional or IT-only blocks start closed. Open Show only if you need them. Tabs keep a ?tab= value in the address bar so you can bookmark a section.
To change school type after signup (primary, nursery, or secondary), open Admin → School, or Change school type on the AI setup card. In the full portal you can also use Change school type in the sidebar. That updates setup suggestions such as duty areas and default named periods. It does not rewrite the live rota. On a trust, set the type per school under Admin → Schools.
Invite a user
- Open Admin. You land on People.
- Enter Email, Temporary password, and Role.
- Optionally Link to staff: pick a directory person, or leave blank to auto-match by email (or create a staff record).
- Select Invite.
- Share the portal URL and credentials securely.
Roles available in the invite form: Admin, Duty lead, Office, Staff, Viewer.
Several Admins can work at the same time. There is no extra seat charge for extra Admin logins. Only the owner can invite another Admin (or another Owner), because you cannot grant your own rank. Ask the owner if you need a second Admin.

Staff link (My schedule)
A login must be linked to a staff directory person (person_id) to see My schedule, duties, and lessons.
| How the link is made | Behaviour |
|---|---|
| Admin invite | Explicit pick, or auto-match email / create person |
| Admin user list | Change the staff dropdown on any user |
| SCIM provisioning | Match existing staff by external id then email, else create |
| SSO (OIDC) sign-in | Same match rules; backfills link if the user had none |
| Staff CSV import | After import, unlinked users with matching emails are linked |
Billing
The Billing tab is for the school owner. It shows the plan, seat use, and billing email, plus Manage billing for the Stripe portal.
If someone cancels, SchoolRota keeps the portal open until the end of the paid period. Billing then shows that the subscription is set to cancel and the last day of access. Use Manage billing to resume if you want to stay on. After that date the portal is suspended until you resubscribe.
Review users
The user list shows email, role, an MFA badge, and the linked staff name (or No staff link).
SCIM provisioning
Tenant owners can auto-sync users from Entra, Okta, Google, or any SCIM 2.0 provider. On People, open School sign-in (IT). See SCIM provisioning or the IdP pilot runbooks for end-to-end school IT checklists.
MFA (two-factor authentication)
Local-password tenant owners, admins, and duty leads must enable authenticator MFA on first sign-in (a login-style card, then Done). After that, Account is where they manage backup codes and the authenticator.
- Scan the QR code with Microsoft Authenticator, Google Authenticator, or similar.
- Save the backup codes shown once at enrolment (or after regenerating).
- At sign-in: password first, then a six-digit code (or a backup code).
- SSO accounts use MFA from your identity provider - not SchoolRota.
- Admins can Reset MFA on another user if they lose their device (they must re-enrol on next sign-in).
- Office users with a local password may enable MFA optionally from Account.
Backup codes
Each backup code works once. Store them securely (password manager or printed copy in the school safe). Use Regenerate backup codes if you lose the list.
Change history
Open the Change history tab for paginated history: when, who, what, and details.

Compliance
Publishes, invites, and configuration changes should appear here. Use it when investigating “who changed the board?”
Sign out
Use Sign out at the bottom of the sidebar, on Account, or in the focused setup header during first-run.
After a person has a linked login, Microsoft profile photos can replace initials on the rota.

