Your account
/account, reached from Account in the top bar. Every signed-in user manages
their own.
Two-factor authentication
Section titled “Two-factor authentication”The one worth doing first.
- Click Set up authenticator app.
- Scan the QR code, or type the secret, into an authenticator (Google Authenticator, 1Password, Authy, whatever your school uses).
- Enter a six-digit code to confirm and enable it.
From then on, signing in asks for a code.
You can disable it later, which asks for a code first so somebody who has walked up to your unlocked machine cannot simply turn it off.
Turn this on before you invite anyone else. The account with every permission should be the best-protected one, not the one nobody got round to.
Change your password
Section titled “Change your password”Straightforward. Changing it does not sign you out of other sessions, so if the reason you are changing it is that somebody else knows it, sign out everywhere as well.
SSO fallback password
Section titled “SSO fallback password”If your school uses single sign-on, you can set a local password as a backup.
At least one administrator should have one. An identity provider outage should not be an outage of your service desk, and setting this up afterwards is not possible by definition.
Daily status email
Section titled “Daily status email”Opt in or out of a daily summary. It arrives each morning to staff who have it turned on, and it is a reasonable substitute for opening the dashboard first thing.
Interface style and theme
Section titled “Interface style and theme”The sun and moon toggle in the top bar switches light and dark. Your choice is remembered on the device, and your interface style preference follows you across machines, so a laptop you have not signed into before picks up what you already chose.
Your recent activity
Section titled “Your recent activity”A log of your own recent actions.
Worth glancing at occasionally. It is also the fastest way to answer “what did I change yesterday” when something you did turns out to be the reason for something else.
The full audit log covers everybody and needs the
audit.view permission. This is just yours.
What you cannot do here
Section titled “What you cannot do here”Change your own roles. Permissions are assigned by somebody with
role.manage, under users. Self-service permission
escalation would defeat the point.
Change your email. That is the sign-in identifier and it is managed by an administrator, or by SCIM if your identity provider provisions accounts.
Delete your account. Deactivation is an administrator action, so history keeps its attribution.