SPEDup has four role flags, and a person can hold more than one. Your effective permissions are the combination.
| Flag | Usually called |
|---|---|
isTeacher | Teacher |
isAdmin | School administrator |
isDistrictAdmin | District administrator |
isItinerant | Itinerant staff |
The highest role you will hold is district administrator. Anything above that is internal to the SPEDup team.
What each role is for
Teacher. Documents. Writes ABC and intervention reports, requests admin support, views the directory, sees analytics for their assigned students. Everyone who joins a school by code starts here.
School administrator. Runs a building. Everything a teacher can do, plus creating and editing students, classrooms, and staff, editing any report at the school, and deactivating records. The creator of a school gets this automatically.
District administrator. Runs a district. Schools, users, and students across the district, district wide reports, and blackout dates. Assigned to a district rather than to a single school.
Itinerant. Travels between buildings. Can switch which school they are working in. Combined with a district assignment and without the district administrator flag, this produces the district itinerant: district wide read access, can create reports and record phase changes, cannot edit teachers, students, schools, or users.
Mobile app
| Capability | School admin | District admin | Teacher | Itinerant |
|---|---|---|---|---|
| View the directory | Yes | Yes | Yes | Yes |
| Create and edit students | Yes | Yes | No | No |
| Create and edit classrooms | Yes | Yes | No | No |
| Invite staff and manage roles | Yes | Yes | No | No |
| Deactivate records | Yes | Yes | No | No |
| Create reports | Yes | Yes | Yes | Yes |
| Edit and delete own reports | Yes | Yes | Yes | Yes |
| Edit any report | Yes | Yes | No | No |
| Send admin alerts | Yes | Yes | Yes | Yes |
| Acknowledge and resolve alerts | Yes | Yes | Response team only | Response team only |
| Manage own response team | Yes | Yes | Yes | Yes |
| Switch schools | No | Yes | No | Yes |
| View student analytics | Any student | Any student | Assigned students | Assigned students |
Admin dashboard
| Capability | District admin | District itinerant | School user |
|---|---|---|---|
| Schools | Own district | View only | No |
| Users | Own district | View only | Own school |
| Students | Yes | View only | Own school |
| Classrooms | No | No | Own school |
| Reports | District wide | District wide | Own school |
| Generate data summaries | Yes | Yes | Yes |
| Blackout dates | Own district | No | No |
| Transfer a student | Yes | No | School admin |
| Record phase changes | Yes | Yes | Yes |
| Weekly email test send | Yes | No | No |
The sidebar shows only what your role can reach, so if a page is not listed for you, you do not have access to it.
Two deliberate exceptions
Phase changes are open to everyone. A phase change records intervention history, which is knowledge the person running the intervention holds. Gating it behind student administration permissions would mean the people who know cannot write it down. This is a deliberate exception to the otherwise read only posture itinerant staff have on student records.
Transfers are not. Moving a student to another school reassigns their school record, which is administration rather than documentation. Limited to district administrators and school administrators.
The self edit guardrail
Nobody can turn off their own School Admin or District Admin flag. This applies to every administrator, editing their own account.
It prevents a building from accidentally locking itself out. If your own role needs changing, another administrator has to do it.
How someone's role changes
Roles are assigned by an administrator after the person has joined a school. There is no way to grant yourself a role, and no role is granted automatically beyond the teacher flag everyone gets on joining.
- On the dashboard: Users, open the person, edit their roles
- On mobile: Directory, Staff, open the person, use the role switches
See People and roles.
A note for district IT
Permissions today are enforced in the application interface. Server side enforcement is being extended to match. Treat SPEDup access the way you would treat access to any other student data system: grant administrator roles narrowly, deactivate promptly when someone leaves, and review the user list at the start of each year.