Head teacher / Administrator
The roles, what each can see, and how people get passwords without anyone reading one down a phone.
Each role sees only what the job needs. This is not a courtesy — it is how a bursar is kept out of learner records and a teacher out of another stream's marks.
| Role | Can do |
|---|---|
| Administrator | Everything in the school: structure, staff, settings, all marks and all cards. |
| Class teacher | Their own stream: learners, comments, report cards, register, and emailing a card to a parent. |
| Subject teacher | Marks for the subjects and streams they are assigned, and nothing else. They can read a card for a learner they teach, but cannot email one out. |
| Bursar | Money: fee structures, payments, receipts, the finance dashboard and the SMS wallet. Cannot open learner report cards. |
| Parent | Their own children only. Results, comments, attendance if you allow it, fees and receipts. |
Admin → Staff and parent logins → Create user. Give a login name and a role. For a subject teacher, assign the subject-and-stream pairs they teach; for a class teacher, assign the stream they head.
Add the person's email and use Admin → Staff setup links. They get a link, set their own password, and you never know it. That habit is what stops a school being phished.
Admin → Invite parents. GradeFlex emails the parent a link; they set their own password and are linked to their child automatically. A family with several children lands on one login that shows all of them.
Three things: the school code, the username, the password. Two schools
can both have a jokello without colliding, because the school code
tells them apart.