Skip to contentSkip to content
EDUBaseCloud
Guide

Login & Access: Staff Logins on Two Devices

A staff member can open their own account on a desk computer and again on a phone browser, but two people should never share one username: EDUBase signs staff in with school code, username and password, sessions expire, and the activity log records what the username did, not who typed it.

What actually happens when one login is used on two devices?

A cloud portal treats each browser or app as a separate signed-in session. The fee clerk who opens EDUBase on the counter PC and then on the office laptop is simply holding two sessions against the same username. Both see the same data, because the data lives in the school's database on the server, not on the machine.

The important consequence is not technical, it is accountability. EDUBase's User Logging page records who created, changed or deleted a record, with the changed fields highlighted and a severity badge. If two clerks share one username, the log can only tell you the username. A voided fee transaction, a discount, a changed fee plan — all of it becomes untraceable to a person.

EDUBase sessions expire, so an unattended screen does not stay open indefinitely. Staff passwords are reset by an admin, which means you can cut off a device by resetting the password rather than hunting for the machine.

  • Staff sign in with the institute code, a username and a password.
  • Sessions expire; a forgotten login on a shared PC does not stay live forever.
  • User Logging shows who changed what, with the record opened and the change highlighted.
  • A daily summary of important changes reaches the navbar bell and the Owner App.
  • Password reset is done by an admin, so access can be withdrawn quickly.

Why should every staff member have their own login?

EDUBase allows unlimited staff logins, so there is no reason to make the accounts clerk and the front desk share one. Rights are granted per user, per screen and per action, including view-only versus edit, and a user can be restricted to the campuses they belong to.

Separate logins also make your approval chain real. Payments, discounts, salary changes, admissions and leave can require a second person — that control only means something when the requester and the approver are genuinely two accounts.

For teachers, the app login is created from the employee record in Staff Management, and classes and subjects are assigned there. That is the same identity the teacher uses to mark attendance, write the diary and message parents, so a shared teacher account would mix up diary entries and attendance marks between staff.

  • Unlimited staff logins, so each person gets one.
  • Per-user, per-screen and per-action privileges; campus scope limits what a user can reach.
  • Approvals only work as a control when requester and approver are different accounts.
  • Teacher App logins are created from the employee record and tied to assigned classes.
  • Requisitions keep request, approve and issue as three separate permissions.

How do parents, owners and gate devices sign in differently?

Not every user type uses a username and password. Parents log in to the Parents App with a rotating one-time code sent to the registered mobile, so there is no shared password to leak between families, and staff can look up or reissue that code from the Parent App OTP Portal when the SMS does not arrive.

Attendance hardware is treated as a separate identity again. Attendance tablets, QR scanner phones, face attendance gates and the SMS sending phone each hold their own revocable device token. A tablet that goes missing is cut off on its own, without changing anybody's password.

All portal, app and integration traffic runs over HTTPS, and each school's records sit in its own database on EDUBase's managed servers, so one school's logins can never reach another school's data.

  • Parents: one-time code to the registered mobile, no shared password.
  • Staff and owners: institute code plus username and password on web and the Android apps.
  • Devices: revocable tokens per tablet, scanner or sender phone.
  • One database per school; HTTPS on the portal, apps and integrations.

What should a school's login policy look like in practice?

Write down the rule once and enforce it with privileges rather than trust. The pattern most schools settle on is: one account per human being, rights granted by job, campus scope applied to multi-campus staff, and approvals switched on for money and HR changes.

Then use the reports you already have. The activity log with its severity badges tells you what happened; the owner's daily summary tells you without logging in at all. Day Wise Paid Challans shows collections by day and by user, which is the cash-up check on your counter staff.

  • One login per person; never one login per desk or per department.
  • Grant only the screens and actions the role needs; use view-only where possible.
  • Restrict multi-campus users to their campuses from the navbar switcher.
  • Turn on approvals for payments, discounts, salary changes and admissions.
  • Review User Logging and Day Wise Paid Challans as a routine, not only after a dispute.

How each type of EDUBase user signs in and on what

User typeHow they sign inUsual devicesWhat the school controls
Office and finance staffInstitute code, username and password on the web portalCounter PC, office laptop, phone browserPer-screen and per-action rights, campus scope, admin password reset
TeachersLogin created from the employee record, used in the Teachers AppTheir own Android phone, web portalAssigned classes and subjects, leave and diary approval
Owner or principalInstitute code, username and password in the Owners App and portalPhone, any computerAll campuses, approvals, announcements, message oversight
ParentsRotating one-time code sent to the registered mobileTheir own Android phoneOTP portal for login help, feature restrictions by months overdue
Attendance devicesTheir own revocable device token, not a staff passwordQR scanner phone, biometric terminal, face attendance tabletRegistered devices list; remove or pause a gate
SMS sender phonePortal-issued credential for the free SMS Sending AppOne Android phone per campus with the school's SIMCampus-wise sending, SMS report and delivery logs

Related

Frequently asked questions

Can two staff members share one username to save time?

They can physically, but you should not allow it: the activity log attributes every change to the username, so a shared account destroys your audit trail and makes approvals meaningless. EDUBase allows unlimited staff logins, so there is no saving in sharing one.

Is there a limit on how many staff logins we can create?

EDUBase supports unlimited staff logins, each with its own per-screen and per-action privileges and campus scope. You create them for staff from the users screen, and a teacher's app login is created from the employee record.

What happens if a staff member leaves while still logged in somewhere?

Sessions expire, and an admin can reset the staff member's password, which stops further sign-ins with that account. Attendance tablets and sender phones hold separate revocable device tokens, so those are withdrawn independently.

Can I see what a user did from a device I do not control?

Yes. User Logging records who created, changed or deleted a record with the severity marked, and a link opens the record with the change highlighted; a daily summary of important changes reaches the Owner App.

Do parents need a password if the whole family uses one phone?

No. Parents log in with a rotating one-time code sent to the registered mobile number, and staff can look up or issue that code from the Parent App OTP Portal if the SMS does not arrive.

Can a user who works at two campuses use one login for both?

Yes. A user is granted the campuses they need and switches campus from the top bar; owners see all campuses, and reports can be viewed per campus or combined.

Does using the portal on a phone browser need a separate account?

No. The same staff account signs in on the web portal from any device over HTTPS. The Teachers and Owners apps use the same identity for the tasks built into those apps.

Ready to see it on your own data?

Book a free demo, or message us on WhatsApp and we will reply in working hours.

Book a demo WhatsApp