CampusOps HQ · Checking environment…
CampusOps HQSchool IT Operations

SCHOOL IT OPERATIONS

Welcome back

Sign in to manage devices, students, locations, distribution, and day-to-day school IT operations from one secure workspace.

Spaces, capitalization, and punctuation are normalized automatically. You no longer need to type the dashes exactly.
CampusOps HQ School IT Operations · v3.9 Alpha
Checking…
Not signed in
No role
No campus
No session

OPERATIONS OVERVIEW

Dashboard

Fast visibility into campus devices and daily activity.

Quick actions

Common IT workflows.

Recent activity

Permanent transaction trail.

STUDENT SELF-SERVICE

My CampusOps HQ

Your school IT profile and devices. This portal can only access the student record linked to your signed-in account.

Loading your profile…

NATIVE STICKER-FREE SCANNING

CampusOps HQ Scan for Android

The native Android companion signs directly into CampusOps HQ. No Safari/Chrome scanner page, temporary tunnel pairing, QR pairing code, or Bluetooth pairing is required.

Android app

Included with this standalone build under android/CampusOps HQScan.

OrganizationLoading…
AuthenticationDirect staff sign-in
Chromebook identityAlt + V hardware serial
OCRNative CameraX + ML Kit
Local Windows connectionADB USB reverse
Production connectionPermanent HTTPS CampusOps HQ API

What the phone can test now

Native app functions are permission-scoped to the staff account signed into the phone.

Alt + V serial OCRReady
Unknown serial acknowledgementReady
Chromebook → assigned studentReady
Student → assigned ChromebookReady
Distribution API foundationReady
Campus Intake API foundationReady

Windows USB test connection

During development, the phone connects straight to your local CampusOps HQ server through ADB. This avoids temporary trycloudflare.com links entirely.

  1. Run npm run dev on the Windows PC.
  2. Enable Developer Options and USB debugging on the Android phone.
  3. Connect the phone with a USB data cable and approve the debugging prompt.
  4. Run adb devices, then adb reverse tcp:8787 tcp:8787.
  5. Run the CampusOps HQ Scan debug app from Android Studio.
  6. Leave the app server as http://127.0.0.1:8787 and sign in with a CampusOps HQ staff account.

The HTTP exception exists only in the Android debug build for the USB development connection. Release builds require HTTPS.

HALLWAY RECOVERY

Identify Found Chromebook

No sticker required. Use Alt + V on the Chromebook, then read its serial from the screen.

USB scanner: click the field once, then scan. Most scanners send Enter automatically.

Point this box at the Alt + V serial number
OCR text
No capture yet.

Camera access requires HTTPS on phones. This alpha uses on-device browser OCR; we’ll tune speed and accuracy from your real Chromebook screens.

Useful for physical labels when present. Digital serial identification remains the fallback when labels are removed.

Ready to identify

Scan a serial number, read it from the Chromebook screen, or scan a QR/barcode.

FAST DESK MODE

Checkout / Return

Designed for a physical USB scanner: student first, device second.

Issue device

Permanent assignment or daily loaner.

Return device

Scan the Chromebook and make it available again.

START-OF-YEAR WORKFLOW

Chromebook Distribution

One focused workflow: select a student, complete required paperwork, verify the Chromebook, and assign it.

Working campus
School year
Student campus will automatically control assignment.Student identity source is organization-configurable.
1Student
2Paperwork
3Chromebook
4Complete

STEP 1

Find Student

Search the CampusOps HQ roster by name, student ID, or school email.

StudentPaperworkDevice

Select a student

CampusOps HQ will automatically use that student's campus for the assignment.

STEP 3

Verify & Assign Chromebook

Type or scan the serial/asset tag. CampusOps HQ checks the selected student, paperwork, campus, pool, and device status together.

Select a student above before checking a Chromebook.

No Chromebook checked yet.

CAMPUS INVENTORY

Move Chromebooks Into a Campus

Use this before distribution to move available devices from Shared Inventory or another authorized campus.

Recent Distribution Activity

Campus intake, paperwork changes, and permanent assignments are audited.

ASSET DATABASE

Chromebook Inventory

Search and manage the fleet. Device creation stays out of the way until you need it.

0 ChromebooksAll inventory
AssetSerialModelPoolStatusAssigned ToCampusLocation
Showing 0

DATA ONBOARDING

Import Center

Bring an entire school or district into CampusOps HQ without copying rows by hand. Choose a file once; CampusOps HQ handles batching, validation, de-duplication, and progress.

BUILT FOR LARGE ROSTERS & FLEETS

One file. Up to 5,000 records.

Files are processed in safe server batches automatically. Keep this page open while the progress screen runs.

5,000records / import
Autosafe server batches
0copy / paste steps

LIVE GOOGLE DIRECTORY · READ ONLY

Google Workspace + Chrome Enterprise Sync

Connect a customer Google Workspace tenant using domain-wide delegation. CampusOps HQ only reads student users and managed ChromeOS devices; it does not change Google accounts, organizational units, device state, or policies.

Not configured
Connection & student OU mapping
Platform service accountNot configured by Platform Owner
Domain-wide delegation Client ID
Required read-only scopes

Only Google users inside the mapped student OU paths are synchronized. The root OU cannot be used. More-specific paths take priority.

Run live synchronizationStudent users are mapped into CampusOps HQ by Google OU. New ChromeOS devices enter Organization Shared Inventory so school staff can place them deliberately.
StartedResourceStatusSeenCreatedUpdatedSkippedErrors
No live sync history yet.

GOOGLE / CHROME ENTERPRISE

Import Managed ChromeOS Devices

Choose the CSV exported from Google Admin. CampusOps HQ recognizes deviceId and serialNumber, preserves Google management metadata, and places new devices in Organization Shared Inventory.

Google CSV

STUDENT ROSTER

Import Students from CSV

Use this as a universal fallback when live Google synchronization is not configured, or for schools using Microsoft/SIS exports. Upload the roster, map its columns, choose a default campus, then import the entire file.

Universal CSV

STUDENT ROSTER

Students

Search the roster first. Add/edit tools open only when needed.

StudentIDGradeEmailCampusIdentityAssigned DeviceProfile

STUDENT IT PROFILE

Student Profile

Complete device custody, agreements, receipts, and activity.

Loading student profile…

INTEGRATIONS

Google Workspace / Chrome Enterprise

Use read-only live Google Directory synchronization for mapped student users and managed ChromeOS devices, with CSV imports retained as a fallback.

Connection status

Live Directory connection status for this organization.

Google / Chrome Enterprise ecosystem

Schools can use live synchronization or CSV fallback without changing CampusOps HQ's official custody and assignment records.

ChromeOS device CSV importAvailable fallback
Google Workspace student identityLive read-only sync
ChromeOS Directory synchronizationLive read-only sync
CampusOps HQ custody stateNever overwritten by Google

CHROME ENTERPRISE IMPORT

Managed Device Import

Device file onboarding has moved into the dedicated Import Center, with file browsing, 5,000-device imports, validation, de-duplication, and live progress.

Student Google links

Linked Workspace identity plus any stored Classroom relationship records. Local development remains fictional-only.

StudentSchool EmailGoogle StatusClassrooms

ACCESS CONTROL

Feature Permissions

Override individual staff capabilities without changing their base CampusOps HQ role. Campus and tenant boundaries still apply.

Select User

Student portal accounts intentionally cannot receive staff overrides.

Override Rules

Inherit uses the selected role's normal rule. Allow adds a feature. Deny removes it.

These overrides never expand campus or organization scope. A Watts-only user remains Watts-only.

Feature Matrix

Base role access and the selected user's explicit override.

APPROVAL AUTHORITY

Approval Permissions

Choose which staff may review or make final decisions for protected CampusOps HQ workflows. Approval authority never bypasses campus or organization scope.

Select Staff Member

Administrators are built-in final approvers. Student portal accounts cannot receive approval authority.

Authority Levels

NoneNo approval access
Review onlyMay review when workflow is built
Approve / DenyMay make final decision

A Watts-only approver remains Watts-only. Granting approval authority does not reveal another campus or organization.

Approval Matrix

These categories will power the future Approval Center and Account Services workflows.

STAFF & ACCOUNT SECURITY

User Accounts

View staff first; account creation and controls open only when needed.

CampusOps HQ Users

Organization accounts, roles, campus scope, last login, and current session count.

UserRoleCampus ScopeStatusLast LoginSessionsLogin GuardAction

Recent Account Status Changes

Disable and re-enable actions are recorded with the administrator identity and optional reason.

TimeUserChangePerformed ByReason

SESSION SECURITY

Session & Login Security

Control session expiration and automatic temporary lockouts after repeated failed sign-in attempts. All limits are enforced by the server.

Organization Session Policy

A session ends when no protected CampusOps HQ action occurs for this many minutes. Allowed: 5–240.

This is a hard limit from sign-in time, even while the user stays active. Allowed: 1–24.


Failed-login protection

Allowed: 3–20 attempts.

Only failures inside this rolling observation window count together. Allowed: 5–60.

After the threshold is reached, that organization + email sign-in identifier is blocked for this period. Allowed: 5–240.

Current Security State

Active sessions
Idle policy
Absolute maximum
Failed-login rule
Temporarily locked identifiers
Last policy update
CampusOps HQ does not use a background heartbeat to keep abandoned sessions alive. Failed-login protection is applied uniformly to an organization + email identifier, whether or not that email belongs to a real account.

SECURITY AUDIT

Login History

Review authentication activity for this organization. CampusOps HQ records security metadata only—never passwords.

Authentication Events

Newest first. Network address and browser/device user-agent are captured when the request provides them.

TimeEventUser / EmailOutcomeNetworkReasonBrowser / Device

ORGANIZATION STRUCTURE

Locations & Campuses

Create and manage every physical location inside this organization. Shared Inventory remains organization-wide and is never treated as a campus.

ORGANIZATION-WIDE

Organization Shared Inventory

New imported Chromebooks can stay here until a campus claims them. This is not a physical campus and cannot be deactivated.

DISTRIBUTION ADMINISTRATION

School Years & Agreement Types

Configure the annual distribution cycle and the paperwork CampusOps HQ uses to determine permanent-assignment eligibility.

Historical safety: CampusOps HQ never deletes prior agreement or assignment history from this screen. Once a school year has been used, its name and dates lock; status can still be managed.

Add School Year

Only one school year can be Active at a time.

Planning years can be edited until agreement/distribution history exists.

Add Agreement Type

Agreement codes are permanent identifiers after creation.

Deactivating a type hides it from future distribution intake without deleting historical student agreement records.

School Years

Planning, active, and historical distribution cycles.

School YearDatesStatusUsageHistory Lock

Agreement Types

Organization-wide paperwork definitions used by the Distribution Center.

AgreementCodeRequiredStatusRecorded History

COMMERCIAL PRODUCT FOUNDATION

Organization & License

CampusOps HQ is now designed as a paid multi-school SaaS product. The development school uses the same paid plan through a complimentary owner-issued license.

Commercial model

Pricing is deliberately not hard-coded yet.

ProductPaid SaaS
Tenant modelOne organization per school/customer
Development schoolComplimentary Pro
Future billingPayment provider integration planned

Tenant isolation

Every student, asset, transaction, report, Google link, and future account action belongs to an organization.

CampusOps HQ uses authenticated sessions and server-enforced roles and approval authority. Administrator has full organization/commercial access; IT Admin has broad day-to-day operational access; Technician handles device operations; Office Staff can perform student/device lookup plus daily loaner checkout/return only; future roles remain locked down until explicitly configured.

ACCOUNTABILITY & YEAR-END

Inventory Reports

Current Chromebook inventory plus activity for a selected school-year period.

CampusOps HQ Chromebook Inventory Report

Select a period to generate the report.

Current Inventory Snapshot

Where every registered Chromebook stands right now.

Period Activity

Transactions recorded during the selected date range.

Currently Issued / Loaned Devices

Device-level accountability at the time this report was generated.

AssetSerialStatusPoolStudentStudent ID

Reporting note: “Currently Assigned” is a live inventory count. “Issued this period” and “Returned this period” are transaction counts. Unique-device counts are shown separately so reissues do not inflate the number of physical Chromebooks.

AUDIT TRAIL

Transaction History

Assignments, loaners, returns, and found-device events remain recorded.

TimeActionAssetStudentReasonPerformed By