Administrator dashboard
What the root-account Safe Exam Browser Admin dashboard does — recovery, active-course connection, and reusable tool presets with bulk rollout.
Root-account administrators get a Canvas-embedded, school-wide dashboard in the account navigation placement, labeled Safe Exam Browser Admin. It is the recovery and rollout surface for the whole institution.
Access requirements
The dashboard requires both a signed LTI Administrator role and Canvas's signed root-account-admin value, plus an administrator OAuth grant. An instructor enrollment, a sub-account admin, or a course-level install is intentionally not enough. If it is missing or denied, see Troubleshooting → Canvas launch.
First use
Open Safe Exam Browser Admin from root-account navigation and complete its separate OAuth authorization. This upgrades your existing Canvas grant with the administrator scopes — you authorize once and reuse the same refreshable grant in every Canvas context. Only Canvas-authorized root-account courses appear; the dashboard browses active courses in bounded, server-filtered pages rather than importing the full historical catalog.
What you can do
Connect courses
Validate and connect selected active courses, then initially synchronize their Classic and New Quiz discovery. A term/course picker pages through the account catalog.
Recover passwords
Controlled, no-store reveal of course and assessment secrets — the value is shown briefly and then disappears automatically.
Rotate exit passwords & codes
Rotate a course exit password, reset an assessment exit password to its effective default, and rotate the protected Canvas access code.
Toggle SEB per assessment
Enable or disable SEB enforcement on a connected assessment, and reset an assessment to its course defaults.
School tool presets
Create reusable, validated tool definitions once and assign them to courses; queue a selected-course or all-course rollout and reconcile in bounded batches.
Review activity
Every mutation is recorded in a secret-free activity view. Reveals and rotations show that they happened, never the value.
How tool presets behave
A preset assigned to a course is synchronized into that course's catalog as
school-managed: instructors can enable or disable it but cannot silently change
its launch URL or resource access. Updating or deleting a preset synchronizes every
assigned course and invalidates the affected configuration fingerprints — students
in those courses must download a fresh .seb file. Quiz-only tool definitions
created by an instructor stay on the assessment and never become course defaults.
Safety model
Every administrator mutation additionally requires a short-lived action token bound to your LTI subject, Canvas user, root account, deployment, and current session — so a stale tab or a replayed request cannot make changes. Password reveals are no-store and bound to your session. This is why the dashboard is safe to use for live recovery during an exam window, but you should still prefer routine changes outside active assessments.
Device deployment
Install the SEB configuration-encryption identity onto exam devices through your device-management platform, non-extractably and scoped to SEB.
Instructor workflow
What instructors do from the course-navigation tool — discover assessments, set SEB policy and tools, enable enforcement, and manage passwords.