Safe OnlineExam
Roll out & operate

Instructor workflow

What instructors do from the course-navigation tool — discover assessments, set SEB policy and tools, enable enforcement, and manage passwords.

Instructors work from the course-navigation placement of the tool. This page is a short orientation you can hand to faculty; it is not a policy document.

First launch

On first use, the instructor launches the tool from the course and completes Canvas OAuth (the one-time "Connect Canvas" step). This authorizes the API access the tool needs to read assessments and set access codes. Canvas still enforces the instructor's actual course permissions.

The workflow

Refresh assessments

Refresh the course to discover published Classic Quizzes and New Quizzes. A learner can only use an assessment whose Canvas data is current, verified, published, and within its unlock/lock window — the verification window is 24 hours, and a failed refresh marks discovery stale rather than exposing a broken exam.

Set course defaults and tools

Configure course-level defaults: URL policy, start/exit password policy, and selected exam tools. Tools have an exact HTTPS launch URL and typed resource rules (exact URL, a path and its descendants, or a confirmed whole-domain rule). Wildcards, credentials, and identity-provider hosts are rejected.

Enable SEB on a quiz

Enabling requires an effective exit password (assessment override, course default, or the managed default). The tool creates the access code, writes it to the Canvas assessment, and stores SEB state only after Canvas confirms the change. The management view never reveals the code.

Add a quiz-only tool if needed

Define a tool that exists for a single quiz. It stays on that assessment and never becomes a course default or appears in other assessments.

Reveal, rotate, disable as needed

Passwords are redacted by default; a narrowly bound, short-lived reveal is available. You can rotate the access code, reset an assessment to course defaults, and disable SEB — which removes Canvas access-code protection through the intended action only.

Changing a protected setting forces a re-download

The detector sidebar is an affordance; the SEB URL filter in the generated configuration is what actually controls what can load. Changing any selected tool or URL policy changes the configuration fingerprint, so students must download a new configuration. Communicate setting changes before an exam window.

What instructors never see or handle

  • The raw Canvas access code — it is created, hidden, and rotated for them.
  • Any student's private device identity or the encryption private key.
  • Another course's data — the tool is scoped to their launch.

On this page