Instructor workflow
What instructors do from the course-navigation tool — discover assessments, set SEB policy and tools, enable enforcement, and manage passwords.
Instructors work from the course-navigation placement of the tool. This page is a short orientation you can hand to faculty; it is not a policy document.
First launch
On first use, the instructor launches the tool from the course and completes Canvas OAuth (the one-time "Connect Canvas" step). This authorizes the API access the tool needs to read assessments and set access codes. Canvas still enforces the instructor's actual course permissions.
The workflow
Refresh assessments
Refresh the course to discover published Classic Quizzes and New Quizzes. A learner can only use an assessment whose Canvas data is current, verified, published, and within its unlock/lock window — the verification window is 24 hours, and a failed refresh marks discovery stale rather than exposing a broken exam.
Set course defaults and tools
Configure course-level defaults: URL policy, start/exit password policy, and selected exam tools. Tools have an exact HTTPS launch URL and typed resource rules (exact URL, a path and its descendants, or a confirmed whole-domain rule). Wildcards, credentials, and identity-provider hosts are rejected.
Enable SEB on a quiz
Enabling requires an effective exit password (assessment override, course default, or the managed default). The tool creates the access code, writes it to the Canvas assessment, and stores SEB state only after Canvas confirms the change. The management view never reveals the code.
Add a quiz-only tool if needed
Define a tool that exists for a single quiz. It stays on that assessment and never becomes a course default or appears in other assessments.
Reveal, rotate, disable as needed
Passwords are redacted by default; a narrowly bound, short-lived reveal is available. You can rotate the access code, reset an assessment to course defaults, and disable SEB — which removes Canvas access-code protection through the intended action only.
Changing a protected setting forces a re-download
The detector sidebar is an affordance; the SEB URL filter in the generated configuration is what actually controls what can load. Changing any selected tool or URL policy changes the configuration fingerprint, so students must download a new configuration. Communicate setting changes before an exam window.
What instructors never see or handle
- The raw Canvas access code — it is created, hidden, and rotated for them.
- Any student's private device identity or the encryption private key.
- Another course's data — the tool is scoped to their launch.
Administrator dashboard
What the root-account Safe Exam Browser Admin dashboard does — recovery, active-course connection, and reusable tool presets with bulk rollout.
Student experience
What a student does — connect Canvas once, run a setup check, download a fresh configuration, and take the exam in SEB — and what the tool does for them.