Trust

Institution Controls: School Sign-in and Student Roles

Schools and districts can keep students on their school Google accounts, turn off email sign-in on managed Chromebooks, stop students from creating Spaces, and let them join only Spaces a staff member co-runs.

Schools and districts asked us for a way to use Vivipod with students without opening a door to the rest of the internet. These controls answer three questions an IT team usually has:

  • Who can sign in? Only students' school accounts, on the devices you manage.
  • Who can create Spaces? Staff, but not students, if that is your policy.
  • Who can students join? Only Spaces that one of your staff helps run.

The first is set in your Google Admin console. The other two we set up for your school or district: email us and we will configure them with you.

Table of Contents

Keep sign-in on school accounts

On Chromebooks your district manages, students can be limited to their school Google account, with personal email sign-in turned off.

On a managed device, the sign-in page offers only Google and tells students to use their organization account.

All of this is in the Google Admin console, for the organizational unit that holds your students or their devices:

  1. Allow only school Google accounts. Under Chrome's sign-in settings, restrict device sign-in to your domain, turn off Guest mode, and allow secondary accounts only from your Google Workspace domains. Continue with Google then works only with a school account; Google turns the rest away.

  2. Tell Vivipod which sign-in methods to offer. Force-install https://vivipod.com as an app for the same unit and set its managed configuration to:

    { "allowedAuthMethods": ["google"] }
    

    The sign-in page then offers only what you list, here only Google, as above. A sign-in method we add later stays off your devices until you add it to the list. If the list has a mistake in it, the page offers nothing and tells students to ask IT, so you'll see it on your first test device. This step is for ChromeOS, and it also puts Vivipod in the launcher.

  3. Block email sign-in in your web filter. Block vivipod.com/auth/email/ and every address under it. Every step of signing in with an email code is there. In the Admin console's URL blocklist, that address on its own is enough: it blocks everything that starts with it, and a * at the end isn't allowed. In a filter that matches exact addresses, use its wildcard form, such as vivipod.com/auth/email/*. Don't block vivipod.com/auth/ itself: Google sign-in is under it.

    This is what stops a personal email address from being used: step 2 only decides what the sign-in page shows, and it doesn't apply in Incognito or in another browser. To check the rule on a student device, vivipod.com/auth/email/probe should be blocked and vivipod.com/auth/probe should load.

  4. Disallow Incognito for the same unit.

Email us and we will send the full walkthrough for your Admin console.

Decide who can create Spaces

Students in your district can be prevented from creating Spaces of their own. Staff create them as before.

A student who tries to create a Space sees your district's name and why they can't.

The rule follows the person, not the device. It applies wherever the student signs in, including at home.

Keep students in Spaces your staff help run

Students can join a Space only while one of your staff is an owner or admin of it. We call that staff member a co-admin. A student who opens a Space outside your district, with none of your staff running it, can still read an Open Space but can't join or request to join it.

Joining a Space no district staff member runs is refused, and the message says what would make it possible.

This is what makes shared classes work. In a dual-enrollment course, the college instructor owns the Space and makes the district teacher an admin. From then on, district students can join it like any other Space.

The college instructor owns the Space; the district teacher is an admin, which lets district students join.

A staff member counts once Vivipod has confirmed their email address with a one-time code. Signing in with Google alone doesn't confirm it: staff are asked for a code the first time they create a Space, and the Members panel names a co-admin who still needs to confirm. Staff from outside your domain, such as a partner college's instructor you trust with your students, can be added to your staff by name.

If the co-admin leaves

If the last staff member steps down or is removed as an admin, students who are already in the Space keep their access, and their work stays. No new students from your district can join until another staff member is added. The owner and admins see why in the Members panel, and the staff member who was removed is notified.

Without a district co-admin, the Members panel says so. Students who already joined stay.

Requests waiting for approval are marked too, so an admin knows why approval won't go through.

A pending request shows what it needs before it can be approved.

How we set it up

Email support@vivipod.com with:

  • the email domains your students sign in with, and the ones your staff use
  • any staff outside those domains who should count, such as partner instructors
  • whether staff may create Spaces and join outside Spaces on their own (the usual choice) or should be held to the same rules as students

Settings apply to existing accounts as well as new ones, and you can change them at any time. Students or staff with no connection to your district are not affected.

What these controls don't cover

  • Reading Open Spaces. Anyone with the link can read an Open Space without signing in, as on any website. Use your web filter if students should not open Vivipod links from outside the district. Private Spaces are visible only to their approved members.
  • Personal devices. The sign-in controls apply to devices you manage. The rules about creating and joining Spaces apply to the student's account everywhere.
  • A self-service admin page. We configure your district's rules with you on request; your team doesn't manage them in Vivipod directly.

For privacy, accessibility, and the documents your review needs, see Vivipod for institutions.