CampusOps HQ · Checking environment…
CampusOps HQSchool IT Operations

SCHOOL IT OPERATIONS

Welcome back

Sign in to manage devices, students, locations, distribution, and day-to-day school IT operations from one secure workspace.

Start typing at least 3 letters. CampusOps HQ suggests active organizations already using the platform, so you do not need to know the login slug. Spaces, capitalization, and punctuation are normalized automatically.
CampusOps HQ School IT Operations · v3.9 Alpha
Checking…
Not signed in
No role
No campus
School Year: Not set
No session

OPERATIONS OVERVIEW

Dashboard

Organization-wide visibility into devices, students and daily operations.

VIEWINGAll authorized locations
SCHOOL YEARLoading…
LAST REFRESH

Chromebook status

Current device state for the selected location.

Inventory by school / location

Compare Chromebook distribution across your organization.

Location operations

Students, inventory, assignments and issues by school/site.

Quick actions

Common IT workflows.

Recent activity

Permanent transaction trail for the selected location.

CUSTOMER ONBOARDING

Setup Guide

Get this organization operational without guessing what comes next. Required steps are based on the organization’s live CampusOps HQ data; optional integrations never block readiness.

Checking setup…

CampusOps HQ is reviewing this organization.

CHECKING
0%

Required for operations

Complete these before relying on CampusOps HQ for day-to-day device distribution.

Recommended / Optional

Helpful security and integration improvements that do not block normal CSV-based operation.

Launch principles

What customers should know before they start.

Student & device onboardingCSV import is fully supported
Google Directory live syncOptional advanced integration
Chromebook careBuilt-in electronic operational acknowledgment
Billing changesNever delete organization records
Setup checklistRead-only status; no automatic data changes

STUDENT SELF-SERVICE

My CampusOps HQ

Your school IT profile and devices. This portal can only access the student record linked to your signed-in account.

Loading your profile…

NATIVE STICKER-FREE SCANNING

CampusOps HQ Scan for Android

The native Android companion signs directly into CampusOps HQ. No Safari/Chrome scanner page, temporary tunnel pairing, QR pairing code, or Bluetooth pairing is required.

Android app

Included with this standalone build under android/CampusOps HQScan.

OrganizationLoading…
AuthenticationDirect staff sign-in
Chromebook identityAlt + V hardware serial
OCRNative CameraX + ML Kit
Local Windows connectionADB USB reverse
Production connectionPermanent HTTPS CampusOps HQ API

What the phone can test now

Native app functions are permission-scoped to the staff account signed into the phone.

Alt + V serial OCRReady
Unknown serial acknowledgementReady
Chromebook → assigned studentReady
Student → assigned ChromebookReady
Distribution API foundationReady
Campus Intake API foundationReady

Windows USB test connection

During development, the phone connects straight to your local CampusOps HQ server through ADB. This avoids temporary trycloudflare.com links entirely.

  1. Run npm run dev on the Windows PC.
  2. Enable Developer Options and USB debugging on the Android phone.
  3. Connect the phone with a USB data cable and approve the debugging prompt.
  4. Run adb devices, then adb reverse tcp:8787 tcp:8787.
  5. Run the CampusOps HQ Scan debug app from Android Studio.
  6. Leave the app server as http://127.0.0.1:8787 and sign in with a CampusOps HQ staff account.

The HTTP exception exists only in the Android debug build for the USB development connection. Release builds require HTTPS.

HALLWAY RECOVERY

Identify Found Chromebook

No sticker required. Use Alt + V on the Chromebook, then read its serial from the screen.

USB scanner: click the field once, then scan. Most scanners send Enter automatically.

ONLY frame SN: + serial here
OCR text
No capture yet.

Camera access requires HTTPS on phones. Keep SN: + serial level inside the blue guide, but do not move so close that the text becomes blurry. CampusOps HQ will refocus when the browser allows it and digitally magnify the SN area for OCR.

Useful for physical labels when present. Digital serial identification remains the fallback when labels are removed.

Ready to identify

Scan a serial number, read it from the Chromebook screen, or scan a QR/barcode.

FAST DESK MODE

Checkout / Return

Designed for a physical USB scanner: student first, device second.

Issue device

Permanent assignment or daily loaner.

Return device

Scan the Chromebook and make it available again.

START-OF-YEAR WORKFLOW

Chromebook Distribution

One focused workflow: select a student, complete required paperwork, verify the Chromebook, and assign it.

Working campus
School year
Student campus will automatically control assignment.Student identity source is organization-configurable.
1Student
2Acknowledgment
3Chromebook
4Complete

STEP 1

Find Student

Search the CampusOps HQ roster by name, student ID, or school email.

Type a student name, ID, or email, then press Search or Enter.
StudentPaperworkDevice

Select a student

CampusOps HQ will automatically use that student's campus for the assignment.

STEP 3

Verify & Assign Chromebook

Type or scan the serial/asset tag. CampusOps HQ checks the selected student, paperwork, campus, pool, and device status together.

Select a student above before checking a Chromebook.

No Chromebook checked yet.

OPTIONAL INVENTORY STAGING

Move Chromebooks Into a School / Location

Optional: pre-stage available devices at a school or location. If you leave a Chromebook in Shared Inventory, permanent assignment will automatically move it to the student’s school.

Recent Distribution Activity

Campus intake, paperwork changes, and permanent assignments are audited.

ASSET DATABASE

Chromebook Inventory

Search and manage the fleet. Device creation stays out of the way until you need it.

0 ChromebooksAll inventory
AssetSerialModelPoolStatusAssigned ToCampusLocation
Showing 0

DATA ONBOARDING

Import Center

Bring an entire school or district into CampusOps HQ without copying rows by hand. Choose a file once; CampusOps HQ handles batching, validation, de-duplication, and progress.

BUILT FOR LARGE ROSTERS & FLEETS

One file. Up to 5,000 records.

Files are processed in safe server batches automatically. Keep this page open while the progress screen runs.

5,000records / import
Autosafe server batches
0copy / paste steps

LIVE GOOGLE DIRECTORY · READ ONLY

Google Workspace + Chrome Enterprise Sync

Connect a customer Google Workspace tenant using domain-wide delegation. CampusOps HQ only reads student users and managed ChromeOS devices; it does not change Google accounts, organizational units, device state, or policies.

Not configured
Connection & student OU mapping
Platform service accountNot configured by Platform Owner
Domain-wide delegation Client ID
Required read-only scopes

Only Google users inside the mapped student OU paths are synchronized. The root OU cannot be used. More-specific paths take priority.

Run live synchronizationStudent users are mapped into CampusOps HQ by Google OU. New ChromeOS devices enter Organization Shared Inventory so school staff can place them deliberately.
StartedResourceStatusSeenCreatedUpdatedSkippedErrors
No live sync history yet.

GOOGLE / CHROME ENTERPRISE

Import Managed ChromeOS Devices

Choose the CSV exported from Google Admin. CampusOps HQ recognizes deviceId and serialNumber, preserves Google management metadata, and places new devices in Organization Shared Inventory.

Google CSV

STUDENT ROSTER

Import Students from CSV

Use this as a universal fallback when live Google synchronization is not configured, or for schools using Microsoft/SIS exports. Upload the roster, map its columns, choose a default campus, then import the entire file.

Universal CSV

STUDENT ROSTER

Students

Search the roster first. Add/edit tools open only when needed.

StudentIDGradeEmailCampusIdentityAssigned DeviceProfile

STUDENT IT PROFILE

Student Profile

Complete device custody, agreements, receipts, and activity.

Loading student profile…

INTEGRATIONS

Google Workspace / Chrome Enterprise

Use read-only live Google Directory synchronization for mapped student users and managed ChromeOS devices, with CSV imports retained as a fallback.

Connection status

Live Directory connection status for this organization.

Google / Chrome Enterprise ecosystem

Schools can use live synchronization or CSV fallback without changing CampusOps HQ's official custody and assignment records.

ChromeOS device CSV importAvailable fallback
Google Workspace student identityLive read-only sync
ChromeOS Directory synchronizationLive read-only sync
CampusOps HQ custody stateNever overwritten by Google

CHROME ENTERPRISE IMPORT

Managed Device Import

Device file onboarding has moved into the dedicated Import Center, with file browsing, 5,000-device imports, validation, de-duplication, and live progress.

Student Google links

Linked Workspace identity plus any stored Classroom relationship records. Local development remains fictional-only.

StudentSchool EmailGoogle StatusClassrooms

ACCESS CONTROL

Feature Permissions

Override individual staff capabilities without changing their base CampusOps HQ role. Campus and tenant boundaries still apply.

Select User

Student portal accounts intentionally cannot receive staff overrides.

Override Rules

Inherit uses the selected role's normal rule. Allow adds a feature. Deny removes it.

These overrides never expand campus or organization scope. A Watts-only user remains Watts-only.

Feature Matrix

Base role access and the selected user's explicit override.

APPROVAL AUTHORITY

Approval Permissions

Choose which staff may review or make final decisions for protected CampusOps HQ workflows. Approval authority never bypasses campus or organization scope.

Select Staff Member

Administrators are built-in final approvers. Student portal accounts cannot receive approval authority.

Authority Levels

NoneNo approval access
Review onlyMay review when workflow is built
Approve / DenyMay make final decision

A Watts-only approver remains Watts-only. Granting approval authority does not reveal another campus or organization.

Approval Matrix

These categories will power the future Approval Center and Account Services workflows.

STAFF & ACCOUNT SECURITY

User Accounts

View staff first; account creation and controls open only when needed.

CampusOps HQ Users

Organization accounts, roles, campus scope, last login, and current session count.

UserRoleCampus ScopeStatusLast LoginSessionsLogin GuardAction

Recent Account Status Changes

Disable and re-enable actions are recorded with the administrator identity and optional reason.

TimeUserChangePerformed ByReason

SESSION SECURITY

Session & Login Security

Control session expiration and automatic temporary lockouts after repeated failed sign-in attempts. All limits are enforced by the server.

Organization Session Policy

A session ends when no protected CampusOps HQ action occurs for this many minutes. Allowed: 5–240.

This is a hard limit from sign-in time, even while the user stays active. Allowed: 1–24.


Failed-login protection

Allowed: 3–20 attempts.

Only failures inside this rolling observation window count together. Allowed: 5–60.

After the threshold is reached, that organization + email sign-in identifier is blocked for this period. Allowed: 5–240.

Current Security State

Active sessions
Idle policy
Absolute maximum
Failed-login rule
Temporarily locked identifiers
Last policy update
CampusOps HQ does not use a background heartbeat to keep abandoned sessions alive. Failed-login protection is applied uniformly to an organization + email identifier, whether or not that email belongs to a real account.

SECURITY AUDIT

Login History

Review authentication activity for this organization. CampusOps HQ records security metadata only—never passwords.

Authentication Events

Newest first. Network address and browser/device user-agent are captured when the request provides them.

TimeEventUser / EmailOutcomeNetworkReasonBrowser / Device

ORGANIZATION STRUCTURE

Schools & Locations

One organization can contain multiple school sites, district offices, warehouses, storage areas, and other locations. Students belong to a school/location; Shared Inventory remains the neutral organization-wide device pool.

NEUTRAL ORGANIZATION-WIDE POOL

Organization Shared Inventory

New Chromebooks and devices enter here by default. They remain neutral until manually moved or permanently assigned to a student, at which point CampusOps HQ automatically relocates the device to that student’s school/location.

DISTRIBUTION ADMINISTRATION

School Years & Agreement Types

Configure the annual distribution cycle and the paperwork CampusOps HQ uses to determine permanent-assignment eligibility.

Historical safety: CampusOps HQ never deletes prior agreement or assignment history from this screen. Once a school year has been used, its name and dates lock; status can still be managed.

Add School Year

Only one school year can be Active at a time.

Planning years can be edited until agreement/distribution history exists.

Add Agreement Type

Agreement codes are permanent identifiers after creation.

Deactivating a type hides it from future distribution intake without deleting historical student agreement records.

School Years

Planning, active, and historical distribution cycles.

School YearDatesStatusUsageHistory Lock

Agreement Types

Organization-wide paperwork definitions used by the Distribution Center.

AgreementCodeRequiredStatusRecorded History

IN-APP ALERTS

Notifications

Operational alerts, support updates, and setup reminders without relying on email or SMS.

CAMPUSOPS HQ SUPPORT

Support

Create a support request without leaving CampusOps HQ. Organization and account context are attached automatically.

Tickets

Your requests. Administrators and IT Admins can see organization-wide tickets.

Select a ticket

Messages and status history will appear here.

ACCOUNT CONTACT

My Account

Keep phone information ready for future account recovery, security alerts, and SMS verification. Phone verification is not enabled yet.

CampusOps HQ Account

Your signed-in organization identity.

Phone Numbers

Saved privately to your organization account.

Phone verification will be added with 2FA later.

Password

Change your CampusOps HQ password. Other web sessions and all mobile sessions are revoked after a successful change.

SECURITY

Requires 14+ characters with uppercase, lowercase, a number, and a symbol.

Authenticator App (2FA)

Administrators can protect their account with a standards-based 6-digit authenticator code.

Checking…

ORGANIZATION PROFILE

Organization Settings

Contact information, operating defaults, and school-wide CampusOps HQ preferences.

Organization Contact

Operations Defaults

Defaults used by future inventory and checkout actions.

When available loaners fall to this number or lower, users with Notifications access receive an alert.

IT Contact

Primary technical contact for the organization.

Billing Contact

Stored now so billing can be connected later without redesigning the organization profile.

COMMERCIAL PRODUCT FOUNDATION

Organization & License

CampusOps HQ is now designed as a paid multi-school SaaS product. The development school uses the same paid plan through a complimentary owner-issued license.

Subscription & access

Your organization’s commercial status and licensed capacity.

StatusLoading…

Billing

Secure subscription checkout and billing management through Stripe.

Loading billing status…

Tenant isolation

Every student, asset, transaction, report, Google link, and future account action belongs to an organization.

CampusOps HQ uses authenticated sessions and server-enforced roles and approval authority. Administrator has full organization/commercial access; IT Admin has broad day-to-day operational access; Technician handles device operations; Office Staff can perform student/device lookup plus daily loaner checkout/return only; future roles remain locked down until explicitly configured.

ACCOUNTABILITY & YEAR-END

Inventory Reports

Current Chromebook inventory plus activity for a selected school-year period.

CampusOps HQ Chromebook Inventory Report

Select a period to generate the report.

Current Inventory Snapshot

Where every registered Chromebook stands right now.

Period Activity

Transactions recorded during the selected date range.

Currently Issued / Loaned Devices

Device-level accountability at the time this report was generated.

AssetSerialStatusPoolStudentStudent ID

Reporting note: “Currently Assigned” is a live inventory count. “Issued this period” and “Returned this period” are transaction counts. Unique-device counts are shown separately so reissues do not inflate the number of physical Chromebooks.

AUDIT TRAIL

Transaction History

Assignments, loaners, returns, and found-device events remain recorded.

TimeActionAssetStudentReasonPerformed By