User Access
Audience: District Admins holding a user type out of TKG Analytics, whether for an hour while they load and check data or for the whole year. Admins, Platform Admins and anyone holding the Maintenance add-on can do the same.
What It Is
Your district holds one lock for each of its three user types: District Users, School Users and Teacher Users. While a type is locked, every member of that type is held out of TKG Analytics and sees a page saying so. District Admins have no lock and are never held out.
A member's type is the highest primary role their membership holds, in the order District User, School User, Teacher User, which is the order the user lists use. Someone holding only an add-on, such as Uploader, has no type and is never locked.
A type is either Unlocked or Locked. There is nothing in between and nothing that expires: a lock holds until someone clicks Unlock. Lock School Users for the afternoon while you load a file, or lock Teacher Users in September and leave them locked all year. It is the same lock either way.
It is not an outage and it is not something that happens to you. Someone locked it, the history says who, and any District Admin can unlock it.
The User Access Page
- Log in to TKG Analytics with your district credentials.
- Click your name in the top-right of the navigation bar.
- Click User Access.
The page has three parts: the Locks card listing every user type, the Lock and Unlock forms beside it, and the history at the bottom.
The Locks Card
The card opens with Never locked, naming your district's District Admins. No lock reaches them, so a district can never lock itself out.
Below that is one row per user type, each with a pill and a sentence:
- Unlocked.
- Locked. Use Unlock to bring it back.
- Locked for every district. Nobody can lift it from this page, so open a helpdesk ticket.
Beside each row is a Lock button while the type is unlocked, and Unlock while it is locked. A type held for every district has neither, because nothing on this page can lift it.
Locking One Type
Click Lock beside the type. The page confirms with Teacher Users are locked. and the type stays locked until someone clicks Unlock.
Clicking Lock on a type that is already locked changes nothing, and the page says Nothing changed.
You cannot lock your own user type. District Admins have no type, so this only comes up for someone holding the Maintenance add-on: their own row carries This is your own user type. Another District Admin can lock it. in place of the button, and the page refuses the change if it arrives anyway. Locking yourself out would leave you on the access turned off page with no way back to undo it.
Locking Several Types at Once
Use the Lock form to the right. Every unlocked type starts ticked; untick the ones you
want left alone. Add a reason if you want one, such as Uploading and checking data. The
people it locks out see it, and so does the history. Click Lock.
It locks each ticked type that was unlocked, and remembers exactly those as the types locked together. A type that was already locked is left as it is. If nothing ticked was unlocked, nothing is recorded and the page says Nothing changed.
Locking from this form is also what the Maintenance add-on passes, which is covered under Who Can Change Access.
Unlocking
Use the Unlock form to the right. It lists every locked type with the date it was locked, and ticks the ones locked most recently for you. Untick anything you want left locked, tick anything else you want back, and click Unlock. The page confirms with District Users and School Users are unlocked.
Unlock moves exactly what you tick and nothing else:
- A type you leave unticked stays locked. If Teacher Users were locked in September and you locked the other two this morning, the form ticks District Users and School Users and leaves Teacher Users alone.
- Ticking follows the most recent lock, however it was set. A type you lock from its own row is ticked next time, the same as one locked from the Lock form.
- A type you lock or unlock on its own, from its row, stops counting as part of the group it was locked with. That is what the Maintenance add-on follows, under Who Can Change Access.
A locked type is held out on every page, at once. Plan your communications before you lock.
When To Lock
- Bulk SIS uploads. Hold users out during large roster or identity updates (onboarding, start-of-year rollovers, mid-year schedule shifts) while rosters and scopes settle.
- Assessment uploads. Control the release of new benchmark or state results: stage the import, validate it, coordinate your communications, then unlock so every result appears at once.
- A user type you do not use. A district with no teacher logins locks Teacher Users once and leaves it locked.
What Each Audience Sees
A locked member is sent to a page headed Your access is turned off on every request. It names your district and their user type:
Riverbend School District has turned off access to TKG Analytics for its Teacher Users.
When the lock that holds them carried a reason, the page shows it: Reason: Processing Spring 2027 Midterm 1 scores. Otherwise it shows no reason. Either way, the page tells them to contact one of your district's District Admins if they need access. It does not promise that access is coming back.
Everyone else in the district carries a banner on every page while any type is locked:
Teacher Users are locked. Locked by [name] on [date] for [reason]. Change access.
Each part of the second sentence appears only when it was recorded, and the sentence is left out entirely when nothing recorded the lock, which is what a lock set outside the app looks like: there is nobody to name and a date would be a guess. For someone who cannot open the User Access page, the banner ends with A District Admin can unlock them. instead of the link.
The user lists (District Users, School Users, Teacher Users) each carry the status for their own type, with a Manage user access link to this page for anyone who may open it. While the type is unlocked it is a quiet line. While it is locked the list carries a callout instead, because a list of people who cannot sign in looks exactly like a list of people who can:
Teacher Users are locked. Teacher Users cannot sign in. A District Admin can unlock them from the User Access page.
Where the lock carried a reason, the callout ends with it instead: Reason: Processing Spring 2027 Midterm 1 scores. On the District Users list the callout also says that District Admins on it are not affected, because that list carries them and no lock reaches them.
Who Can Change Access
Admins, Platform Admins, District Admins and anyone holding the Maintenance add-on can open the User Access page and lock and unlock. A Platform Admin can do it for a district they support, once they have switched to it. Everyone else is refused.
The Maintenance add-on also lets its holder through a lock set from the Lock form: a Teacher User with the add-on keeps working while Teacher Users are locked that way, so a district can keep one teacher checking data. It does not let them through a lock set from a row's own Lock button, or through a type turned off for every district. Neither does it survive a change by hand: once someone locks or unlocks that type from its row, it stops counting as part of the group it was locked with, and the add-on stops passing it. Nothing else takes it out of that group. Locking the rest of your types afterwards, or unlocking part of the group and leaving this type ticked off, both leave it exactly where it was.
Reading the History
Every lock and unlock is recorded, and the list at the bottom of the User Access page shows them newest first. Each entry names who made the change and when, and which types moved between unlocked and locked. A lock that carried a reason shows it on its own line, and an entry with no person behind it is named by its reason instead.
Entries from before this page existed, when the district had a single maintenance mode switch, are still there. They read as Updated by [name], with Maintenance Mode going from off to on or back.
A district with nothing recorded is told so plainly.
Submitting Scores Locks Your District
When anyone at your district submits an assessment for processing, your District Users, School Users and Teacher Users are locked for the run, which is every type this page can lock. It stays locked when the run finishes: processing never unlocks. That is on purpose. It gives your team the first look at the numbers before principals and teachers see them, and it leaves the order you reopen in up to you. Use Unlock on this page, one type at a time or all three, whenever you are ready.
Those locks carry a reason naming the assessment, so the history tells you which submission locked you. See Submitting Scores for Processing for what a submission runs and who hears when it finishes.
When Your District Did Not Lock It
The platform team can lock your district while processing a new set of scores for you. Those entries name the work instead of a person, so the banner reads Locked on [date] for score processing. Where the run is for one assessment, the entry names it too, as score processing for Spring 2027 Benchmark 1, so you can tell which upload locked you.
You do not have to wait for anyone. Use Unlock on the User Access page like any other time. If you do not know why your district is locked, open a helpdesk ticket and ask.
A type can also be locked with no entry in the history at all, when the platform team set it outside the page. Its row reads Locked, the banner names nobody, and Unlock lifts it.
When a type was turned off for every district at once rather than for yours, its row reads Locked for every district and offers no button. Unlock cannot lift it: the page tells you access for that type is still off rather than confirming it came back. Open a helpdesk ticket to have it lifted. Once it is lifted, check the row: a lock your own district had set on that type beforehand does not come back with it, so lock it again if you still want it held.
Need Help?
- Helpdesk Ticket: Helpdesk Ticket
- Website: https://tkganalytics.org