Realsmart Help

← Realsmart Help

Reduced admin access — control what an admin can do

Reduced admin access — control what an admin can do

Not every admin needs to run syncs, change platform settings or export data. The Access tab on an admin user lets you set exactly what they can do — from full access down to a reduced day-to-day set — and everything in between. These limits are enforced on the server: a reduced admin who types a URL or bookmarks a page is refused (403), not merely shown a shorter menu.

Before you start

  • You must be an admin who holds Manage other admins' access (full admins do by default).
  • The person you're editing must be an admin. The Access tab only appears for admins.
  • You cannot change your own access — ask another full admin.

Open the Access tab {#step-1}

Edit the admin user (Users → the person → edit) and choose the Access tab. You'll see a preset selector, the capability switches grouped by area, and a live plain-English summary of what this person can and cannot do.

Access tab showing the preset selector, four grouped capability switches and a Changed from preset badge

Pick a level {#step-2}

Two starting points:

  • Full admin access — everything in the admin area, including settings, imports, logs and other admins' access.
  • Reduced admin access — day-to-day user and group management only: manage users & groups, delete users & groups, reset passwords, and view sync status. No settings, sync changes, imports, exports, logs, reporting, MIS data, Smart Parents or admin-access editing.

Choosing a level resets every switch to that baseline.

Fine-tune the switches {#step-3}

Under the preset, each capability is one switch, grouped into Users & groups, Sync & platforms, Data & privacy and School & admin control. Turn individual capabilities on or off — for example, start from Reduced and additionally allow View logs & audit trail. A row that differs from the preset is marked Changed from preset, with a Reset button to put it back.

You can only change capabilities you hold yourself — switches for anything you don't have are disabled. This stops anyone granting more than they have.

Read the summary and save {#step-4}

The summary card always shows the plain-English result — "Jane can: manage users & groups · delete users & groups · reset passwords · view sync status. Jane cannot: change school settings · …". When it reads right, choose Save access. The change is recorded in the audit trail with who changed what.

Safeguards

  • No self-edit — you can't change your own access.
  • Last full admin protected — a school can never be left with zero full admins; give another admin full access first.
  • No escalation — you can only grant capabilities you hold.
  • Enforced, not hidden — every restricted page and action refuses a reduced admin server-side.

The older on/off toggle

The legacy edit screen still has a single Reduced admin access on/off switch. Turning it on applies the Reduced preset; off restores full access. It now enforces the same limits (it used to only hide menus). For fine-grained control, use the Access tab above.

Related

Was this helpful?