Realsmart Help

← Realsmart Help

What's new in the admin

What's new in the admin

A tour of the recent body of work, with links to the full guides. Everything below is live in the rebuilt (v2) admin.

Reduced admin access — now actually enforced

  • Pre-admission pupils are now chosen, not imported automatically — and they're grouped by the school year they were born into, so you can set a year group for a whole group at once. The year group is filled in for you by matching against your own current pupils, so it comes out in exactly the form your school already uses. Accepted applicants are no longer added overnight on their own. See Import pre-admission students.

  • Real, granular admin permissions. "Reduced admin access" used to only hide menu items — a reduced admin could still reach settings, imports and other restricted pages by typing the URL. It now enforces on the server: every restricted page and action refuses a reduced admin.

  • The Access tab. Edit an admin and open Access to choose a Full or Reduced preset, then fine-tune 15 individual capabilities (manage/delete users, reset passwords, view/run syncs, change sync/platform/API settings, import/export, view logs, MIS data, classroom reporting, Smart Parents, school settings, manage other admins, and — for the Realsmart platform school only — manage the SmartLogin SAML SP registry) with a live plain-English summary. See Reduced admin access.

  • Safeguards — you can't reduce your own access or the last full admin of a school, you can only grant what you hold yourself, and every change is recorded in the audit trail.

  • The trust viewAdmin permissions now shows each admin's access-level chip (Full / Reduced / Custom) alongside their school access.

The new admin area is your default

We've rebuilt the admin, one area at a time — and it's now the default. When you sign in you land here in the new (v2) admin automatically; there's nothing to switch on. The classic admin is still there if you ever need it, one click away with Switch back to version 1 (bottom-right of every v2 page), and your choice sticks. Stepped back onto a classic page? A quiet Back to v2 icon returns you. If something isn't here yet, Report a bug (bottom-right of every page) sends the team a note with the page and your account captured automatically. See Report a bug and switch between v1 and v2.

End of year, managed properly

  • End of year area — the provisioning window made visible: a timeline of the active → frozen → new-year phases, a plain-English "what happens at the end of term for your school" summary, and a guided resume for the new year. Classroom end-of-term behaviour is now a 3-way policy (archive / leave / archive next term), settable per school or across the trust.
  • Tidy-up and orphans — review protected users/groups (now with a read-only review-before-delete step and a select-all for bulk clean-ups that warns before anything consequential), and find Google accounts that aren't in Realsmart (with last-login evidence) to keep or suspend — human-confirmed, never automatic.
  • Active Directory is held too — on-prem AD now pauses with everything else during the summer freeze (it used to keep syncing because it runs on its own connector feed), so nothing reaches AD until you resume.
  • Roll your AD intake years forward (in time) — schools whose AD places pupils by intake year now get a pre-emptive reminder during the freeze — in-app and by email — to roll their intake years forward before September, personalised with your real resume date and current intake years. It only goes to intake-year AD schools (never year-group schools), escalates as resume nears, and clears itself once you've done it.

See what's coming from your MIS

  • MIS sync preview — MIS sync can now be on in preview, just like Google: the real Wonde fetch runs but nothing is imported, and a new page shows exactly what would come in — learners, staff, groups and pre-admissions, counted and drillable — with the sync's own reasoning for who's included or held. See MIS sync preview.

MAT (trust) tooling

  • User log trace — search one username and see that person's sync activity across every school in the trust, interleaved and school-labelled, with per-school health and one-click fixes (re-sync / open user). See Trace a user's activity across the trust.
  • Shared Google domain protection — for trusts sharing one Google domain, sync no longer lets schools remove each other's memberships: removal is a trust-wide decision, visible in the logs. See Shared Google domain trusts.
  • Merge users everywhere — the duplicate-account merge (with its audit log and undo) is no longer MAT-only: standalone schools have it too, under Users & Groups. See Merge duplicate user accounts.
  • Admin permissions overview — instead of opening each admin one at a time, see every admin's school access across the whole trust in one place: who has full access, who's reduced and to what, and "who can access this school?". Reduce an admin to a subset with select-all / search / live counts — enforced everywhere (switcher and every cross-trust view), not just hidden. See Admin permissions.

Logs you can act on

  • Errors-first triage — the Logs area groups failures by root cause, shows the affected people with links, the actual platform error (formatted, expandable, copyable), and whether a later retry resolved it.
  • Recurring errors logged once — a failure that repeats identically every run (a class that can't be created, an account the provider keeps rejecting) is now recorded once per affected user and problem with a running count and a last seen time ("failed 47 times, last seen today") instead of hundreds of duplicate rows — the signal, not the noise. See Understanding and actioning sync errors.
  • The "affected" column is populated — every membership change shows who and which group or classroom; log entries are attributed across Google, Entra and AD alike.
  • Platform-scoped logs — the Entra and AD sections link straight to their own filtered logs.

The Realsmart API (Advanced features)

A cached, scoped, Wonde-style API over your school's data: per-school tokens with per-resource scopes, versioned URLs, pagination/filtering/includes, rate limits and full request auditing — with personalised documentation in this Help area (your school's real URLs and examples). See the API section.

Quality-of-life

  • Profile pictures & school logo — users can set their own photo; admins can set anyone's; the school logo upload now resizes and stores safely.
  • Beacon is an app now, not a special button — the support helpdesk used to be its own icon in the top bar. The top bar now carries your apps launcher — the same panel you see across your school's sites — and Beacon appears there, and in the Apps area, as an ordinary app wherever it's switched on (opening straight into Beacon, already signed in). One place for every app, Beacon included.
  • Consistent, safer confirmations — every "are you sure?" is now a themed in-app dialog (dark/light aware) instead of the old browser pop-up. Destructive actions carry a plain explanation, an accurate count, and consequence warnings (e.g. "deleting a user who owns a Google Classroom orphans the course"); the biggest ones — like bulk-deleting users — ask you to type DELETE to confirm.
  • Sidebar organisation — grouped sections (Users & Groups / Data / Platforms / Engagement / Admin), and exactly one item highlights at a time.
  • Service-aware admin — schools only see the platforms they actually use: Google options hide when Google sync is off, Entra options hide when Entra is off, and shared wording adapts to what's enabled.
  • Wonde data area — browse exactly what your MIS sends, now with name search and optional includes; user pages cross-link to "what Wonde says".
  • MFA enforcement, staff or students — two independent school-wide settings requiring two-factor: one for staff, one for students (Reception through Year 13 — no age exception, so consider it carefully for your youngest pupils). Never locks anyone out; it's a "set it up at your next sign-in" requirement, not "must already have it".
  • AD display names — a %TITLE wildcard for staff display-name formats.

Under the bonnet

The sync engine itself is documented in plain language — what runs when, how change detection works, the provisioning window, and how every action is logged: How the sync engine works.

Was this helpful?