KeyLockr QR Login
Tooo Lab Admin Console
-
logout
Selected school is pending approval
Device enrollment, MDM token creation, machine monitoring, and classroom control are all disabled until SafeX approves this school. Please contact SafeX with your SafeID and school ID to request approval.
Machine list
Devices appear here automatically after receiving managed configuration. Use the device number to identify and name them.
School settings
Current school
Use the dropdown at the top to switch schools. This panel shows the current school; click Edit to modify or New School to create one.
School profile
The ID is generated by the system and is not manually editable.
New schools start as pending approval; each admin can keep up to 3 pending schools.
School administrators
Add multiple administrator SafeIDs to this school. Existing school administrators can add or remove other administrators.
macOS deployment and PKI
Each school has one reusable base MDM profile. It contains a school bootstrap credential and can be assigned to the whole Mac fleet in Mosyle or Jamf. Every Mac connects automatically after receiving it and shows its own device number. The base profile does not install Tooo Network Filter or create a VPN.
Multiple Macs:
Push the same profile to every target Mac; there is no per-device token, profile, or acceptance step. Devices come online first; administrators only identify and name them afterward.
Optional network filtering:
Deploy the separate Filter profile only when Tooo content filtering is explicitly enabled and no other product manages system network traffic, and scope it to the same Macs whose Filter policy is enabled. Do not deploy it when using only other Lab features.
ChromeOS Chromebook deployment
Configure Google Workspace and Verified Access here, then download the managed policy and deployment details required by Google Admin Console.
Google Admin Console deployment details
Ext ID
—
OAuth Client ID
—
BE URL
—
Verified Access SA
—
Enroll Token
—
Teacher authorization
New teacher authorization
| Teacher SafeID | view | command | assist | grant time | Actions |
|---|
No authorizations yet.
Students
Use the students.csv headers; keep the location_id column, but its values are ignored. person_id is the student ref. When sis_username is empty, the email local part becomes the macOS username. Existing students not listed are deactivated together with their cards and active sessions.
New student
Leave empty if the student does not use a Chromebook; can be cleared later to unbind
Enter the local account short name the student uses on the Mac; leave empty if not using macOS account login.
min/day
0 = no time (default, student relies on time credits); 1-1440 sets the daily base quota. Every student is time-limited; time credits are a cumulative balance used until exhausted.
Today's remaining time
| Class | Ref | Name | Today's progress · remaining (effective quota) | Parent SafeID | Workspace Email | Cards | Actions |
|---|
No students yet.
Policies
New policy
Monitoring & capture
Session · quota · lock
Enrolled Lab machines always disable P2P regardless of this toggle.
Content filter
Allowed remote commands
Advanced: edit raw config_json (fields not shown in the form above)
| Policy name | Version | Status | Actions |
|---|
No policies yet.
Time credits
Remaining credit balance:
Credits are a one-time cumulative balance. Unused minutes carry across days until used or expired.
| Minutes | Reason | Granted by | Granted at | Valid until | Status | Actions |
|---|
Usage history
Recent screenshots
| Login | Logout | Duration | Machine | Sign-in type | Status |
|---|
No login records for this student yet.
Student cards
| Card UID prefix | Bound at | Last used | Status | Actions |
|---|
No cards bound yet. Use the macOS Admin App to enroll cards.
To add a student card: use the macOS Admin App on a Mac with a USB HID card reader attached. The web admin is for viewing and unbinding only.
Usage reports
Analyze actual sign-in-to-sign-out time by student, grade, machine, or the Tag captured when the session started.
Group by
Sign-in type
| Group | Usage | Sessions started | Student count | Machines | Active days | Last login | Actions |
|---|
No usage records match the selected filters.
Too many groups. Narrow the date range or add filters.
Raw sessions
| Login | Logout | In-range usage | Student | Grade / Class | Machine | Tag | Sign-in type |
|---|
No raw sessions are available within the retention period.
Showing the latest 200 raw sessions.
Audit log
Machine tools
Common actions
Admin Bypass
No admin bypass is active for this machine.
School admins only. This temporarily bypasses the Lab kiosk lock so an on-site admin can recover the Mac — it is NOT a screen unlock, it grants admin-level access. The Lab lock resumes when the timer expires or is revoked.
Identify and name device
The Mac or Chromebook is already online after receiving managed configuration. Enter the large device number shown on it to identify the machine; the nickname is optional. This confirmation does not gate connection, policy, or monitoring.