KeyLockr QR Login
Tooo Lab Admin Console
-
logout
Selected school is pending approval
Device enrollment, MDM token creation, machine monitoring, and classroom control are all disabled until SafeX approves this school. Please contact SafeX with your SafeID and school ID to request approval.
Machine list
Default view only shows device online, last-seen, and MDM status. Use buttons to manage school settings or add devices.
School settings
Current school
Use the dropdown at the top to switch schools. This panel shows the current school; click Edit to modify or New School to create one.
School profile
The ID is generated by the system and is not manually editable.
ChromeOS Chromebook (optional)
Chromebook deployment (for Google Admin Console)
Ext ID
—
OAuth Client ID
—
BE URL
—
Verified Access SA
—
Enroll Token
—
New schools start as pending approval; each admin can keep up to 3 pending schools.
Deployment and PKI
Download the school MDM profile and check CA readiness. The profile is used by MDM to push CA trust, browser policy, System Extension pre-approval, and Transparent Proxy network filtering.
Teacher authorization
New teacher authorization
| Teacher SafeID | view | command | assist | grant time | Actions |
|---|
No authorizations yet.
Students
New student
Leave empty if the student does not use a Chromebook; can be cleared later to unbind
Enter the local account short name the student uses on the Mac; leave empty if not using macOS account login.
min/day
0 = no time (default, student relies on time credits); 1-1440 sets the daily base quota. Every student is time-limited; time credits are a cumulative balance used until exhausted.
Today's remaining time
| Class | Ref | Name | Today's progress · remaining (effective quota) | Parent SafeID | Workspace Email | Cards | Actions |
|---|
No students yet.
Policies
New policy
Monitoring & capture
Session · quota · lock
Enrolled Lab machines always disable P2P regardless of this toggle.
Content filter
Allowed remote commands
Advanced: edit raw config_json (fields not shown in the form above)
| Policy name | Version | Status | Actions |
|---|
No policies yet.
Time credits
Remaining credit balance:
Credits are a one-time cumulative balance. Unused minutes carry across days until used or expired.
| Minutes | Reason | Granted by | Granted at | Valid until | Status | Actions |
|---|
Usage history
Recent screenshots
| Login | Logout | Duration | Machine | Status |
|---|
No login records for this student yet.
Student cards
| Card UID prefix | Bound at | Last used | Status | Actions |
|---|
No cards bound yet. Use the macOS Admin App to enroll cards.
To add a student card: use the macOS Admin App on a Mac with a USB HID card reader attached. The web admin is for viewing and unbinding only.
Audit log
Machine tools
Common actions
Admin Bypass
No admin bypass is active for this machine.
School admins only. This temporarily bypasses the Lab kiosk lock so an on-site admin can recover the Mac — it is NOT a screen unlock, it grants admin-level access. The Lab lock resumes when the timer expires or is revoked.
Add device
The 6-digit code is the normal add-device flow. The MDM enrollment token below is only for MDM, bulk, or unattended installs: place the token in managed config so the client binds automatically on first launch; after binding it uses its device key for signed requests.