> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nycadultedlabels.nyc/llms.txt
> Use this file to discover all available pages before exploring further.

# User roles

> Permissions for Admin, Data Lead, Data Member, and Intake Member.

## Security requirement — MFA until SSO

<Warning>
  **Everyone using the system must enable MFA** (authenticator app) until DOE Single Sign-On is available. This applies to all roles. Admins may disable MFA only to unlock an account; the user must turn MFA back on afterward.
</Warning>

Set up MFA from **Profile** after your first sign-in. Contact an Admin if you lose your authenticator device.

## Admin

**Scope:** All schools

Full access including user management, security recovery, school and agency ID configuration, all cabinets and students, enrollment dashboard, **email validation**, **ThoughtSpot analytics**, school year rollover, archive boxes, reports, cleanup, and migration tools.

## Data Lead

**Scope:** Assigned school

Manage school data, cabinets (including **custom drawer capacity**), bulk imports, duplicate review (with address comparison), NYC address verification on All Students, sibling confirmation, unassigned queue, bulk move, enrollment dashboard, school settings (including **intake session time windows**), school year rollover, archive boxes, and cleanup tools.

<Note>
  **Email Validation** (`/admin/validation`) and **ThoughtSpot Analytics** (`/admin/thoughtspot-analytics`) are **Admin-only**. Data Leads do not see these links.
</Note>

## Data Member

**Scope:** Assigned school

Add, edit, search, print, and export student records for their assigned school. Print Avery **5163** or **94205** labels in batches via **Download Word Doc** (Letter, 100%). Uses the same **left sidebar** as Data Leads, with fewer admin links.

## Intake Member

**Scope:** Assigned school

Access only the **Intake Form** (full-screen — no left sidebar). Register new and returning students, capture and verify addresses (NEW), run live duplicate checks (name + address), enforce session hours, flag potential siblings, and review a success summary after save. Labels are printed later from the Dashboard. Cannot access the main dashboard or admin tools.

<Warning>
  Intake Members are limited to `/intake` and their assigned intake sessions. Admins and Data Leads can open Intake for testing.
</Warning>

## Navigation

| Role                            | Chrome                                                  |
| ------------------------------- | ------------------------------------------------------- |
| Admin / Data Lead / Data Member | Left sidebar + top bar (school, dark mode, profile, ⌘K) |
| Intake Member                   | Intake-only header (Translate, Reset, Sign out)         |

Sidebar groups: **Daily**, **Students**, **Storage**, **Print**, **Admin**, **Help**. Links are filtered by role.

## Role comparison

| Capability                      | Intake Member | Data Member | Data Lead | Admin |
| ------------------------------- | ------------- | ----------- | --------- | ----- |
| Register / log visits on Intake | ✓             | —           | ✓         | ✓     |
| Search & edit students          | —             | ✓           | ✓         | ✓     |
| Print label batches             | —             | ✓           | ✓         | ✓     |
| Cabinets & archive              | —             | —           | ✓         | ✓     |
| Duplicates / enrollment issues  | —             | —           | ✓         | ✓     |
| Email validation                | —             | —           | —         | ✓     |
| ThoughtSpot analytics           | —             | —           | —         | ✓     |
| Users & all schools             | —             | —           | —         | ✓     |
