account_navigation placement — from first authorization through bulk tool rollout.
Accessing the Dashboard
The root-account dashboard is not a publicly accessible page. It is served exclusively through the Canvas LTIaccount_navigation placement and enforces several signed claims before granting access.
The dashboard requires a signed Canvas administrator role, a signed root-account-admin value, numeric account claims, and an active administrator OAuth grant. Opening the service URL directly will not grant administrative access.
Authorize the Dashboard
1
Open Safe Online Exam Admin
Navigate to your Canvas root account and select Safe Online Exam Admin from the account navigation menu.
2
Initiate Canvas Authorization
When prompted, select Authorize Canvas to begin the OAuth flow.
3
Review the Requested Permissions
Carefully review the requested course, term, account, and assessment permissions before proceeding.
4
Complete Authorization
Finish the Canvas OAuth flow and return to the still-open LTI page. The application stores one refreshable OAuth grant per Canvas user.
Connecting Courses
The dashboard tracks only courses that have been deliberately connected to Safe Online Exam — it does not import the root account’s complete enrollment history.1
Open Configured Courses
From the dashboard, open Configured courses and select Connect courses.
2
Search the Course Catalog
Search Canvas’s active course catalog. Use the enrollment term filter to narrow results when working within a specific semester.
3
Select and Connect
Select the intended courses and confirm the connection.
4
Refresh Course Metadata
Open any connected course and select Refresh to synchronize the current Classic Quiz and New Quiz metadata from Canvas.
Operational Term Selection
The Operational term selector is shared across the entire root account and persists across browsers and page reloads. By default, the dashboard displays non-concluded connected courses belonging to the selected term. Select Show past and other courses to inspect historical connections. Changing the operational term or course status never deletes connection records. Safe Online Exam refreshes stored Canvas course status periodically and whenever a course is connected or manually refreshed.Connecting a course gives administrators a recovery and rollout view. It does not automatically enable SEB on every assessment in that course.
Recovery Actions
From any connected course, a root administrator can perform the following recovery operations:- Reveal the effective course start and exit passwords for 30 seconds
- Rotate the course exit password
- Reveal an assessment’s start password, exit password, and current Canvas access code for 30 seconds
- Reset an assessment exit password to the current course or managed default
- Regenerate a Canvas access code
- Reset assessment policy to course defaults
- Enable or disable SEB on an assessment
- Refresh assessment metadata from Canvas
Course Reset Procedure
The course reset action rebuilds an entire course from a clean Safe Online Exam state. To initiate it, choose the course reset action and enter the exact Canvas course ID when prompted. What the reset does:- Performs read-only Classic Quiz and New Quiz discovery to record the current Canvas access-code state of every assessment, assembled in memory without changing cached learner-verification state.
- Removes every current access code from Canvas using the account-administrator grant.
- Only after all Canvas changes succeed: deletes the local course policy, assessment settings, outstanding course grants, and school-tool preset assignments for that course in one PostgreSQL transaction. That transaction also stores a reset receipt on the retained root-account course connection.
- The Canvas OAuth grant for the administrator
- The administrator’s course connection record
Handling Canvas Failures
If Canvas rejects or cannot confirm any assessment change during a reset attempt, Safe Online Exam automatically restores the exact pre-reset Canvas access-code state for every assessment already modified during that attempt, and keeps the local assessment settings available for recovery and retry. If Canvas cannot confirm a restoration, or if the database transaction commit response is ambiguous and the service cannot verify the durable reset receipt, the dashboard requires manual verification of every assessment in that course before another reset can proceed.Managing School Exam Tool Presets
A school tool preset is a reviewed web resource that administrators define once and can assign to any connected course. Instructors can enable or disable assigned presets for individual assessments, but they cannot silently rewrite the preset’s launch URL or resource policy.1
Open Approved Exam Tools
From the dashboard, navigate to Approved exam tools.
2
Create a Preset
Create a preset with a clear, descriptive name, an exact HTTPS launch URL, and only the resource rules the tool genuinely requires.
3
Assign to Courses
Assign the preset to selected connected courses, or roll it out to all connected courses at once.
4
Review Rollout Results
Review the rollout result summary and retry any failed course assignments.
Scale limits for school presets
Scale limits for school presets
Safe Online Exam supports at most 32 school presets per root account and 2,000 courses in a single bulk rollout request. Large institutions should connect courses and roll out presets in reviewed batches to stay within these limits.
Related Pages
Canvas Setup
Install the LTI and OAuth Developer Keys in Canvas before using the administrator dashboard.
Instructor Workflow
Understand what instructors configure after a course is connected and school tools are assigned.
Configuration Reference
Review environment variables and service settings that affect administrator behavior.
Troubleshooting
Diagnose dashboard access failures, OAuth errors, and Canvas API rejections.