Staff, Instructor & Administrationሠራተኞች፣ አስተማሪዎች እና አስተዳደር
Course-scoped teaching access, roster/gradebook/submission workflows, protected administrator writes, user deletion, certificate administration and vocabulary-audio authority.
በኮርስ ደረጃ የተገደበ የማስተማር መዳረሻ፣ የተማሪ ዝርዝር (Roster)፣ የውጤት መዝገብ (Gradebook)፣ የቀረቡ ስራዎች፣ የተጠበቁ የአስተዳደር ለውጦች፣ የuser account ስረዛ፣ certificates እና የVocabulary ድምፅ ስልጣንን የሚያብራራ ሙሉ መመሪያ።
Roles and access boundariesRoles እና የመዳረሻ ወሰኖች
| Role/context | Audited access |
|---|---|
| Instructor / assistant | Only courses explicitly assigned through course_staff; can view roster, student records, submission queue and gradebook for those courses. |
| Administrator | Global course/staff/identity/certificate/audio administration plus instructor workspace access. |
| Scholarly editor | Privileged identity/MFA treatment exists, but the audited Admin navigation itself is administrator-only. |
Instructor workspace: course → roster → submissions → gradebookየአስተማሪ የሥራ ቦታ ሂደት (Instructor workspace)
The Instructor landing page lists assigned course versions, their status and enrollment counts, with three primary actions:
Student display name, email, enrollment status/date, completion and a link to the student record.
Queue of instructor-assessed assignment submissions whose status is Submitted or Returned.
Course assessment/assignment result matrix across enrolled students.
Instructor student recordየInstructor የተማሪ መዝገብ
The student record consolidates the selected enrollment, academic results, locked completion if one exists, and instructor-assessed assignment submissions. It is a course-scoped staff view, not a public student profile.
If the current staff user is also an administrator and no immutable completion exists, the page exposes an administrator-only enrollment-status control with an audit note.
Instructor-assessed submissions and gradingየInstructor የምዘና ሂደት
- Open the course Submission queue.
- Open a submission to read the student response and any stored file metadata.
- If status is Submitted, enter points awarded (0 through points possible) plus optional feedback and click Record grade.
- Or provide required revision feedback and click Return for revision.
- The service records submission events so the submission history is auditable.
Returned work remains in the staff queue. Grading converts points to a percentage according to the instructor policy layer.
Administration dashboard and security gateየአስተዳደር መነሻ ገጽ እና የደህንነት መግቢያ
Administrator reads require privileged MFA state. Sensitive writes additionally pass the administrator_write_required gate: fresh password + TOTP reauthentication and the deployment write flag GTM_ADMIN_WRITES_ENABLED=1.
The Administration landing page exposes Users, Audit log, Certificates, Vocabulary audio and per-course Staff management.
User directory and protected deletionUsers እና የተጠበቀ የaccount ስረዛ
The Users page searches by name/email and shows Name, Email, Status, Roles, Verified, Created and Action. Permanent deletion is deliberately restricted to eligible non-privileged student/test accounts and is never offered for the currently signed-in administrator.
Why some user accounts show Delete and others do not ለምን አንዳንድ user accounts የDelete አማራጭ አላቸው እና ሌሎች የላቸውም?
The absence of a Delete action is not automatically a UI defect. The administration interface exposes destructive deletion only when the account satisfies the server-side eligibility rules.
- Eligible student/test account: may expose Delete when no protected identity or academic-record boundary prevents removal.
- Current administrator account: Delete is intentionally not offered.
- Privileged staff identity: protected from ordinary destructive account deletion.
- Protected/formal academic record: the account may remain non-deletable because transcript, certificate, completion or other protected academic identity must remain intact.
- Enrollment alone: should be diagnosed separately from account identity. Removing or changing a course enrollment is not the same operation as deleting the user account.
When two records appear to belong to the same person, first compare email address, verification state, role, enrollment and protected-record status. Similar names alone are not sufficient evidence that one record should be deleted.
Assigning course staffየኮርስ ሠራተኛ ምደባ (Course staff assignment)
For a course version, Administration lists assigned staff and allows an administrator to assign a selected user as Instructor or Assistant, or remove an existing course-staff assignment. This is a sensitive administrator write and is disabled unless the write flag and privileged MFA gate are satisfied.
Certificate administrationየCertificate አስተዳደር
The certificate-admin table lists number, recipient, course, status and issue time. A valid certificate can be revoked by entering a reason and submitting the protected Revoke action. Revocation is preserved in the certificate record and becomes visible in public verification.
Vocabulary audio authority workflowየVocabulary ድምፅ ስልጣን የሥራ ሂደት
The restricted Vocabulary Audio page is the authority workflow behind NT Greek 310 fixed recordings:
- Review coverage from Word 1 → 310 and listen to approved fixed audio.
- Use Device preview only as explicitly non-authoritative speech synthesis.
- Submit controlled batches or individual candidates with speaker/source metadata and accepted audio files.
- Listen to pending candidates and mark four QA gates: technical quality; complete beginning/end; all scripted forms present; Modern Greek pronunciation passes listening review.
- Approve only after all gates pass, or reject with notes.
Individual candidates accept MP3, WAV, OGG or M4A up to the audited 5 MB limit. The controlled pilot batch shown in the UI covers ranks 1–5.
Audit log and accountabilityAudit Log እና የተጠያቂነት መዝገብ
Administrator actions and many identity/academic actions emit audit events. The Administration Audit Log is the privileged read surface for reviewing those events. Instructor assignment changes, grading/return actions, certificate events, account/security events and other sensitive operations are designed to leave server-side evidence rather than relying on browser history.
Current administrative boundaries / known gapsየአሁኑ admin ወሰኖች / የሚታወቁ ክፍተቶች
- The public/student manual should not expose internal admin secrets, session tokens, password hashes or private academic data.
- The audited Security UI shows recent sessions but does not expose per-session revoke controls.
- Assignment-file schema exists, but learner file upload/download remains intentionally gated off in the audited UI.
- Admin writes can be globally disabled even when an administrator is otherwise authenticated.
- Terms/Privacy templates still require final legal/privacy review before the platform manual can treat them as finalized policy.