Keep your account safe
Everyday habits and settings that protect your school's JPRAXC accounts, e-mail and records.
Most account problems start outside the software: a shared password, a phone left unlocked, a convincing fake e-mail. This guide lists the habits and settings that make the biggest difference. The administrator should read all of it; everyone else should read the first section.
For everyone#
- Use your own account. Every person signs in with their own Login ID. Never share a password with a colleague, even for a moment. Actions in the ERP are recorded against the account that made them.
- Use a strong, separate password. Do not reuse the password of your personal e-mail, bank or social media accounts.
- Turn on the second sign-in step if your school has not required it already. See Sign in and the second sign-in step.
- Keep your recovery codes away from your phone. See Recovery codes.
- Lock your phone with a PIN or fingerprint. On the JPRAXC mobile apps, keep the app PIN private.
- Sign out on shared computers. Use Sign out in the sidebar before you leave a computer that others use, and do not let the browser save your password on it.
- Check before you click. JPRAXC links open pages on jpraxc.com. If a message asks you to type a password, one-time code or recovery code into a form, a chat or a reply, do not do it.
For administrators#
Protect the administrator e-mail#
The administrator e-mail registered with your licence receives the password-recovery code, the activation details, invoices and licence notices. Whoever controls that mailbox can take control of the administrator account.
- Use a mailbox that belongs to the school, not a personal address that leaves with a person.
- Give it a strong, unique password and turn on its own two-step sign-in.
- Limit who can open it.
Require the second step where money moves#
In Users & Control › Access control, the Second sign-in step policy can require the authenticator app for Roles that can change fees, payroll or accounts, or for Everyone who signs in to the workspace. At the very least, keep it on for anyone who handles fees, payroll or accounts.
Give each person only what they need#
- Create roles that match real jobs, and give each role only the modules it needs.
- Review roles at the start of each session, and after anyone changes job.
When someone leaves or changes role#
- Change their role, set a new password, or disable their account on the same day. Their records and past actions stay in the ERP.
- If they used the second step, select Reset second step on their row once their phone is no longer theirs to use for the school.
Control where staff sign in from#
Users & Control › Access control also lets you approve the computers and networks staff sign in from, put staff sign-in on hold, or limit it to set hours. Use these for evening, holiday or exam periods.
Keep the product up to date#
Install updates when School ERP tells you one is available (School Settings › Software update). JPRAXC supports the current release and the one before it, so do not fall far behind.
Keep the activation details private#
Store the activation e-mail and its PDF where only the owner or principal can reach them. Do not forward them to staff, vendors or partners.
If you think an account has been misused#
- Change the affected password straight away, and reset the second step if a phone may be in the wrong hands.
- Tell your school administrator.
- Report it to JPRAXC: e-mail support@jpraxc.com with "Security" in the subject, or use the Security incident / compromised account category of the direct report form on the grievances page (opens in a new tab).
