← All policies

User Account Policy — Hummingbird (DepEd Abra · DRRM deployment)

DRAFT for review. Matches system behavior as of 2026-07-12.

Account types

Two kinds of account are issued in this deployment, plus the operator's own.

RoleScopeHow created
School DRRM CoordinatorOwn school only (enforced server-side)Division provisioning, or self-registration + Division approval; one account per school (enforced by a database constraint, not only by policy)
Division DRRM Office (Division Admin)Full operational authority division-wideDivision provisioning (Administration page or script)
Platform operatorSupport, diagnostics and the private ops desk. Not a Division account — held by the supplier and keyed to a single named addressHeld outside the Division's account set

A school account may additionally be marked by the Division as *read-only* (may view its records but change nothing) or as the *school head* (certifies preparedness packages). These are markings on the school's single account, not extra accounts.

No Superintendent or Viewer accounts are issued. Where a workflow requires that an approver be a different person from the reviewer, the separation is between two Division Admin accounts; the system enforces "not the same person", not a rank.

Credentials lifecycle

  • Provisioning issues a one-time temporary password shown once to the administrator; the account must set its own password on first sign-in (enforced — the app pins the session to the change-password page).
  • Passwords: minimum 10 characters (server-enforced); the set-password forms show a live strength meter and requirements checklist.
  • Forgotten password: self-service via "Forgot your password?" (verified email link), or a Division administrator issues a new one-time temporary password (identity verified by the office; forced change applies again).
  • Sessions: signing in persists on that device until sign-out or administrative action; tokens refresh automatically. "Sign out of all devices" (Change-password page) revokes every session, e.g. after a lost phone. An admin password reset also invalidates existing sessions.

Self-registration (schools without an account)

Register → pick your school from the directory → request enters the Division's approval queue → account is inert until approved. If email sending is configured, the address must be verified before approval. A school that already has an account cannot register a second one.

Deactivation and deletion

The Division can delete any account from the Administration page (confirmation required). Guardrail enforced by the system: you cannot delete your own account. Deletion removes sign-in and profile immediately; reports, documents, and audit entries already filed remain, attributed by the author's name — see the Data Retention Policy.

Departures and transfers (Division SOP)

When a coordinator leaves a school: delete (or reset) the account promptly, then provision the successor. History stays intact; the successor's actions are recorded under their own name.