User Account Policy — Hummingbird (DepEd Abra · DRRM deployment)
DRAFT for review. Matches system behavior as of 2026-07-12.
Account types
Two kinds of account are issued in this deployment, plus the operator's own.
| Role | Scope | How created |
|---|---|---|
| School DRRM Coordinator | Own school only (enforced server-side) | Division provisioning, or self-registration + Division approval; one account per school (enforced by a database constraint, not only by policy) |
| Division DRRM Office (Division Admin) | Full operational authority division-wide | Division provisioning (Administration page or script) |
| Platform operator | Support, diagnostics and the private ops desk. Not a Division account — held by the supplier and keyed to a single named address | Held outside the Division's account set |
A school account may additionally be marked by the Division as *read-only* (may view its records but change nothing) or as the *school head* (certifies preparedness packages). These are markings on the school's single account, not extra accounts.
No Superintendent or Viewer accounts are issued. Where a workflow requires that an approver be a different person from the reviewer, the separation is between two Division Admin accounts; the system enforces "not the same person", not a rank.
Credentials lifecycle
- Provisioning issues a one-time temporary password shown once to the administrator; the account must set its own password on first sign-in (enforced — the app pins the session to the change-password page).
- Passwords: minimum 10 characters (server-enforced); the set-password forms show a live strength meter and requirements checklist.
- Forgotten password: self-service via "Forgot your password?" (verified email link), or a Division administrator issues a new one-time temporary password (identity verified by the office; forced change applies again).
- Sessions: signing in persists on that device until sign-out or administrative action; tokens refresh automatically. "Sign out of all devices" (Change-password page) revokes every session, e.g. after a lost phone. An admin password reset also invalidates existing sessions.
Self-registration (schools without an account)
Register → pick your school from the directory → request enters the Division's approval queue → account is inert until approved. If email sending is configured, the address must be verified before approval. A school that already has an account cannot register a second one.
Deactivation and deletion
The Division can delete any account from the Administration page (confirmation required). Guardrail enforced by the system: you cannot delete your own account. Deletion removes sign-in and profile immediately; reports, documents, and audit entries already filed remain, attributed by the author's name — see the Data Retention Policy.
Departures and transfers (Division SOP)
When a coordinator leaves a school: delete (or reset) the account promptly, then provision the successor. History stays intact; the successor's actions are recorded under their own name.