Skip to content

MissionLab school workspace

My school

Your classes, the students in them, and the missions you have assigned. Preparing and running a mission never needs any of this. A class is what lets you assign a mission to named students and read the work that comes back.

Sign in to see your school and classes.

Everything else in MissionLab runs without an account. Signing in only adds your class.

Local example

Classes

No classes yet.

Local example

Join codes

No join codes have been issued.

Local example

Assigned missions

No missions have been assigned yet.

What comes back

Review student work

Students export what they wrote and you open it in the review workspace. This school workspace records which missions are assigned and who opened them. It does not store a student’s answers, marks or portfolio.

Open the review workspace
Technical details

Phase and contract

CubeSTEM MissionLab Twin · M4-B1 institution, class and publishing surface. Contract missionlab-m4b1-institution-class-publishing-0.1.0. Institution account contract cubestem-p1-a5-institution-account-0.1.0.

Tenant isolation

Institution tenant not provisioned. Rosters are pseudonymous. RLS—not client-side hiding—enforces tenant access, and assignment packages are canonical M4-A publications. Institution tenants are provisioned by a platform administrator in A5: claim a one-time administrator invitation on the institution account page, or use a teacher enrollment code supplied by an institution admin.

Enrollment codes

Bounded enrollment codes. The plaintext is returned once and is not stored. The database retains only its SHA-256 digest and a short display hint.

Commercial entitlement

Effective state unentitled. Outside active, historical reads, releases, exports and privacy workflows remain available; new teaching activity is blocked.

Institution audit

No audit events are visible.

Authority boundary

M4-B1 does not persist learner evidence, submissions, assessments, grades, portfolios, official attempts, credits, or hardware commands. Participant clients receive no service-role, node-token, serial, bridge, operator, or ESTOP-clear authority.