Roles and permissions in Privacy Governance Console
Understand what admins and teachers can do in PGC, and what role is required for each action.
In this article
Privacy Governance Console (PGC) has two user-facing roles: District Admin and Teacher. These map to roles in SchoolDay. Admins have full control over the console, including governance actions. Teachers have read access and can submit application approval requests. Role assignment happens in SchoolDay, not inside PGC itself.
Role comparison
|
Capability |
District Admin (Primary) |
District Admin |
Teacher
|
|---|---|---|---|
|
Activate PGC in SchoolDay Connect |
Yes |
No |
No |
|
Deploy PGC browser extension via Google Admin |
Yes |
No |
No |
|
View compliance dashboard |
Yes |
Yes |
No |
|
View applications list |
Yes |
Yes |
Yes |
|
Search and filter applications |
Yes |
Yes |
Yes |
|
View application details |
Yes |
Yes |
Yes |
|
Mark application as PII approved/unapproved |
Yes |
Yes |
No |
|
Apply and manage tags |
Yes |
Yes |
No |
|
Configure tag-based approval rules |
Yes |
Yes |
No |
|
Review and act on teacher approval requests |
Yes |
Yes |
No |
|
Submit an application approval request |
No |
No |
Yes |
|
Track an app's vetting status |
No |
No |
Yes |
|
Export District Application Report (CSV) |
Yes |
Yes |
No |
|
Add an application from the database |
Yes |
Yes |
No |
|
Request a vendor to integrate with SchoolDay |
Yes |
Yes |
No |
Note: The Primary District Admin role is required specifically for activating PGC in SchoolDay Connect and deploying the browser extension via Google Admin. Standard District Admin permissions are sufficient for day-to-day console use.
Two types of approval
PGC has two separate approval mechanisms. They have different purposes, different audiences, and are set independently.
|
Approval status (tag-based) |
PII Approved flag |
|
|---|---|---|
|
Question it answers |
Can this app be used in classrooms? |
Has IT reviewed how this app handles PII data? |
|
Set by |
Admin applies a tag (Approved for Use, Rejected for Use, etc.) |
Admin clicks Actions > Approve PII Usage |
|
Visible to teachers |
Yes (teachers see Approved, In Review, Rejected, or Awaiting Review) |
No (shown in the admin application list only, for internal reference) |
|
Part of the teacher request workflow |
Yes |
No |
|
Required to complete a review |
Yes |
Optional (use it to track your own data review work) |
An app can be Approved for Use (teachers can use it) without the PII Approved flag being set, and vice versa. They do not depend on each other. Use the PII Approved flag when your process requires a documented technical data review separate from the classroom-use decision.
How roles are assigned
Roles in PGC are determined by a user's role in SchoolDay. PGC does not have a separate user management interface.
To assign or change a user's role in SchoolDay:
- For non-admin roles (e.g., teacher or student), update the role in your source data (CSV file, SIS, or OneRoster) and re-run the sync. SchoolDay will reflect the change automatically.
- For District Admin role, contact SchoolDay support directly.
Related articles
- Privacy Governance Console overview
- How teachers request application approval
- Manage application approvals