NCEdCloud Approve Role

NCEdCloud Approve Role — How LEA Administrators Review and Approve Role Requests

What is the NCEdCloud Approve Role Process?

The NCEdCloud approve role process is the step where an LEA Administrator reviews a pending admin role request submitted by a staff member and either grants or denies the requested access. NCDPI’s RapidIdentity platform routes role requests to the appropriate approver queue automatically.

This applies to all administrative roles across all 115 NC school districts using NCEdCloud. The most important thing to know is that only users with the LEA Administrator role can approve role requests — help desk staff and data auditors cannot approve requests even if they receive notification about them.

How to Find and Review Pending Role Requests

  1. Log in to ncedcloud.mcnc.org with your LEA Administrator credentials.
  2. On your dashboard, open the “Requests” or “Approvals” module.
  3. The pending requests queue shows all outstanding role requests submitted by staff in your LEA.
  4. Click on a pending request to view the details: requester’s name, role requested, school scope (if applicable), and any justification note.
  5. Review the request against your district’s role assignment policy.
  6. Select “Approve” or “Deny.”
  7. Add an optional note explaining the decision if you are denying.
  8. Save the decision. The requester’s account is updated immediately on approval.

What to Check Before Approving a Role Request

CheckWhy It Matters
Is the requester still employed at the district?Verify against current HR records
Does the role match the requester’s job function?Principle of least privilege
Is the school scope correct (for school-scoped roles)?Prevents access beyond what is needed
Has the requester completed any required training?Some districts require IT onboarding before granting help desk roles
Does the district already have enough people with this role?Avoid over-provisioning high-privilege roles

Approving vs. Directly Assigning Roles

LEA Administrators can also assign roles directly from the admin console without going through the request workflow. This is useful for new hires where the Requests module tile may not yet appear on their dashboard, or for urgent access needs. Direct assignment and request-based approval produce the same result — the role is active on the account immediately.

To assign a role directly:

  1. Navigate to the user account in the admin console.
  2. Open the Roles or Permissions section.
  3. Add the appropriate role.
  4. The role is active immediately.

Notifying Requestors of Approval Decisions

NCEdCloud sends a system notification to the requester when a decision is made. Some districts configure email notifications as well. Regardless of system notifications, it is good practice for the LEA Administrator or their designee to follow up directly with the requester — especially for denials — to explain the decision and suggest next steps if the request needs to be resubmitted.

Frequently Asked Questions

Can more than one LEA Administrator approve role requests?

Yes. Any user with the LEA Administrator role can approve role requests. Districts with multiple LEA Administrators share the approval queue, and any one of them can process a pending request.

What happens if I accidentally approve the wrong role for a user?

Revoke the role immediately using the Revoke Role process. Navigate to the user’s account in the admin console, remove the incorrectly assigned role, and if needed, approve the correct role request. Acting quickly limits the window of unintended access.

How do I deny a role request without locking the user out of NCEdCloud?

Denying a role request only prevents the requested elevated access — it does not affect the user’s standard account access. The user continues to log in normally. A denied request removes only the specific role from consideration; their existing account and current roles are unchanged.

Can I set an expiry date on an approved role?

This depends on your district’s NCEdCloud configuration. Some RapidIdentity deployments support time-limited role assignments. If your district needs temporary role access — for a substitute, a contractor, or a seasonal staff member — ask your Identity Automation contact or NCDPI support whether role expiry can be configured.

Where can I see a log of all role approvals I have made?

Audit logs in the NCEdCloud admin console record role changes, including approvals and denials. Access the audit log from the admin console navigation. If you cannot find it, contact your NCDPI support contact for assistance in locating the audit trail in your district’s configuration.

Related Reading

NCEdCloud Request Role Guide (/ncedcloud-request-role/)

NCEdCloud Revoke Role Guide (/ncedcloud-revoke-role/)

NCEdCloud LEA Administrator Role Overview (/ncedcloud-lea-administrator/)

NCEdCloud Help Desk Role Guide (/ncedcloud-help-desk/)

NCEdCloud Data Auditor Role Guide (/ncedcloud-data-auditor/)

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *