← All manuals and guides

Educator Growth & Evaluation: User Manual

Part of the Leadership Hub. For how this tool sits beside the rest of the suite, see For school leaders in the AlloFlow teacher guide. That chapter is the suite overview; this is the operating manual for one tool.

21 sections about 35 minutes end to end reviewed September 8, 2026 printable with your preferred paper size and margins

Where to start

Evaluators and principals: read sections 1 through 7 and section 12 to run and protect a cycle; add section 19 if you will use the principal-managed Drive helper.

Educators being evaluated: section 8 is written for you, and section 10 shows the summary you will receive.

District IT and administrators: section 9 is the deployment, and sections 11 and 12 cover privacy, data location, and backups.

1. Choosing Your Record Path

The workspace offers three deliberately different paths. The difference is where records live, who can see them, and who is responsible for setup.

Private, principal-managed, and district-hosted paths
AspectPrivate on-devicePrincipal Drive helperDistrict portal
Who it is forOne evaluator drafting, simulating, and exporting on one device.One principal who needs a small Drive handoff without a district-wide repository.A district that wants authenticated, shared, two-way records.
Setup neededNone.The principal copies three files into their own private Apps Script project, with district approval.A district administrator deploys and configures the repository, membership, and assignments.
Where working data livesIn this browser profile on this device. A deliberate export creates a separate file wherever you save or send it.Exported HTML packets in the principal's district Drive, plus the principal's local source workspace until it is handed off.The district deployment account's repository and released-summary folders inside its Google Workspace tenant.
Educator accessNo authentication. Real local records expose a read-only Educator preview. Only the explicitly fictional sample makes perspective changes interactive for rehearsal.A reviewed viewer/commenter permission to one exported packet; it may expire or be revoked.Each educator signs in and sees only their assigned record.
ControlsVisible save state, staged import review, automatic pre-import backup, manual exports, read-only preview for real records, an interactive coach limited to fictional data, and a reviewed backup-before-clean transition into real work.Validated one-educator packet, verified-account domain boundary, immutable final review, live permission re-read, optional expiration, and proof-based revoke.Managed identity, roles, assignments, mutation validation, server audit, two-party workflow, reviewed administrator changes, private audited exports, and archive rehearsal.
Official recordNo.No; the Drive folder needs a deliberate records handoff.The district still decides which authorized personnel system is official.

A third, middle path, one principal sharing reviewed packets from their own district Drive, is covered in Sharing Through Your Own Drive and Sending an Evaluation to an Educator by Email.

A good path: learn with fictional data first. Use the principal helper only when a district-approved one-recipient Drive handoff is sufficient; use the portal when identity, assignments, shared live records, and district audit are required.

2. Quick Start

Three ways in, all the same tool. Inside AlloFlow, open Educator Tools → Leadership Hub → Educator Evaluation — that is the route the Leadership Hub documents and the one to teach colleagues. It is also still reachable from AlloFlow's Project Settings with Open Educator Evaluation. Or go straight to alloflow-cdn.pages.dev/educator-evaluation in any modern browser, which is the link to bookmark or hand to a colleague. Once the tool is open, Manual in its header returns you to this page from any tab.

First-time setup dialog for Educator Evaluation. The current dialog offers a guided fictional tour, private local work, and a record-path planning route.
First launch asks what you want to do. The fictional option starts a resumable in-app tour; the setup option opens the neutral three-path chooser.
  1. Choose a starting point. Start a guided sample tour opens a fictional roster and walks through Overview, Trends, Staff, Walkthroughs, Formal, Audit, and Setup; Start real work locally preloads nothing and shares nothing; Choose a record path opens the neutral three-path setup center. Only the path you select expands.
  2. Set up the workspace. On the Setup tab, enter your organization, building, academic year, and evaluator name, then choose your evaluation framework (section 6).
  3. Add educators. On Staff, choose + Add educator, enter a name and unique staff code, then save. The form is a draft: Cancel creates no record or audit event. For a whole roster at once, choose Paste roster instead: one educator per line as name, staff code, assignment, and due date, with commas or tabs between the fields, so a copy from a spreadsheet works directly. A preview marks every line as ready or skipped with its reason, and nothing is added until you confirm.
  4. Start observing. Log walkthroughs as you do them, and assign formal observations when the cycle calls for them. Trends build themselves.

In the private path, edits are saved to this browser profile after a short delay. Watch the persistent Saving, Saved on this device, or Changes are not saved status. A blocked, full, or unavailable browser store is reported instead of being treated as success; download an emergency backup before closing. Exports, Drive sharing, the district portal, and optional AI reflection are deliberate transmissions described in section 11.

Practice first

Everything for trying the tool without real records sits under one Practice menu in the header. In a fictional workspace it offers Replay tour, Continue the rehearsal, Open Simulation Studio, Edit the tour, a list of scenarios to load, and the move to real work. In a real workspace it offers Practice in a fictional workspace: your real records are set aside on this device, a fictional roster opens, and Return to real work restores the real workspace exactly and discards the practice data. Starting practice from a named scenario does the same in one step.

The Practice menu open in the header of a fictional workspace: Replay tour, Continue the rehearsal, Open Simulation Studio, Edit the tour, a Load a scenario group listing Small-school tour, Busy midyear, and Evidence-gap review, and Move to real work.
The Practice menu. In a real workspace the same menu offers Practice in a fictional workspace and the scenarios; the real records are set aside and restored on return.

Scenarios and the tour are yours to shape. Simulation Studio (Setup tab) has three presets and a plain-language request box; shape the controls and choose Save current controls to keep the result under a name, which then appears in the Practice menu. Export writes the saved scenarios, and any custom tour script, to a small file; Import merges a file by name, so a district can hand every principal the same training data. The Tour script box below the presets holds the guided tour as a short list of steps, each a tab, a title, and one sentence: edit the wording, add a step about your policy, or trim it, and the tour runs your version until you restore the built-in one.

The first minute

The Google Form this tool replaces takes two minutes to start, so the first minute here is designed to match it. On first launch, Start real work locally is the recommended, focused option; the guided sample stays one click to its left for anyone who wants to try the tool with fictional data first. A blank workspace opens on the Overview with a Set up your first real cycle card whose Add my first educator button jumps straight to the Staff tab with the add form open and the name field focused. Above the tabs there is a single status row rather than a stack of banners: the workspace mode, the save state, and any notice sit on one line, and a Details toggle shows the longer explanation of where records live when you want it.

Rehearse one complete fictional evaluation

Before entering a real name or record, use the built-in rehearsal to experience every evaluator-owned and educator-owned step from assignment through final release.

  1. Enter simulated data. On first launch choose Start a guided sample tour. Finish the seven-screen tour or choose Exit tour. Confirm that the top banner says Simulated data and the role control says Fictional educator, not Educator preview.
  2. Open the stable practice cycle. On Overview, find Practice one complete fictional evaluation and choose Start rehearsal with Teacher 08. The card tracks formal steps completed, fictional final release, and the next owner.
  3. Assign and follow the owner prompts. Choose + Assign formal observation. The Full-cycle rehearsal coach then names the next owner and offers Continue as Fictional educator or Continue as Evaluator when a perspective change is required.
  4. Complete the formal cycle in order. Submit fictional prework; record the pre-conference; start the observation; enter factual, de-identified evidence; tag a component; complete the privacy check; and publish. Then submit the fictional educator reflection, record the post-conference, enter a human-selected rating and rationale for every domain, sign, acknowledge receipt as the fictional educator, and finalize as evaluator.
  5. Complete the annual release. Choose Continue to annual rating preview. For each rated domain, enter the human-selected rating, explain the annual judgment in your own words, and select at least one supporting item from that educator's published or locked evidence. Enter any required local-measure inputs, choose Review final release, verify the disclosure, and confirm the release. In simulated data this records a fictional release only; it does not create or update a district personnel record.
  6. Verify the chain. Back on Overview, the card should read 10 / 10, Recorded, and Rehearsal complete. Choose Review completed fictional cycle and confirm the timeline includes assignment, evidence publication, evaluator signature, educator acknowledgment, finalization, and release.
Fictional-data boundary: interactive perspective switching exists only while the workspace is explicitly simulated. In real local work, Educator preview remains read-only because a role switch is not authentication; the educator responds through a deliberately shared packet or the authenticated district portal. Never paste real personnel or student-identifying information into the rehearsal.
Evaluation Overview after the fictional Teacher 08 rehearsal is finished. The practice card reads Rehearsal complete, 10 of 10 formal steps complete, final release Recorded, and next owner Done, with Review completed fictional cycle and Prepare a clean real workspace buttons beneath the completion message.
A finished end-to-end rehearsal. The completion card routes either to the fictional audit chain or to the reviewed clean-workspace transition.

Move safely from practice to real work

The practice workspace is a rehearsal environment, not a template for personnel records. When training is complete, use the built-in transition so the rehearsal remains recoverable while real work begins in a separate empty workspace.

  1. Open the transition. On the completed rehearsal card, choose Prepare a clean real workspace. The tool opens Reports & audit and moves to the practice-to-real controls.
  2. Review what will happen. Choose Review clean-workspace transition. Check the displayed fictional educator count, fictional workflow-record count, current planning path, and the promise that a backup downloads before the reset.
  3. Acknowledge the boundary. Check the statement confirming that the clean workspace starts empty. Until it is checked, Download rehearsal backup and start clean stays disabled.
  4. Preserve and separate. Choose Download rehearsal backup and start clean. The browser downloads a dated JSON recovery copy, then starts a blank real-work workspace. The sample records are never copied, converted, or mixed into the new workspace.
  5. Complete first-cycle readiness. On Overview, follow Set up your first real cycle. The checklist routes you through Choose an approved record path, Confirm workspace details, and Add the first educator. Its status changes from 0 / 3 ready as each local requirement is completed.
Authorization boundary: the readiness checklist confirms that this browser workspace has a path, complete identifying details, and an educator. It does not approve a personnel-record system or replace district privacy, retention, labor, security, or legal review. Store the downloaded rehearsal backup only where fictional training files are permitted.
Blank private on-device Evaluation Overview showing the Set up your first real cycle card, zero of three ready, and the first Choose record path action. The three readiness items are approved record path, workspace details, and first educator.
The clean real-work Overview makes the next safe setup action explicit and keeps the three readiness requirements visible.

Changing the fictional scenario

In a simulated workspace, open Setup → Simulation Studio. It is intentionally absent from real workspaces. The language interpreter is a local rules parser, not an AI service: no request or record leaves the browser.

Simulation Studio on the Setup tab showing three scenario presets, a large natural-language scenario field with an Interpret request locally button, and the first manual parameter controls for fictional educators and buildings.
Simulation Studio supports preset scenarios, locally interpreted natural language, manual parameters, or a combination of all three.
Adjustable simulation parameters
ParameterAllowed valueWhat happens at the boundary
Fictional educators1 to 60Values outside the range are normalized and shown before preview.
Buildings1 to 8The selected number is distributed across fictional profiles.
Finalized cycles0 to educator countCannot exceed the roster.
Overdue cycles0 to remaining non-finalized educatorsFinalized and overdue counts cannot overlap.
Published walkthroughs per educator0 to 8The preview reports the resulting total.
FrameworkPennsylvania Act 13, Maine PEPG, or Portland PEPGUse the profile menu for exact selection; recognized framework language can also set it.
Intentionally thin evidenceNone or Domain 1 to 4Creates a safe fictional evidence-gap exercise.
  1. Natural language only: type a concrete request such as 18 educators, 3 buildings, 4 overdue, 2 finalized, 2 walkthroughs per educator, Portland framework, thin evidence in Domain 3, then choose Interpret request locally. The result names recognized settings, corrections, and clauses it ignored. Reword only the ignored part; do not assume it was applied.
  2. Manual only: start with Small-school tour, Busy midyear, or Evidence-gap review, then edit the number fields and menus. A normalization warning shows every requested-to-applied correction.
  3. Combined: interpret a sentence first, then fine-tune any field manually. Manual values visible at preview time are authoritative.

Choose Preview changes and inspect the educator, building, finalized, overdue, and walkthrough totals. Nothing changes yet. Apply this simulated scenario replaces only the fictional workspace. Undo last simulation remains available while the Simulation Studio is mounted; export a sample JSON if you need a durable comparison across reloads.

3. A Tour of the Workspace

Evaluators see eight tabs. The Overview is the daily home base: what is coming due, which human step needs attention next, how far the roster has progressed, and how the selected educator's final evaluation is composed.

Evaluation Overview in simulated data. A Practice one complete fictional evaluation card shows zero of ten steps, final release not recorded, next owner Evaluator, and a Start rehearsal with Teacher 08 button. Below it, Coming due and Needs your attention show dated work and direct next-step links.
The current Overview begins with the fictional full-cycle practice card, then the due-date bands and evaluator-owned next-action queue.

A Manual link sits in the header on every tab, so this document is always one click away from wherever you are working.

Directly above the tabs, one status row shows which kind of workspace you are in (private on-device, simulated data, or an educator response packet), whether the latest change is saved, and any notice from the last action with its own Dismiss. Choose Details to expand the sentence about where records live; the row stays compact otherwise.

A footer runs along the bottom of every screen as a standing reminder of the design commitments: no AI scoring, evidence and judgments stay separate, and published records are append-only.

Find the record that needs attention

On Overview, Find your next record filters the action list and roster. Search a name, staff code, assignment, building, or evaluator; narrow by Next step owner or Cycle due. Due-date filters include past due, today through fourteen calendar days, fifteen to thirty days, and open cycles with no due date. Finalized cycles do not count as overdue work.

The matching count reports the filtered educators. Completion charts still cover every active educator you are allowed to access, and filtering does not change the selected educator or any saved record. Use Clear filters to restore the list; keyboard focus returns to search.

The fictional evaluator overview with Search educators, Next step owner, and Cycle due filters, a matching-educator count, and the Needs your attention action list. Completion totals remain based on the full authorized active roster.
Find work by educator, responsibility, or due date. Opening a next step selects the educator and the relevant formal observation, SPM, or visit.

Needs your attention lists evaluator-owned work by cycle due date. Select the action itself to open its relevant record, including when another observation or a locked SPM is also present. Complete final evaluation moves to the annual rating composer. These shortcuts navigate; they do not publish, approve, sign, or finalize a record.

What the tool deliberately does not do

4. Walkthroughs: Evidence and Interpretation

A walkthrough is a middle-of-lesson visit that captures factual evidence. It does not replace a comprehensive observation and it never auto-scores a rubric.

Walkthrough observations tab. The left column lists visit records with badges reading Private draft and Published. The right column shows a published walkthrough for Teacher 03 with separate sections for Directly witnessed evidence and Interpretation or feedback, component tags 2B and 3D, and a conversation area noting that published comments are appended and cannot alter the original evidence.
Evidence and interpretation are recorded in separate fields, and drafts stay private until you publish.

Review each saved visit separately. The publication privacy checkbox belongs to the selected draft and its current content. Switching visits or receiving changed content clears that checkbox. Read the new draft and check it again before publishing. The same boundary applies when you arrive through an Overview shortcut.

5. The Formal Observation Cycle

Formal observations walk a ten-step tracker in order, and the tool will not let steps be skipped silently. The tracker across the top of the record always shows where you are.

Formal comprehensive observations in the fictional sample, showing Teacher 03 at Step 8 of 10. The ten-point tracker has completed steps through Post-conference, Ratings is current, and a Full-cycle rehearsal coach identifies Fictional educator as next owner and offers Continue as Fictional educator before acknowledgment.
The tracker and rehearsal coach partway through a fictional cycle. The coach identifies who owns the next step; later tracker points stay dim until their prerequisites are complete.
  1. Assigned. The observation is created for an educator and stamped with the framework snapshot in force.
  2. Prework. The educator submits pre-observation reflection.
  3. Pre-conference. You meet and record it.
  4. Observation. You observe and collect evidence.
  5. Evidence review. Evidence is published so the educator can see exactly what was recorded.
  6. Reflection. The educator responds to what was observed.
  7. Post-conference. You discuss it together.
  8. Ratings. You enter human ratings with a written rationale for each domain. Nothing is scored by AI at any point.
  9. Acknowledged. You sign, and the educator acknowledges. Acknowledgment records that they saw the record, not that they agree with it.
  10. Finalized. The record locks. Later context appears as appended comments.

Alongside the tracker, the evidence map organizes evidence by domain and shows each domain's weight within Observation and Practice. Component names appear, but rubric-level performance descriptors are not reproduced, because that text is licensed.

In simulated data, the Full-cycle rehearsal coach can change between evaluator and Fictional educator so one principal can practice both sides. That control does not appear as an editable educator role for real local records. Real two-person work requires an educator response packet or authenticated portal account.

Returning to earlier records: when an educator has more than one formal observation, use the Observation record selector beside the educator selector. Records are newest first and show their observation date plus Finalized or the current step. Selecting a finalized record opens its locked history; it does not reopen the workflow.

Artifact boundary: the prework field accepts text and district-authorized, access-controlled references only. None of the three record paths uploads, versions, scans, or retains attachment files. Keep the actual artifact in the district-approved repository, manage its permissions and retention there, and do not paste student-identifying information into the reference.

Annual judgment and supporting evidence

The annual rating is a separate, cycle-level professional judgment. For every domain you rate, record a written rationale and select one or more supporting records. Eligible sources are only this educator's published walkthroughs, formal observations whose evidence has been published, and locked SPM / SLO records. Private drafts, another educator's records, and hand-typed record identifiers cannot support final release.

The tool stores the references as provenance, not as automatic scoring inputs. You still decide what the evidence means. Before final release, the review names what will lock; the district portal independently verifies every selected reference and refuses a missing, unpublished, unlocked, or mismatched source. The final snapshot and released summary retain the rationale and its evidence trail so a later reader can understand the basis for each domain judgment.

Publishing formal evidence, signing, finalizing, approving or locking an SPM / SLO, posting a shared comment, and recording the annual release each open a final review. Read the educator, record, content, visibility, and lock effect before confirming. Cancel returns to the editable record without applying the milestone.

The educator statement

At any point before finalization, the educator can attach a statement in their own words. It is theirs: no evaluator can edit it, it appears verbatim under "In your own words," and it leads the released summary, ahead of any ratings. This mirrors the contractual right to attach a memorandum to a personnel record. Once the record is finalized, the statement is frozen with it.

SPM / SLO: proposal, results, and lock

Use SPM / SLO record to choose among the selected educator's plans. Each option names its date, status, version, and goal. The screen opens unfinished work first unless you followed a shortcut to a specific record. Locked plans remain available for review. Switching educators changes the available records; it does not expose another educator's plans in the educator view.

The SPM / SLO progress guide shows five stages: Prepare proposal, Review proposal, Submit results, Rate and lock, and Locked record. The owner label identifies whose turn it is. A returned proposal goes back to preparation and shows the return reason below. On a narrow screen, focus the guide and use the arrow keys to scroll through its stages. The guide describes the saved workflow; the form controls carry out each action.

The fictional educator SPM screen with a plan-record chooser, a five-stage progress guide, an Educator's turn label, and a returned proposal requiring revision. An earlier locked plan is also available through the chooser.
Select the intended plan, follow the current stage, and review the return reason before resubmitting. Existing locked records remain read-only.

Changing plans with unfinished edits: if a save was refused, the recovery notice keeps those edits with their original plan. You can review another record and return to retry, copy, or discard the unsaved edits. A successful retry is required before advancing that plan. Changing records does not submit or approve anything.

  1. Educator: draft the goal, baseline, measures, and planned actions, then submit the plan.
  2. Evaluator: review the submission. Return it with a reason when changes are needed, or review and approve its current version.
  3. Educator: revise and resubmit a returned plan. After approval, enter year-end results and reflection and submit them for review.
  4. Evaluator: enter a human-selected rating and written rationale, review the lock effect, then lock the record. The locked SPM and its annual LEA rating are saved together.
  5. Annual review: review eligible published or locked evidence alongside the annual judgments. Finishing a formal observation or locking an SPM does not automatically finalize the annual record.

After a published walkthrough or finalized formal record, authorized work in other parts of the cycle can continue. Private pre-conference notes remain hidden from educators. Finalizing the annual cycle closes current-cycle edits; annual rollover is the route to the next year.

6. Framework Profiles

Choose the profile on the Setup tab. Every record permanently remembers which framework and weights it was scored under, so changing profiles mid-year never rewrites old scores.

Setup tab headed Setup, sources, and sharing, opening with a Record Path Setup card titled Choose what happens after you create a record. Three numbered paths sit side by side: Private on-device, marked Selected with no deployment; Principal-managed Drive with a Choose principal helper button; and District portal with a Choose district portal button. The footer links Maine DOE Educator Effectiveness and PEPG Rule Chapter 180, reflecting the Maine default
Workspace setup and the framework picker, with the official references for whichever profile is active.

Pennsylvania Act 13 (Danielson 2021)

Assignment-aware composition: 70/10/10/10 for classroom teachers, 80 percent Observation and Practice where Building Level Data is unavailable, and 100 percent Observation and Practice for temporary classroom teachers.

Portland, Maine (PEPG guidebook)

Uses the published guidebook's four performance levels (Unsatisfactory, Novice/Needs Improvement, Proficient, Excellent), all 22 Danielson components, a categorical decision matrix rather than a numeric average for the summative practice rating, and an evidence expectation of at least nine pieces. Confirm the details against your current district guidebook, because the district plan governs.

How the Portland matrix reaches a summative practice rating

Portland's summative practice rating is categorical, not an average. The tool checks four rules in order and stops at the first one that fits:

Decision rules, applied top to bottom
ResultWhen
UnsatisfactoryAny domain is rated Unsatisfactory.
ExcellentTwo or more domains are Excellent and none is below Proficient.
Novice/Needs ImprovementThree or more domains are at Novice/Needs Improvement.
ProficientEverything else: no more than two domains below Proficient, and none Unsatisfactory.

Because the rules run in order, a single low domain outranks several high ones. That is the intended behaviour of a matrix and the main way it differs from an average:

Worked examples, using the four domain ratings in order
Domain ratingsResultWhy
0, 3, 3, 3UnsatisfactoryOne Unsatisfactory domain decides it, even beside three Excellent domains. An average would have read 2.25.
3, 3, 2, 2ExcellentTwo Excellent domains and nothing below Proficient.
3, 3, 1, 2ProficientTwo Excellent domains, but one sits below Proficient, so the Excellent rule does not apply.
1, 1, 1, 2Novice/Needs ImprovementThree domains at Novice/Needs Improvement.
2, 2, 2, 2ProficientThe ordinary case.

No summative practice rating is produced until all four domains are rated. A partially rated record stays blank rather than guessing.

Maine PEPG (district plan governs), the default

New workspaces start on this profile. Maine systems are local. Your district plan, built with a steering committee that has a teacher majority, chosen by the local bargaining unit representative where teachers are covered by an agreement, and revised by consensus, defines the rubric, rating levels, category weights, and process. Enter your plan's Professional Practice and Student Learning and Growth split. Since the 2019 amendments, student learning and growth measures are a district choice rather than a state mandate. This workspace mirrors your plan; it never substitutes for it.

The Trends tab shows finalized ratings and workflow activity over time. Evidence text, comments, and rationales are never aggregated into a number.

Teacher trends and cohort context tab. An amber notice reads that this is a privacy-aware aggregate and not FERPA certification, that cohort values appear only when at least ten eligible peers contribute, that small groups are suppressed, and that results are descriptive and must not be the sole basis for personnel decisions. Below are trend filters for educator, metric, and a date range, then a longitudinal snapshot for Teacher 03 counting published walkthroughs, finalized formal observations, and released cycle snapshots.
Trends, with the cohort-suppression rule stated on the screen where the comparison is made.

Coverage across the roster

For evaluators, Trends opens with two roster-wide panels. Walkthrough coverage across the roster lists each active educator with their published visit count, last visit, and days since, sorted so the longest-unvisited educators appear first; the screen calls it a planning aid for spreading visits, not a judgment about anyone. Documented evidence by domain counts evidence tags on published records and names the components with no tagged evidence yet, which is a professional-development planning signal, never a rating. Both panels follow the date filters and count activity only; ratings are never aggregated there.

Two Trends panels in fictional sample data. Walkthrough coverage across the roster lists eight educators with six never-visited rows first, each showing zero published visits and No published visits yet, then Teacher 01 with two visits, a July 6, 2026 last visit, and 48 days since, and Teacher 03 with one visit nine days ago. Beside it, Documented evidence by domain counts one Planning and Preparation tag, five Classroom Environment, nine Instruction, and zero Professional Responsibilities, and names the components with no tagged evidence yet in each domain.
Roster-wide coverage on Trends: the longest-unvisited educators surface first, and the domain counts show where documentation is thin. Fictional sample data.

Documented evidence by component

Below the domain counts, a component grid shows every framework component with the number of published records that tag it and how many educators those records cover. Cells shade with volume; components with nothing documented are outlined and say so. Read it as a map of where evidence has been gathered across the building and where it has not, for example a domain that is well documented in one homeroom and silent everywhere else. It is a count of evidence tags, never a rating, and it never aggregates a score.

Trends tab in fictional sample data. Under the roster coverage table, a Documented evidence by component panel lists the four domains; each component appears as a small cell such as 2B with 3 records and 2 educators, 3D with 4 records and 3 educators, while undocumented components like 1A read Not yet documented.
The component grid on Trends. Shaded cells have published evidence; outlined cells have none yet. Fictional sample data.

The framework snapshot

Every record is stamped with the framework and weights that were in force when it was created. If your district changes frameworks, or you switch profiles to compare, the tool recalculates nothing retroactively: a record scored under Pennsylvania Act 13 keeps its Act 13 math forever, and a Maine record keeps its Maine math. This is why a trend line stays trustworthy across a policy change, and it is also why two records in the same list can be scored differently on purpose.

8. For Educators Being Evaluated

Your next step follows your own work

The Your next step card prioritizes work the educator can do: pre-observation materials, reflection, acknowledgment, a returned SPM plan, or year-end results. An evaluator's concurrent task does not hide these actions. When only evaluator work remains, the card says no action is required from you right now. Real local educator preview remains read-only; the fictional workspace allows role switching for rehearsal.

A fictional educator overview showing a returned SPM plan as Your next step, with a Your turn label and a button to revise and resubmit, even though a formal observation also has evaluator work remaining.
The educator sees their own next action and opens the corresponding record. Acknowledgment records receipt, not agreement.

There are two deliberately different educator perspectives. In a private on-device workspace, Educator preview lets the evaluator inspect visibility but cannot change a real record. In the district portal, an educator signing in with their managed district account gets editable educator-owned steps and their own set of tabs, scoped to them alone. Colleagues' records are never visible.

Read-only Educator preview in a real private on-device workspace. A blue banner states that changes are blocked because local role switching is not authentication. Teacher 03's My evaluation page is visible, but the statement field and Save statement button are disabled and direct the educator to a response packet or authenticated portal.
The local Educator preview is a visibility check, not educator access. Real-record fields stay disabled because a local perspective switch does not authenticate another person.
The district portal signed in as an educator. The banner reads District Google account with the educator's own address and Educator access. Only the seven educator tabs appear, the page shows that educator's own weighting donut badged In progress, and the statement box is open for writing. No roster and no colleagues' records are visible.
The same portal signed in as the educator. They see their own record and nothing else, with no roster and no way to reach a colleague's file.

Three things worth knowing as an educator. You see the same evidence your evaluator sees, as soon as it is published. Acknowledging a record means you have seen it, not that you agree with it. And if you disagree, or if there is context the ratings do not capture, write a statement: it leads the document, word for word, and no one can edit it.

You can download your own workflow summary and growth snapshot at any time. The teacher view cannot export the whole workspace or see organization-wide audit events.

9. Setting Up the District Portal

Get IT permission first. The portal must live in a district-owned Google account, never a personal one, and district IT and leadership should approve it like any system that touches personnel records, including LEA authorization, a privacy and security review, and approval of any rating forms.

The portal is a separate deployment from the AlloFlow Class Mailbox. The mailbox is deliberately open to anyone with the link, because homework is low-stakes. The evaluation portal is the opposite: district-domain accounts only, and it fails closed without one.

  1. Create a district-owned standalone Apps Script project. Add all four required files: Code.gs, Index.html, Portal.html, and appsscript.json. In Project Settings, first enable display of the manifest.
  2. Review scopes and ownership with district IT. The project uses the deployment owner's Drive for the private repository. Record who assumes ownership if that account changes.
  3. Add a temporary no-argument setup wrapper. Apps Script's Run button cannot supply the object argument directly. Paste the template below at the end of Code.gs, replace every example value, run runDistrictSetupOnce as the same account named by bootstrapAdmin, save the returned repository IDs, then delete the wrapper and save again.
  4. Deploy a Web app. Choose Execute as: Me and Who has access: users in your domain; never choose Anyone. Copy the resulting /macros/s/…/exec URL.
  5. Verify before real records. Run verifyDeploymentIdentity(), then test the URL as an administrator, an assigned evaluator, an assigned educator, an unlisted same-domain account, and a personal Gmail account. The last two must receive Access unavailable; each permitted account must see only its authorized scope.
  6. Register the reviewed URL. Re-run the setup wrapper with the exact webAppUrl included, remove the wrapper again, and give staff only that reviewed /exec link. Google sign-in and server assignments, not possession of the link, decide access.
function runDistrictSetupOnce() {
  return setupEvaluationRepository({
    allowedDomain: 'example.k12.pa.us',
    bootstrapAdmin: 'principal@example.k12.pa.us',
    adminDisplayName: 'Principal',
    organization: 'Example School District',
    building: 'Example School',
    academicYear: '2026-27',
    webAppUrl: '', // add the reviewed /exec URL on the second run
    teachers: [{
      id: 'teacher-001', code: 'T-001', name: 'Educator Name',
      building: 'Example School', assignment: 'Grade 6',
      employeeType: 'professional', buildingData: true,
      teacherSpecificData: true, evaluator: 'Evaluator'
    }],
    members: [
      { email: 'principal@example.k12.pa.us', displayName: 'Principal', role: 'admin', active: true },
      { email: 'evaluator@example.k12.pa.us', displayName: 'Evaluator', role: 'evaluator', active: true },
      { email: 'teacher@example.k12.pa.us', displayName: 'Educator', role: 'teacher', teacherId: 'teacher-001', active: true }
    ],
    assignments: [
      { teacherId: 'teacher-001', evaluatorEmail: 'evaluator@example.k12.pa.us', active: true }
    ]
  });
}

Current operational boundary: treat this package as a district-reviewed pilot until the district has documented and tested backup/restore, the archive-first annual rollover below, retention and legal-hold handling, authorized deletion, deployment-owner transfer, and official-record handoff. The portal makes rollover safer; it does not make those lifecycle responsibilities disappear.

The district portal in an evaluator's browser. A green banner identifies the signed-in district account and evaluator access beside controls for refreshing, sending a content-free portal notice, and reviewing released-summary access. The server, rather than a role switch, decides which records are visible.
The connected portal. The signed-in identity replaces the role switch, because the server decides what each person can see.

After connecting, Run setup health performs a read-only check of the domain lock, repository files, assignments, unresolved release/rollover recovery, private-artifact recovery, and whether the effective deployment owner still matches the bootstrap administrator. It never completes a pending workspace commit and never changes a ledger. Its parity check compares every projected value: all eight Message cells, Audit payload columns 0-9, and all thirteen Snapshot cells. The Audit previous-hash and row-hash columns are verified separately as a chain. Ledger-only Message and Audit rows are reported as legitimate retained conversation or operation history; health does not propose deleting them. The Private artifact recovery row derives from the sealed, integrity-checked operation journal, so a missing or stale advisory marker cannot hide or manufacture pending work.

The health result is content-free. Along with counts, it reports the current workspace revision, recovery category and age, the current audit-verification result, the last clean reconciliation time, and remaining email quota only when Apps Script can expose that number safely. It never returns evaluation text, member email addresses, or notification recipients. Duplicate IDs, a canonical/ledger row with the same ID but different content, an unexpected Snapshot, ambiguous configuration state, or an outbox ID collision are marked for district-IT manual review. If parity or typed-recovery inspection is unavailable or requires manual review, the derived-ledger row says Needs attention; it is never presented as healthy merely because no automatic repair can run.

Review and confirm a workspace-ledger repair

  1. Select Run setup health. Read the recovery category, age, revision, parity counts, audit verdict, and last clean reconciliation before deciding whether repair is appropriate.
  2. Select Review ledger repair. Review changes nothing. The server creates a ten-minute token bound to the signed-in administrator, current workspace revision, and complete health fingerprint. Any intervening change makes it stale.
  3. Inspect the listed counts and effects. An automatic plan may only append safely missing canonical Message, Audit, or Snapshot rows; replay an exact queued operation-audit entry; synchronize an unambiguous academic-year configuration value; or complete a pending commit whose journal and active state prove completion is safe. It never edits or deletes an existing ambiguous or ledger-only row.
  4. Check the repair acknowledgment only after the plan matches the incident or operations record. Then select Confirm reviewed repair. A direct confirmation without the current review token and acknowledgment is refused.
  5. Run setup health again and preserve the result with the district change or incident record. If the review says the condition is nonrepairable, stop: do not confirm, edit Spreadsheet rows, or remove a property. Route the review to district IT to inspect the canonical workspace, pending journal, ledger, audit chain, and approved backup.

There is no clear anyway, force, discard, or delete option. An owner mismatch is also a warning rather than an ownership-transfer tool: district IT must transfer and test Apps Script and Drive custody through approved Google Workspace procedures.

Review and confirm released-summary access recovery

  1. From Setup health, select Review released-access recovery. This first step is read-only. It reports only the scope, workspace revision, document and queue counts, unregistered queue items, reviewed quarantine candidates, candidates needing district IT, static issue categories, and allowed effects; it does not expose evaluation content, account addresses, Drive IDs, or permission principals.
  2. Stop if the review is uninspectable, requires manual review, or says it is not repairable. Released-folder owner, location, or retention ambiguity and an uninspectable principal are manual-review-only. Otherwise compare the bounded batch and deferred counts with the district incident or access-change record; the global reviewed workflow can repair known permission drift.
  3. Check the access-policy acknowledgment and confirm with the current review. The token is bound to the signed-in administrator, selected scope, and current workspace, directory, registry, queue, folder, next-batch access state, and exact privately held orphan queue/file candidates. It expires after ten minutes, is single-use, and is revalidated under the server lock before any mutation. Confirmation can quarantine only those exact reviewed candidates.
  4. A confirmation processes no more than 20 documents. If recovery remains, run a new read-only review before each next batch. An educator-scoped review is deliberately narrower: it cannot run global Released evaluations folder recovery and does not touch folder-wide state.
  5. Run Setup health again. A stale review, changed access state, unidentified principal, invalid pointer, or overflow/manual result must be reviewed again or escalated to district IT; do not edit the recovery property to bypass it.

Routine district administration without the script editor

An authorized administrator now has a District operations center inside Setup. It is for recurring work after the one-time repository deployment. Each sensitive operation follows the same pattern: enter the request, review a server-produced summary that changes nothing, check the explicit acknowledgment, then confirm. Reviews are tied to the signed-in administrator and current repository state, expire after ten minutes, and cannot be reused. A confirmation that waited for another operation re-resolves the signed-in account and its active directory authority after acquiring the server lock; a demotion, deactivation, reassignment, or account change while queued prevents the mutation.

District workspace configuration

  1. Open Setup → Workspace setup while signed in with administrator access. Evaluators and educators see the current values as read-only.
  2. Edit the organization, default building, academic year, evaluator display name, approved built-in framework profile, optional Maine Professional Practice weight, or AI reflection policy. These edits are only a browser draft at this point.
  3. Select Review district configuration. The server returns a current-versus-proposed table plus the number of active educators, open cycles, and records whose weights or finalization history are already protected.
  4. Compare every row with the district-approved plan. When a framework or weight changes, the review explicitly states that eligible future work can use the new policy while existing frozen snapshots are not recalculated.
  5. Check the impact acknowledgment and select Confirm reviewed configuration. The server rejects direct configuration changes made through ordinary autosave, stale reviews, expired reviews, reviews created by another administrator, and reused tokens. A successful confirmation creates a server audit event.

Custom rubric boundary: the district portal currently persists only its approved built-in framework profiles. Custom rubric JSON import remains available in a private on-device workspace, but it is intentionally unavailable in the portal until the server can validate, version, license-review, and preserve the exact rubric for every affected record. The portal administrator can download the current rubric reference without changing policy.

Accounts and evaluator assignments

  1. Create the educator profile in Staff first. The profile ID is an opaque application ID, not an email or employee number.
  2. Open Setup → District operations center → Accounts and evaluator assignments. Wait for the current managed member table to load.
  3. For an educator account, enter the managed-domain email, display name, choose Educator, and link the correct educator record. For an evaluator or administrator, choose that role; no educator link is used.
  4. Select Review member change. Compare the normalized managed email, role, record link, and active status. Check the legitimate-educational-interest acknowledgment, then choose Confirm directory change.
  5. To authorize an evaluator, choose the educator and an active evaluator/administrator member, set the assignment active or inactive, then use Review assignment change and the same confirmation step.

The portal blocks an educator account that points to a missing educator, an assignment to a missing or inactive evaluator, removal of the bootstrap administrator, or a change that would leave no active administrator. If any other member or assignment changes during review, reload and review again.

Annual cycle due-date schedule

  1. Open Annual cycle due-date schedule, choose the date, and optionally enter an exact building name.
  2. Choose Open cycles without a due date for the safest fill-in operation, or All open cycles only when replacing current dates is intended. Inactive and finalized cycles are never changed.
  3. Select Review schedule impact. Read the affected count, finalized count skipped, and sample names. A zero-result review cannot be confirmed.
  4. Confirm the scope and apply. Then choose Reload scheduled records and spot-check the Staff list.

Audited private exports and official-record handoff

Private export is not official-record filing. The portal creates the requested file privately in the deployment owner's Authorized exports folder. It does not email, share, move, or declare that file to be the official personnel record.

Before each export, Review private export performs a read-only inspection of the configured folder and every existing file. It reports content-free counts for existing files, drifted files, explicit access grants, and folder drift, and binds the exact access and file-inventory fingerprints to the review. It does not expose principals, file IDs, or record content. Confirmation revalidates the exact reviewed inventory, deployment owner, managed parent, non-trashed state, and access fingerprint; removes non-owner viewers/editors from the folder and all prior exports; disables editor resharing; and re-inspects everything before it creates the new file. If any item moved, disappeared, was replaced, was trashed, changed owner, or has access that cannot be identified, inspected, removed, or verified, the workflow fails closed with no new export and requires district-IT manual review. Capacity is reserved before a review token is issued: 249 existing exports may create file 250, but a folder already holding 250 refuses the review before a token, journal intent, ACL repair, or new file is created. Confirmation rechecks that bound under the repository lock, while an exact replay of an already-created file 250 remains available. District IT must apply the approved retention procedure before preparing another export. The service does not silently create a replacement folder.

  1. Choose Roster and cycle status CSV, One educator's complete portal record, or Complete repository workspace backup.
  2. Write a specific authorized purpose, such as the approved annual HR handoff under a named district procedure. Avoid generic text such as “backup.”
  3. Select Review private export. Verify the scope, named educator when applicable, current counts, purpose, private destination, and the content-free Authorized exports access review. Do not confirm if inspection is unavailable, manual review is required, or any count is unexplained.
  4. Confirm district authorization, destination, retention, legal hold, and handoff. Select Create verified private export. The server first rejects a stale access fingerprint, then repairs and re-verifies the folder and every prior export before creating the new file. It re-reads and hashes the new stored bytes before returning a Drive link and writes the event to the canonical audit. If the file is created but the audit sink is temporarily unavailable, the result says recovery_pending / auditPending. The verified file already exists: do not create it again. Keep the review open, run health, choose Review ledger repair, inspect and acknowledge the exact outbox replay, select Confirm reviewed repair, then return and choose Check exact export outcome to close the artifact journal.
  5. If the browser says the outcome could not be confirmed, keep the original review and acknowledgment open and select Check exact export outcome. That exact token is an idempotency key: the server recovers and returns the journaled file and canonical audit result instead of creating a duplicate. The portal checks outcome under the same server lock as creation. It releases the old form only when the server conclusively proves that nothing started and the review is unusable; an ambiguous, pending, completed, or unavailable verdict keeps exact recovery locked in place. Do not cancel, reload, or prepare a new export review while that option remains available.
  6. Open the Drive link, preserve the displayed SHA-256 under district procedure, complete the approved handoff, and document custody. Delete or retain the private working export only according to district policy.

Archive inventory and non-destructive restore rehearsal

  1. Select Load and verify annual archives. Before listing, the server takes the repository lock, rechecks that the same signed-in account is still an administrator, revalidates owner-only private access on the configured folder and every archive file, then recalculates each embedded workspace hash. A sticky viewer/editor or link-sharing failure stops the inventory. A pending workspace commit or private-artifact recovery must be resolved before this ACL-repairing inventory runs; annual-rollover recovery itself still permits archive inspection. Custody inspection and selected-file lookup are bounded at 250 folder items; an oversized folder stops for district-IT review before item 251 is read.
  2. For a verified archive, choose Review rehearsal. Compare archived year/revision and record counts with the active year/revision.
  3. Acknowledge that the action creates a separate candidate and does not perform a live restore. Choose Create private restore candidate. If the candidate is verified but its audit write is pending, keep the review open and do not create another candidate; use the reviewed ledger-repair flow to replay the exact audit entry, then choose Check exact candidate outcome to close the artifact journal.
  4. If the browser response is lost, retain the review and select Check exact candidate outcome. The server verifies and returns the one journaled candidate; it does not create a second candidate.
  5. Open the candidate in the private Restore rehearsals folder and have district IT test its contents through the approved recovery procedure. The live workspace remains unchanged; the portal intentionally offers no one-click production restore.
Recommended operating rhythm: run Setup health before a scheduled bulk change, keep the review card with the district change ticket, spot-check after reload, verify the audit event, and rehearse at least one annual archive in a non-production process before the next rollover.

Annual rollover: archive first, then start the new year

Administrator-only and high impact. Complete this in a test repository first. The workflow creates and verifies a private archive before changing the active workspace, but it does not select your retention period, execute a legal hold, transfer ownership, or file the record in your official HR/records system.

  1. Finish district preflight. In the portal, open Setup, run Setup health, and resolve any repository, workspace-integrity, audit-chain, owner-continuity, released-summary recovery, or rollover-recovery warning. Confirm that district backup/restore, retention, legal hold, official-record handoff, and owner succession are documented and tested.
  2. Open Annual rollover & continuity. Enter the immediately following academic year in YYYY-YY form. For example, an active 2026-27 workspace can advance only to 2027-28. Choose Review annual rollover. Review changes nothing.
  3. Read the live impact review. It lists active educators, finalized cycles, open cycles, current walkthroughs, formal observations, SPMs, comments, prior cycle snapshots, and released-document references. The review expires after ten minutes and becomes stale after any intervening workspace save.
  4. Make an explicit custody decision. Check the district-custody acknowledgment only after verifying backup/restore, retention, legal hold, official-record handoff, and deployment-owner responsibility. If open cycles exist, separately acknowledge that they will be preserved in the archive but will not carry into the new active year.
  5. Create the archive and start the year. Choose Create archive & start …. The server first revalidates the existing archive folder and prior files as owner-only private, creates a private JSON file in the repository's Annual archives folder, re-reads it, checks the embedded workspace hash and exact stored bytes, and only then writes the clean active year. An ACL verification failure stops before the year changes.
  6. Verify the result. Open the returned verified private archive link, record its Drive location and archive ID under district procedure, confirm the file is private, then choose Reload active year. Run Setup health again.

What is retained and what is reset

Annual rollover treatment
Retained in the new active workspaceReset for the new active yearPreserved outside the active year
Educator roster and profile identifiers, active/inactive status, member accounts, evaluator assignments, framework configuration, immutable prior cycleSnapshots, and audit history.Due dates, cycle status, activity/finalization/lock timestamps, current ratings, weights and final score, educator statement, released-document pointer, walkthroughs, formal observations, SPMs, and comments.The complete pre-rollover workspace in the verified private JSON archive. Existing released Google Docs remain where they are and are never deleted or unshared by rollover.

Resetting the active pointer to a released summary does not delete that Drive document. The old pointer, permissions, and document context remain in the archive, and the file remains subject to district retention and legal-hold rules. The archive is intentionally private to the deployment owner; districts that require independent custody must copy or export it through an approved, auditable handoff.

If rollover is interrupted

If the archive is verified but the active commit cannot be confirmed, the portal reports Annual rollover recovery required and blocks another review. Do not keep clicking rollover. Choose Recheck interrupted rollover. The server reopens and verifies the recorded archive, then clears the block only if it can prove one of two states: the new-year commit is present, or the exact old revision and old academic year are unchanged. In the second case the verified archive is kept and a fresh review can be started. If the workspace is in any mixed state, the block remains and district IT must compare the active workspace.json, its metadata row, pending journal, and the exact annual archive before proceeding. Never delete a released document or archive merely to clear a warning.

10. The Released Summary: How It Arrives and What It Says

In the district portal, releasing a finalized evaluation is a review, then confirm workflow. Opening the review changes nothing:

  1. Select the finalized educator and choose Review & share released summary. The server resolves the active educator member account; the browser does not supply or edit the recipient.
  2. Read the disclosure card. It names the educator, exact managed Drive account, finalization time, intended access, notification boundary, and whether the action will create, verify, or replace a document. The review token expires after ten minutes and becomes invalid if the record changes.
  3. Check the confirmation only after verifying the account, then choose Confirm and grant access. The summary is generated as a Google Doc in the private Released evaluations folder and that single file is shared view-only with the educator. The initiating evaluator is also given access when they are not the deployment owner, so Open current summary behaves as labeled.
  4. Choosing Review released-summary access later verifies or restores access to the same immutable document; it does not quietly create duplicates. A replacement is offered only when the recorded file is unavailable, and the old pointer is retained as superseded history.
  5. This Drive action does not send the separate content-free portal email. Use Email educator a portal notice deliberately if one is needed. Google can still surface Drive access in its own activity or notification interfaces, so the tool does not promise that Drive itself is silent. If the portal reports Notice sent · audit recovery pending, the email already left: do not resend it. Ask an administrator to run health and complete the reviewed ledger-repair flow so the exact queued audit entry can be restored.
  6. When the educator follows the portal summary link, a link-opened receipt is attempted. It records that the link was clicked, not that the document was read, understood, or actually received. If that write fails, the summary still opens and the portal now displays the receipt error instead of suppressing it.

Sharing is a deliberate evaluator action, never a silent background job. If Drive access succeeds but the repository commit cannot yet be confirmed, the portal says Release recovery required, disables another attempt, and tells an administrator to run Setup health. A failure before commit attempts to remove newly granted viewers and move the uncommitted file to trash; an unconfirmed cleanup also appears in Setup health. Do not retry until the recovery item has been inspected. District IT should still test recipient access, tenant-specific Drive activity, recovery, retention, and legal-hold procedures before production use. In the on-device workspace, use Export growth snapshot instead: it produces a formative, ratings-free file you can hand to an educator directly.

What the document actually says

Below is a real summary produced by the tool, abridged, using fictional names. Notice the order: the educator's own words come first, strengths come before growth areas, and the arithmetic is explained rather than asserted.

Educator Effectiveness Summary — 2026-27

Prepared for Teacher One on 2026-08-13 by Principal Rivera.

This document is a plain-language summary of your finalized evaluation. It is shared view-only with you. Your district decides which authorized personnel system is the official record; the portal holds the observations, timestamps, and revisions used to assemble this copy.

In your own words

This year I rebuilt my small-group reading block so every student conferences with me at least twice a month. Attendance in my first period was uneven through the winter, and I want that context on the record alongside my ratings.

Written by you in the portal (2026-08-13); no one edited it.

Your strengths

Planning and Preparation, rated Distinguished (how the lesson and its goals were designed)
Plans name the standard, the misconception to watch for, and the check for understanding.

Classroom Environment, rated Distinguished (the respect, routines, and culture students experience)
Transitions are routine and student-run; the room lost under a minute across three transitions.

[ two further domains follow, each with its evaluator's written rationale ]

Walkthrough observation (2026-08-09)
The discussion-norms anchor chart is doing real work; students referenced it without prompting. Worth sharing at a team meeting.

Your overall rating, in plain language

Overall score: 2.69 out of 3, which is the "Distinguished" performance band. Bands are fixed statewide cut points: 2.50 and above is Distinguished, 1.50–2.49 Proficient, 0.50–1.49 Needs Improvement, below 0.50 Failing.

ComponentWeightWhat it measures
Observation & Practice70%Your observed practice across the four domains below.
Building Level Data10%Your building's performance data for the year.
Teacher-Specific Data10%The measures selected for your role and assignment.
LEA Selected Measure / SPM10%The measures selected for your role and assignment.

Your final score is the weighted average of these components — each score is multiplied by its weight and the results are added. No component is hidden and no other factor enters the calculation.

[ a domain-by-domain table follows, giving each rating in plain language ]

Growth focus

No component of your finalized evaluation was rated below Proficient.

Transparency and your rights

This summary was assembled only from the finalized records in the district portal: 1 finalized formal observation and your locked student performance measures. Every rating shown here was assigned by a person and carries that person's written rationale in the portal; the software performs arithmetic only.

  • You can read every underlying record, timestamp, and revision in the portal at any time.
  • You acknowledged the observation before finalization; acknowledgment records that you received it, not that you agree.
  • You can add a written response through the portal dialogue, and it becomes part of the record.
  • Finalized records are immutable — nothing in this summary can be edited after release without a new, visible record.

Questions about this evaluation go first to your evaluator or to Sample School District leadership. This copy is shared view-only to your district account; if any detail here disagrees with the portal, the portal record governs.

The wording adapts to your framework profile: a Maine or Portland workspace names that plan's rating levels instead of the statewide Pennsylvania bands.

11. Privacy, Records, and Boundaries

“Local” describes the normal working store, not every action a user can take. Use this data-flow table when reviewing the tool with privacy, labor, records, and IT staff.

Where information goes and what triggers it
ActionDestinationInformation involvedTrigger and choice
Private work and delayed saveThis browser profile on this deviceThe complete local workspaceAutomatic after an edit; visible save status reports success or failure.
Workspace, report, packet, or recovery exportThe download location and any system through which you later store or send the fileThe export's stated scope; workspace JSON is the broadestUser selects a Download/Export action. Review and store it only in an authorized location.
Principal Drive helperThe verified principal's district Drive and one reviewed recipient's Drive accessOne validated educator packetPrincipal completes a disclosure review, then explicitly confirms. Google Drive is asked to notify the recipient.
District portalThe district deployment owner's Google Workspace repository; released copies may be shared to an educator's Drive; annual archives remain private in the repository owner's Drive until an approved district handoffAuthorized workspace records, released summaries, and a complete pre-rollover workspace inside each verified annual archiveManaged sign-in plus server role/assignment checks; sharing and administrator-confirmed annual rollover are separate actions.
AI reflectionThe AI provider configured in AlloFlowThe selected educator's evidence notes and ratings; the name field is omittedOff by default. An evaluator enables it under Setup → Advanced workspace options and requests a second read.
QR codeNo record destination; it encodes only a workspace or portal URLA link, never the current workspace recordsVisible only for the private path or a connected portal.

12. Backing Up and Moving Devices

The on-device workspace lives in your browser's storage. That is what keeps normal editing local, and it is also its main risk: clearing browser data can erase it, and it does not follow you to another computer. A persistent header status distinguishes Saving, Saved on this device, and Changes are not saved.

Reports and audit tab headed Audit, reports, and handoff. The left column shows an audit timeline listing dated events including assigned, prework submitted, observed, evidence published, reflection submitted, and signed, each naming the actor and role. The right column holds an Export and transfer card with buttons for Export workspace JSON, Export status CSV, Workflow summary HTML, and Growth snapshot, an Import another device export section, and a warning that the district-authorized system remains the official summative rating record.
The audit timeline records who did what and when. The export card beside it is your backup and transfer route.

Exports can contain confidential personnel information. Store and transmit them only through district-authorized systems, never personal email or cloud storage.

If storage is corrupt: the app quarantines the raw value rather than silently replacing it with sample data. Download the damaged raw workspace for recovery, retry storage, or use the explicit two-confirmation fresh-start action. If storage is unavailable, continue only as a temporary session and export before closing. If a save fails, use Retry save and Download emergency backup.

The district portal changes the backup owner; it does not remove the concern. Its annual rollover creates and verifies a private point-in-time archive before resetting active cycles, but that archive still lives under the deployment owner's Drive custody. District IT must define and test independent repository backup/restore, archive handoff, retention, legal hold, authorized deletion, annual rollover acceptance, and deployment-owner transfer. Its hash chain can detect many edits to retained rows, but without an independent external anchor it should be described as tamper evidence, not proof that no tail or whole-log deletion occurred.

13. Using It on a Phone

Walkthroughs happen while you are standing in a doorway, so the workspace reflows to a single column on a phone. The tab strip scrolls sideways, cards stack, and buttons keep a large touch target.

The workspace at phone width showing the Walkthroughs tab in a single column: a horizontally scrolling tab strip, a large Start walkthrough button, and stacked visit records badged Private draft and Published, each showing the educator, date, duration, and note.
The Walkthroughs tab on a phone. Everything stacks into one column and nothing scrolls sideways except the tab strip.

Recording a walkthrough on a phone

The walkthrough form is built for a phone held in one hand. Below 640 pixels it becomes a single column with 48-pixel inputs in 16-pixel text, so the phone does not zoom when you tap a field. Quick length buttons set the visit duration to 5, 8, 10, or 15 minutes with one tap. Evidence-tag rows are 44 pixels tall with large checkboxes, and the Save private draft and Review & publish bar sticks to the bottom of the screen so it is always within reach of a thumb. The draft is kept in the browser tab as you type, so an interruption does not erase it.

The walkthrough form at phone width: single-column fields for Announced and Duration, a Quick length row of 5, 8, 10, and 15 minute buttons with 10 min selected, the Lesson phase select, and a save bar pinned to the bottom with Save private draft and Review and publish to teacher.
The walkthrough form on a phone. The quick-length presets and the pinned save bar are the two controls a principal uses most between classrooms.

14. Accessibility

The workspace includes keyboard, screen-reader, contrast, responsive, and touch-target contracts. Automated checks are one layer of review, not a guarantee that every screen or assistive-technology combination has zero barriers.

Language

The evaluation workspace is currently available in English only, while the rest of AlloFlow is translated into many languages. Evaluation records are personnel records, and which language they are written in is a district policy question rather than a display setting, so translation is waiting on that decision rather than on the technology. If your district needs another language of record, that is worth raising before you adopt the portal.

The Educator Evaluation workspace in the high-contrast theme: black backgrounds, white text, amber accents on the selected tab, buttons, and links, and white borders around every card and control.
The high-contrast theme, as it appears inside AlloFlow when that theme is chosen in the app.

Automated checks catch a great deal but not everything. If you hit something that does not work with your assistive technology, that is a bug worth reporting, not a limit you should work around.

15. Sharing the Tool by QR

The Setup tab shows Share by QR only after you choose the private on-device path or connect a district portal. The principal-helper path uses its saved private /exec launcher instead. The QR card keeps a selectable URL visible if QR drawing or clipboard access fails.

Share by QR card on the Setup tab, showing a QR code beside the address https://alloflow-cdn.pages.dev/educator-evaluation and a Copy link button, with the caption that anyone can scan this to open their own private on-device workspace and that your data is not shared by the code.
The Share by QR card in the on-device workspace, pointing to the published page rather than to anything on your machine.

16. Sending an Evaluation to an Educator by Email

The QR card above shares the tool. This section is about sharing one educator's evaluation with that educator, and getting their written response back, without any district server.

On Reports & audit, select one educator and choose Educator packet (send to educator). The packet boundary is state-based: it includes published walkthroughs, released formal evidence and ratings, eligible SPM records, permitted shared comments, and the educator's own submitted words. Evaluator drafts, unpublished evidence, unsigned ratings, internal receipts, audit rows, and every other educator are excluded.

Preview the downloaded HTML before sending it. Limit profile names to codes changes known profile labels, but it does not rewrite narrative evidence or comments; free text may still identify educators, students, colleagues, or classes.

Email the HTML only through a district-approved channel. The educator can open it in a browser and read the released evaluation with no account. Its response form provides their statement, eligible reflections, and a separate acknowledgment for each eligible walkthrough or formal record. Acknowledgment means “received/read,” not agreement or a contractual signature. The form downloads a small JSON response that they return to the evaluator.

Use Import workspace or educator response, then choose the response JSON. File selection does not apply anything. Review the source packet id, educator, statement/reflection/acknowledgment counts, stale records, and ignored fields, then choose Apply this reviewed response.

What a returned file can and cannot change. Only the educator's own words are accepted: their statement, eligible reflections, record-specific acknowledgment intent, and permitted response comments. Ratings, evidence, evaluator notes, workflow state, and supplied timestamps are ignored even if the file was edited by hand. The app stamps the receipt time and reports every stale or dropped field. If a source record changed after packet issue, that response is identified rather than quietly overwriting current work.

The receipt is not a signature. Each checkbox records acknowledgment intent for that specific record. It does not replace the conference or signature process required by district policy.

17. Using Your District's Own Rubric

The tool ships with three scoring profiles (Pennsylvania Act 13, Portland ME PEPG, and Maine PEPG). In a private on-device workspace only, you can relabel and replace the components of the existing four-domain rating structure. This is a compatibility option for local planning, not support for an arbitrary data model and not a district-portal policy control.

As an evaluator, open Setup → Advanced workspace options → Custom rubric. Download current rubric gives you the active one as a JSON file to use as a starting point. Edit the domains, their components, weights, colours and rating-band labels, then use Load a custom rubric. Restore the built-in rubric puts it back.

The JSON must contain exactly four unique domain ids: d1, d2, d3, and d4. Each needs a label and a components array. A domain can contain at most 50 unique component codes. A weighted rubric must give every domain a positive weight and total exactly 100 percent; an unweighted rubric is normalized to four equal 25 percent display weights. Bands must use unique thresholds from 0 through 3. Invalid, duplicate, oversized, or partly valid input is rejected as a whole.

A valid custom rubric and its version tag are now preserved in local browser storage and workspace JSON exports, so reopening the same local workspace does not silently restore the built-in profile. Keep the exact JSON with your backup. The district portal intentionally ignores custom-rubric input until server validation, version custody, and licensing review are available.

Changing a rubric mid-cycle. The four stable domain ids keep ratings attached to their slots, while labels and components can change. A finalized overall score remains frozen. Detailed historical interpretation still depends on the exact rubric version, so export a backup before switching and retain every approved rubric JSON under district procedure.

18. Evidence Checks and the Optional AI Second Read

When you assign ratings, the tool compares them against the evidence you tagged and reports what it finds: a domain rated with no evidence tagged to it, a rating below proficient resting on a single piece, domains with no evidence at all, and how your total compares with what the plan expects. Portland's guidebook, for instance, looks for at least nine pieces across a cycle.

This is counting, not judgment. It runs on the device, needs no AI, and never leaves. Favourable ratings are not questioned for thin evidence, and unrated domains are left alone. The point is narrow and practical: a rating that rests on little documented evidence is the one most likely to be overturned, so it is worth seeing before the record is finalised rather than afterwards.

The optional AI second read. Off by default. A district that permits it can enable AI reflection under Setup → Advanced workspace options. An evaluator can then ask a model whether the evidence they wrote supports the ratings they assigned, and what other readings that same evidence allows, including ones favourable to the educator. The educator's About tab is read-only and does not expose these evaluator controls.

Three boundaries apply and they are deliberate. The model is asked about the documentation, never about the educator, and is explicitly instructed not to assign, suggest or imply a rating. Its answer is advisory: it is shown to the evaluator and is never written into the record, so nothing a model produces becomes part of a personnel file. And enabling it does send that educator's evidence notes and ratings to your configured AI provider, which is why it is opt-in, per workspace, and why the educator's name is not included in what is sent. If your district or contract does not permit AI in evaluation, leave it off and everything else works unchanged.

19. Sharing Through Your Own Drive (Optional)

This is the middle path: a validated one-educator packet is filed in one principal's district Drive and shared through one reviewed Drive permission. It has no roster, assignment model, shared live editing, or district-wide repository. Obtain approval for Apps Script, personnel records in Drive, retention, and account handoff first.

Principal-managed Drive share helper setup card showing zero of seven stages complete, the next-step prompt, the personnel-record boundary warning, approval and project checkboxes, and the Copy Code.gs source control.
The principal-helper checklist is resumable. Source stages complete only after the expected file is fetched and copied, from the clipboard or from the fallback source box.

The same seven setup stages shown in the app

Open Setup, choose Principal-managed Drive, and follow the resumable checklist. A copy control marks a source stage only after it fetches the expected file signature and the copy succeeds. Some windows block the clipboard (Gemini Canvas does); the control then shows the verified source pre-selected so you can press Ctrl+C (Cmd+C on Mac), and copying from that box, or choosing I pasted it, marks the stage.

  1. Confirm approval and account. Verify the intended district-managed Google account and district authorization.
  2. Create the private project. Open script.new, verify the account again, and name the project AlloFlow evaluation share helper.
  3. Replace Code.gs. Use Copy Code.gs or open the published source; select all starter code, paste, and save.
  4. Add the Index page. Choose + → HTML, name it exactly Index, then use Copy Index.html or open its source.
  5. Enable Drive API v3. In Project Settings, show appsscript.json, then use its copy control or open the manifest source.
  6. Deploy privately and save the link. Choose Deploy → New deployment → Web app, set Execute as: Me and Who has access: Only myself, review the account and scopes, then paste the URL ending in /exec into Setup. Preview /dev links are rejected.
  7. Run the deployment check. Open that exact saved URL and select Run deployment check. It must show helper version 3, the expected managed email/domain, and Drive API v3. Changing the URL or copying updated source clears the recorded confirmation.

Storage is checked before sharing. The helper verifies the managed folder path and its private, owner-only access before writing evaluation content. Duplicate matching folders, unexpected recipients, or incomplete permission information block verified sharing. A successful share checks the entire file permission list, including the intended recipient, role, and any expiry. Ask the deployment owner to resolve unexpected access rather than creating a workaround folder.

Share and revoke one packet

  1. In Evaluation Reports & audit, export and locally preview one Educator packet (.html).
  2. Open the private helper and run its deployment check before selecting a personnel file.
  3. Choose the HTML packet. The helper rejects arbitrary HTML and response packets, requires exactly one educator, and auto-fills educator/year metadata. A names-limited packet can still contain identifying free text.
  4. Enter and retype the educator's exact district email. The domain is locked to the verified account. Leave Viewer selected unless district procedure specifically needs Drive comments; those comments do not import into Evaluation. Choose an optional end date only after confirming tenant support.
  5. Confirm policy and choose Review; do not share yet. Inspect packet id and issue time, educator, folder, exact recipient, role, access end, and notification. Editing any field invalidates this snapshot.
  6. Choose Confirm and share this packet. A success message means Drive was re-read and the exact recipient, role, and expiration were proved. Google Drive is asked to email the recipient. Tell the educator to download the shared .html file and open it in a browser; Drive preview shows markup.
  7. Use Filed packets and live access status to re-read current permissions. Choose Revoke this live access for an active row. Success appears only after Drive proves no non-owner permissions remain. If an error names a recovery file, open that exact Drive link immediately and remove access manually.

Updates: replace all three source files, save, then choose Deploy → Manage deployments → Edit → New version. Reopen the same /exec link and run the check again. Editing source without creating a new version does not update the deployed helper.

Custody boundary. The AlloFlow Evaluations folder is a principal-owned working store, not automatic records management. Move or copy the year folder into the district's authorized system at the required handoff point, document that handoff, and transfer project/folder ownership before the principal account changes.

20. Glossary

Walkthrough
A short, frequent, low-stakes classroom visit that captures evidence. It does not score a rubric.
Formal observation
The full ten-step cycle with prework, conferences, evidence, reflection, ratings, acknowledgment, and finalization.
Observation and Practice (O&P)
The classroom-practice portion of a final evaluation, as distinct from data-based measures.
SPM
Student Performance Measure. A district-selected measure that contributes a defined share of the final evaluation.
SLO
Student Learning Objective. A goal set for a group of students, used where the framework calls for it.
PEPG
Performance Evaluation and Professional Growth, the Maine term for a district's educator evaluation system.
Framework snapshot
The tag stamped on every record identifying the framework and weights used when it was created, which is what keeps historical scores stable.
Band
The label a score falls into, such as Proficient. In this tool a band is triage for planning, not a verdict about a person.
Released summary
The final strengths-first document shared with the educator, opening with their own statement.
Acknowledgment
A record that the educator has seen a document. It does not signal agreement.
Cohort suppression
Withholding peer comparisons until enough peers contribute, so no individual can be identified from an aggregate.

21. Troubleshooting