IT Setup Before Invitations
The email, Google sign-in and web filter settings your IT team may need before staff are invited.
Elevate invites your staff by email, and they can sign in with their district Google account. Some email filters and Google Workspace settings block one or both of these. Many districts don't need to change anything, so treat each step below as a check. Do it before your district finishes setup, because invitations can go out as soon as setup is submitted.
Download this checklist as a one-page PDF to send to your IT team.
1. Let our invitation emails through
If your district uses a mail filter such as Mimecast, Proofpoint, Barracuda, Microsoft 365 or Gmail, add our sender as a trusted or permitted sender. Allowing the address or the whole domain is enough.
- From: Elevate by Tandem,
noreply@tandem-education.com - Domain:
tandem-education.com - Subject: You're invited to join Elevate, and later "Reminder: Your Elevate invite expires soon"
- Sent through: MailerSend. SPF
include:_spf.mailersend.net, IPs212.11.79.0/24 - DKIM:
mlsend2._domainkey.tandem-education.com
2. Trust Elevate for Google sign-in
This step is only for districts on Google Workspace. Elevate asks Google for name, email and profile picture only (openid, email, profile). It has no access to Drive, Gmail or Classroom. Trust it for your staff organizational unit; students never use Elevate. Trusted lets an app request any scope, but Elevate only ever asks for these three.
- In the Google Admin console, go to Security > Access and data control > API controls.
- Choose Manage Third-Party App Access, then Add app > OAuth App Name or Client ID.
- Search for this client ID:
525075765238-018igj845fc8lsfpbmoilikac0crln43.apps.googleusercontent.com - Choose your staff organizational unit and set access to Trusted.
3. Allow the app and the microphone
Elevate runs in the browser and transcribes live while an evaluator observes. If your web filter restricts traffic, allow:
elevate.tandem-education.comfor the app and sign-instt-proxy-525075765238.us-central1.run.appfor live transcription (a secure WebSocket)*.googleapis.comandaccounts.google.comfor data and Google sign-inus-central1-project-elevate1.cloudfunctions.netfor invitations and reports- Pop-ups from
elevate.tandem-education.com, because Google sign-in opens one - The microphone for
elevate.tandem-education.com. On managed Chromebooks, add it to theAudioCaptureAllowedUrlspolicy.
If someone still can't find their invitation
- Check junk and quarantine for "Elevate by Tandem". If the email reached your mail server, sending it again lands in the same place, so release it from quarantine.
- Use the newest email. Each new invitation replaces the last one, and older links stop working. Invitations last 30 days.
- Request a fresh link at elevate.tandem-education.com/resend-invite with the address you were invited with.
- Once step 2 is done, invited staff can skip the email and choose Sign in with Google on the login page.
See Managing pending invites for resending invitations from inside Elevate.
Need more help? Contact support.