One tool, two doors: faculty grade, learners read.
Campuses and cohorts. The Grader keeps Pomona and Lebanon apart. Each campus has its own faculty password, its own cohorts, cases, and rubrics, and its own roster, and a learner chooses their campus before entering a PIN. Inside a campus, cohorts group the work by class year: name a cohort on Cases and rubrics, DO 2029 say, add its cases under it, and the Roster, Class analysis, PIN roster, and release then work one cohort at a time. Every grader on the class link sees the same cohorts and cases. Each campus starts with a temporary password; the desk asks you to set a new one the first time you sign in on a computer, and the Admin panel changes it later. A password set on one computer reaches the other graders through the class link, so a campus has one password, not one per desk.
Cases and rubrics. Add each SP case with a short context, then attach its rubric by dropping a Word, PDF, or PowerPoint file or pasting text. If the rubric is a checklist, the kind where each line ends in a point value in parentheses like Chief Complaint (1), the Grader pulls out the individual items and shows you exactly what it will score. Conditions written into an item, such as must include all 4 for credit, are carried through and enforced. A rubric read this way is graded item by item, so every student on that case gets the same numbered list in the same order, which is what makes the class comparable.
One class export. The usual way in. Drop the single Word file your SP system exports for the whole cohort, the one that repeats Individual Checklist and Student: for each learner. The Grader splits it here in the browser into one note per student, keeps each S, O, and A & P as written, and reads the vitals into the vitals strip. This step makes no AI call at all, so it is instant and free, and a class of two hundred comes in as fast as a class of five. Students marked No Data are listed and skipped, and anyone already on the case is skipped so nobody ends up with two PINs.
Separate files. The second mode, for a make-up note or a single remediation. One student per file, Word or PDF, up to thirty at a time. Claude reads each file, lays it out in the SOAP template keeping the student's own words rather than improving them, and pulls the name off the header or the file name if either states it clearly. Because a file uploaded this way is usually named after the student, the Roster shows it as Individual upload while blinding is on rather than showing the file name.
Grading in blocks. A cohort of 226 is not something anyone reads in one sitting, and grading the whole class before looking at any of it means a bad run is only discovered at the end. So the Roster works a block at a time, 30 by default, with 10, 20, 50, and all as the other choices. Press Grade next and Claude works down the checklist for those notes, three at a time, awarding or withholding each point with a short line of evidence, then writing strengths, growth areas, and a narrative that names what was actually missed. Stop after current note halts the run cleanly, and anything the run never reached goes back on the shelf for the next block rather than being counted in this one.
Reading the block. When the run finishes, a banner sits at the top of the Roster with the count of what you have read and what is left. Review the next one walks you through them in roster order, and each note you open can be marked reviewed. Mark all reviewed is there for a block you have spot-checked and are happy with. Ask for the next block while notes in this one are still unread and the Grader stops to say so. It is a stop, not a lock: you can go ahead, but you have to say so on purpose.
Adjust and release. Nothing reaches a learner until you flip whatever points you disagree with, edit the evidence, add your own comment, and release. Release graded acts on whatever the Roster is currently showing, one block or the whole case, and asks you to confirm that you reviewed these evaluations, or spot-checked enough of them to approve the batch. A released note can be pulled back to held at any time from its review page. What the learner receives is the joint evaluation: AI drafted, faculty approved.
Asking Claude about a score. The gold star at the top of the credit column opens Claude beside the note you are reviewing. When the AI could not score an item, the star carries a red count and those items are marked Not scored by the AI, each with its own small star. Ask why an item could not be scored, tell Claude in your own words how it should be scored, or ask it to score the blank items. Claude answers and lists the changes it proposes, with the evidence from the student's note. Nothing on the note changes until you press Apply, and Undo puts it back. When your reasoning should hold for every student on the case, such as how family history generations are counted, Claude can offer it as a scoring rule. A rule you save is listed on the Cases and rubrics tab, travels to the other graders, and is used for every note graded on that case from then on.
Class analysis. Once a batch is graded, Class analysis on the Roster shows the share of the class that earned full credit on each checklist item, worst first, for whatever is currently in view. Two CSVs come out of it. Score matrix is one row per learner and one column per checklist item, carrying the name, the code, the PIN, the points, and the percent, which is what you move into your own system. Item summary is one row per checklist item for the cohort, which is what tells you where to teach differently next time. Like the roster download, the score matrix follows the Admin switch for whether names travel.
PINs, and what a learner opens. A PIN belongs to a learner, not to a note. It is seven characters drawn from an alphabet with no 0, 1, I, L, O or U, so a code read aloud or copied off a printed roster cannot turn into a different one, and letters are not case sensitive when a learner types it. Every note that learner submits carries the same code, this case and the next, so their PIN opens everything you have released to them: one note goes straight to the feedback, and several open as a list with the score on each, plus Download all as PDF for the lot in one file. Feedback appears only after you release it; until then the door says the note is in but not released yet, so a learner who typed the right PIN is not left wondering whether they typed it wrong. A learner device only ever asks the class link for what matches the PIN it was given, never for the class. If the companion Worker has not been updated for the portfolio yet, a learner sees their most recent released note and a line saying the rest are on their way.
The PIN roster. PIN roster on the Roster is one row per learner for whatever is currently in view: their code, their cohort, how many notes they have, how many of those are open to them, and the PIN itself. The three buttons under it, Copy as text, Download CSV, and Print, are how the list leaves the app, sorted so it lines up with your own class list. If a learner loses their PIN, or it gets passed around, find them in the Admin panel and press Issue a new PIN: every note of theirs moves to the new code at once and the old one stops opening anything. Hand out a fresh roster after that, and after any sync that tells you PINs were reissued.
Scores into your LMS. Gradebook export on the Roster is the file course staff move into the gradebook. Pick a cohort, pick a layout, and download. One row per learner with a points and a percent column for every case, plus totals, is the shape most gradebook imports want; one row per learner per case, carrying status and the release date, is there for a system that takes one column of scores at a time. Names and student IDs are in the file, since that is what an import matches on, unless the Admin switch for names in downloads is off, and the dialog tells you which one you are about to get. A learner with no grade yet on a case is left blank rather than counted as a zero.
Blinded grading. Every learner is given a permanent seven digit code when their note comes in, and the same person keeps the same code across cases. With blinding on, which is how the Grader now starts, the roster, the note review page, the PIN roster window, the grading progress, and anything you print from a note all show that code and not the name, so whoever grades is reading the work rather than the person. Three smaller things go with it: the Roster search stops matching on names, since a search box that finds a row by name would hand the name straight back; the list is ordered by code rather than alphabetically, because name order is readable to anyone holding a class list; and Original file is greyed out, because the submission as it arrived carries the name in its header and its file name. The downloads put the name back next to the code, which is how you hand each learner their PIN and move grades into your own system.
What blinding does and does not do. The campus password opens the desk, so anyone who can grade on that campus can also pull the identified CSV. Blinding keeps the name out of view while the score is being decided, which is the thing that protects against grading the person instead of the note. It is not a wall against someone who already has the faculty password. If you need a blinded roster for a co-grader, turn off Put names back in downloads in the Admin panel and every download comes out carrying codes alone.
Admin panel. Press Shift plus Command or Control plus A anywhere in the faculty desk, or use the Admin button on the Overview tab. Either way it asks for the current faculty password first, every time, even when the desk is already unlocked. From there you can change this campus's faculty password, turn blinding on or off, decide whether downloads carry names, look up one learner's code and PIN without unblinding the whole roster, issue that learner a new PIN, and save or forget the publishing key on this device. A password you set here does not stay on this computer: it travels with the class link, so the campus keeps one password rather than one per desk. Chrome and Edge claim that key combination for their own tab search and a web page cannot take a browser shortcut back, so if nothing happens when you press it, use the Admin button.
Several graders, one class. Every faculty grader who opens the hosted Grader and enters the FACULTY_SECRET once is working on the same class. Publish to class reads what the other graders have already published, merges your work into it note by note, and writes the merged class back, so nobody's grading is ever replaced by an older or emptier copy. If two graders changed the same note, the most recent change is kept, and the Grader says when that happened. With Keep graders in sync automatically on, which is how it starts, the desk also brings the others' work in every minute or so and sends yours shortly after you stop editing, so Publish is only needed when you want to be sure or when you are releasing. Pull latest brings the others' work in on demand. Before a block is graded the desk checks the class link and marks those notes as taken, so two graders never spend AI time on the same notes; a note being graded on another desk says so on the Roster. Each grader's name, set once per computer, is shown to the other graders beside the work they published, and it never reaches a learner. The campus password travels the same way: change it on one computer and the others pick it up at their next sync. Only the one-way hash of it travels, never the words, and reading the class record needs the FACULTY_SECRET in the first place. If two publishes ever collide and leave the class unreadable, the desk that collided rewrites it from its own copy, and the Publish dialog offers Rewrite from this desk if it happens while you are watching.
Releasing to learners. A learner sees a note only after it is released and the release has reached the class link. There are three ways to release: tick Also release finished notes in the Publish dialog, which releases either the notes marked reviewed or every graded note still held, for one case or all of them; use Release graded on the Roster for whatever is in view; or release one note from its review page. Each of these goes to the class link straight away when the desk is connected, so a learner on their own phone can open the note with their PIN within moments. Return to held pulls a note back the same way. Because one PIN covers a learner, releasing a second case adds to the list they already open rather than replacing it.
Data, sharing, and hosting. Everything lives in this browser and on the class link. Export a backup on the Overview writes the whole desk to a JSON file and carries this computer's campus passwords and your blinding settings with it, so a restore brings the desk back exactly as you left it. The class link copy carries each campus password as a one-way hash, which is how a password set on one computer becomes the password for the campus; the words themselves never travel, and the class record cannot be read without the FACULTY_SECRET. That copy is split across several database rows when a fully graded cohort runs past the 2 MB a single row holds. Learners never read the class record; their device asks for one released note by PIN. Grading runs through Claude directly when this page is opened inside Claude; hosted, it runs through the companion Worker whose address sits on the WORKER_BASE line near the top of the script.