Exam Manager for university examinations offices

The exam cycle, end to end

StudyDrome Exam Manager runs the exam cycle an examinations office owns: schedule the window, resolve the roster, issue access codes, invigilate the sitting, then release results in stages. Codes live at test level and survive republishing. Results visibility changes on a live exam, across many tests at once, with no republish.

What does the exam cycle look like?

  1. 1
    Schedule. Attach the exam to a calendar event, or leave it available from publication.
  2. 2
    Resolve the roster. Compose the audience from five sources, minus per-test exclusions.
  3. 3
    Issue access codes. Unique per candidate, shared, or none. Export them for distribution.
  4. 4
    Deliver. Access codes, IP restriction and device binding gate who starts, from where, on what.
  5. 5
    Invigilate. Watch progress, time remaining and violations on the Monitor dashboard.
  6. 6
    Mark. Auto-marking runs on submit; free text goes to a grading queue with blind marking.
  7. 7
    Release. Open results one level at a time, on your timetable.

How does the roster get built?

Five sources compose into one audience: a whole course, named student groups, named course groups, course-group clusters, and individually picked students. They union together.

  • Exclusions come off the top: An excluded candidate stays in their group. They simply have no access to this one exam, with an optional reason recorded against the exclusion.
  • Resolved at publish: The roster you publish is the roster that sits the exam, and the resolved count travels with the publication as a record. A late addition to a group needs a republish.
  • Academic holds run on top: A hold carrying the exam-access restriction is checked at six enforcement points, before any code, IP or availability check. The check fails closed — if the lookup itself fails, the candidate is stopped rather than let through.
  • Blocked exams say so up front: A blocked exam renders in the candidate's list with the reason inline and the start button already disabled, so nobody discovers the problem by clicking.
  • Releases stay on the record: Releasing a hold stamps who released it, when and why. The row stays for audit rather than disappearing.

How are access codes issued and distributed?

Three modes: no code, one shared code, or a unique code per candidate.

Codes are ten numeric characters with a hyphen at position five — 12345-67890. Generation retries on collision up to 100 times and raises rather than reusing a code.

The detail that matters to an exam office: codes live at test level, not at publication level. They persist across every republish, deliberately, so correcting an exam never forces you to redistribute codes to a cohort.

Format

Use

Spreadsheet

Bulk handling, mail merge

PDF table

One printed sheet for the invigilator

PDF, one candidate per page

Slips to hand out at the door

Two timestamps track staleness: when the codes last changed, and when they were last exported. Roster changes, regeneration and switching to unique-per-candidate all mark the codes changed. So you can see at a glance whether the batch you printed is still current.

What can an invigilator see during the sitting?

The Monitor workspace has four tabs: Dashboard, Students, Tests and Messages. It refreshes every 30 seconds, 1 minute or 5 minutes. It pauses while the browser tab is hidden, so it never polls in the background.

Column

What it tells you

Student Name

Who

Test Name

Which paper

Progress

Questions answered of total

Time Remaining

Amber at 10 minutes, red at 5

Violations

Count, with the type and time of the last one

IP Address

Where they are connecting from

Status

Not started, in progress, submitted, graded

Session data sits alongside: session count, start time, device fingerprint. A session count above one means the candidate dropped and came back, which is the signal an invigilator acts on.

Filter to "Has Violations" to triage a large sitting. Sort by started time, violations, progress or name. Page sizes run from 5 to 500.

What can an invigilator do mid-exam?

Four actions, on one candidate, several at once, or every active candidate on the test.

  • Message a candidate: Up to 2000 characters with up to 10 attachments. Every message is kept in a searchable history with its delivery status, so you can show exactly what a candidate was told and when.
  • Adjust time: Up to 120 minutes in either direction. The change reaches the candidate immediately as a push, and the server then enforces the attempt's adjusted limit. This is the mechanism for a late start, a technical fault, or an access arrangement applied on the day.
  • Reset a device fingerprint: A candidate whose laptop dies resumes on a replacement without anyone touching the database.
  • Finish an attempt: Submits and grades it, with the candidate notified. The result records that it was finished by an administrator.

How do you release results?

This is the part an exam office cares about most, and it is where Exam Manager is unusual: results visibility is one of six settings that stay editable on a live exam. No republish, and it can be applied across many tests at once from the Grading & Results drawer.

Level

What a candidate sees

Hidden

"Results are not available."

Summary Only

Pass/fail, overall score, percentage, grade level, time spent

Question Details

Summary plus per-question correct/incorrect, points, question text, their own answers

Full Review

Question Details plus correct answers and all options with correctness indicators

That maps onto a real release timetable. Publish with results hidden. Open Summary once marking closes and the board has signed off. Open Question Details for the appeals window. Open Full Review only if and when item security allows — the answer key is gated on that final level alone.

Two settings work together here. The post-completion mode is fixed in the published snapshot and decides whether candidates see results at all. The visibility level is live and decides how much. Changes take effect immediately.

Outbound sends close the loop. Instructions go out before the sitting. Personalised feedback goes out after it, composed from a template with variable substitution. Batches run to 1000 recipients. The send log keeps the exact rendered content per recipient. An appeal is answered with the message the candidate actually received, not a reconstruction.

What does the calendar hold?

The calendar is the record of the exam period. An event carries the window and a room, drawn from the buildings list or typed free. It also carries assigned proctors, one marked primary, and a visibility audience.

Attach a test to an event and the event becomes the exam window: the exam is available inside an occurrence and unavailable outside it. That is also what enables the start-window rule. It closes entry a set number of minutes after the scheduled start. Useful when you want candidates in the room on time.

Events are cancelled, reactivated and completed through explicit status actions rather than deletion. So a cancelled sitting stays on the record, with its reason and its notes. For an exam office that has to account for a sitting afterwards, that audit trail is the point.

Recurrence covers daily, weekly, every two weeks and monthly, including patterns like "the second Monday". A cancelled or rescheduled occurrence is stored as its own record, with a reason. OSCE events are projected onto the calendar automatically when the exam publishes, and republishing updates them rather than duplicating them.

Who is this for?

An examinations office running scheduled sittings for a cohort. The same team owns scheduling, candidate eligibility, invigilation and the results timetable.

Permissions are built for that split. Monitoring sits behind tests:proctor, and 14 of the 15 monitoring endpoints use it; violation data sits behind its own permission. So an exam office can hold invigilation rights without authoring rights. A psychometrician can read violation data without being able to finish someone's attempt. Tenant isolation is enforced at the data layer, independently of how roles are configured.

Frequently asked questions

Do access codes have to be reissued when an exam is republished?

No reissue is needed. Access codes are stored against the test rather than against a publication, deliberately, so they persist across every republish. Correcting a question and republishing leaves the codes your candidates already hold valid. Two timestamps record when codes last changed and when they were last exported. Use them to confirm a printed batch is current.

Can we change what candidates see in their results after the exam?

Yes. Result visibility is one of six settings that live on the exam, not in the published snapshot. It changes immediately, with no republish, and you can apply it across many exams at once. The four levels run Hidden, Summary Only, Question Details, Full Review. Only Full Review reveals the answer key.

How do we stop a specific student from sitting an exam?

Two mechanisms, depending on scope. A per-test exclusion removes one candidate from one exam while leaving them in their group. An academic hold carrying the exam-access restriction blocks exam entry more broadly. It is checked at six enforcement points, before any other check. The candidate sees the reason inline, and releasing the hold records who released it and why.

What happens if a candidate needs extra time on the day?

A proctor grants it from the Monitor dashboard, up to 120 minutes either way. That works for one candidate or the whole sitting. The candidate is notified immediately, and the server enforces the adjusted limit rather than the originally published one. Every adjustment is kept in an audit trail.

Can we prove what a candidate was told during an exam?

Yes. Proctor messages are stored with their delivery status. They are searchable by exam, attempt, candidate and date range, and attachments stay retrievable. Post-exam feedback sends keep the exact rendered content per recipient. Between them, an appeal can be answered with the message the candidate actually received.

How does StudyDrome control where an exam can be taken from?

Three independent layers. Access codes decide who can start. An address allow-list decides where from, and accepts single addresses and ranges. It is enforced when a candidate prepares, starts and resumes, so moving off-campus mid-exam is caught on the next resume. Device binding ties an attempt to the browser it started on, with a proctor reset available when hardware fails.

Book a pilot