Institutional-scale integrity and security
Connected to your LMS.
Private to the level you choose.
Connect MATCHA to your LMS through LTI to authenticate students and submit grades from the grading tool. Choose each course’s privacy level, up to end-to-end encryption that keeps student identities and work unreadable to MATCHA. Assign staff roles and share approved browser and ID configurations across your organization.
Explore the features
In practice
Set the framework. Let instructors teach.
An LMS administrator configures MATCHA as an LTI tool, and organization administrators share approved Browser Configs, Staff Lists, and ID Configs. Instructors then build activities within that framework, reusing the organization’s approved settings.
-
Connect the learning systems
Once MATCHA is configured as an LTI tool, it authenticates students through the LMS and submits grades from its built-in grading interface.
-
Choose the data boundaries
Pick each course’s privacy level, from Standard to Zero Trust. From Level 2, student names, IDs, and emails are encrypted end to end with a course key MATCHA cannot recover; Level 3 extends this to student work. Privacy Levels 2–4 are not yet supported for LMS-managed courses, which use Standard privacy for now.
-
Make consistent practice easier
Assign administrator, instructor, grader, student, and proctor roles, and set each activity’s conditions for access, copy-paste, AI assistance, and browsing. Administrators and instructors must use multi-factor authentication.
In detail
How each feature works.
What each feature does, its options, and what it requires.
LTI Integration (Enterprise feature)
- MATCHA can use LTI to authenticate students and enable grade submission from its built-in grading interface.
- To enable this feature, LMS administrators need to configure MATCHA as an LTI tool.
Privacy Levels and End-to-End Encryption
- Course privacy levels let institutions choose how much student information MATCHA services can process, from standard managed workflows to zero-trust activity design.
- Privacy Level 1, Standard: MATCHA can process student identity, activity data, and work histories when enabled features require it, with an activity-specific disclosure before students begin.
- Privacy Level 2, No PII sharing: student names, IDs, and emails are encrypted end to end between MATCHA Writer and authorized course staff. MATCHA receives only placeholder identity fields and allowed anonymous control data.
- Privacy Level 3, No student information sharing: extends end-to-end encryption to protected student work products, work histories, and submissions, so MATCHA cannot read student work.
- Privacy Level 4, Zero Trust: adds course-pack-only browsing to Level 3, so students do not need to trust MATCHA Writer or MATCHA services with ordinary web-browsing credentials or confidential browsing activity.
- Privacy Levels 2 and above use a course passphrase/private key model that MATCHA cannot recover, giving instructors protected access while keeping encrypted course data unreadable outside the institution.
- For more information, see the Data Protection and Privacy page.
Fine-grained Security and Usage Controls
- Assign organization roles for administrators, instructors, graders, students, and proctors, giving each person access suited to their responsibilities.
- Set activity-specific conditions for access, copy-paste, AI assistance, browsing, and supervised writing.
- Share Browser Configs, Staff Lists, and ID Configs within an organization so instructors can reuse approved settings.
- Set a minimum privacy level for newly created courses. Existing courses retain their current level; enforcing protected levels requires an activated organization recovery code.
- Organization security settings require multi-factor authentication for administrators and instructors. Enterprise customers can also restrict cloud submission destinations.
Enterprise-Ready Activity Management
- MATCHA activities are part of courses, which are parts of organizations.
- An organization can have multiple administrators, instructors, and other members.
- Much of MATCHA's behavior can be controlled through activity settings and configuration objects such as Browser Configs, Staff Lists, and ID Configs, which can be standardized within an organization and shared between instructors.
