Third Party Application integration with Bromcom

When looking to integrate a third party application, it’s best to liaise with the third party for more detailed instructions. The purpose of this guide is to explain how a new User Account can be created to give Third Party Supplier’s access to data in your MIS system through Bromcom’s API interface, which is required for all third party applications to function. This includes the following;

  • How to Add a New User Account with Third Party Permissions
  • Set up Write Back Permissions
  • Checking Data Processing Consent

URLs

The standard URL for Read Only access is below.

  • https://cloudmis.bromcom.com/Nucleus/WebServices/ThirdParty/TPReadonlyDataService.asmx

The standard URL for Write access is below.

  • https://cloudmis.bromcom.com/Nucleus/WebServices/ThirdParty/TPWriteDataService.asmx

How to Add a New User Account with Third Party Permissions

Log in to Bromcom with a User Account that has access to the Setup module. Typically a school administrator account.

Go to Modules>Setup>System Users.

 

Click on New to create a new User Account.

 

Select the Create a New User radio button and fill in the First NameLast NameUsername and Password fields.

You should also ensure that the Third Party tick box is checked under Roles.

 

Press the Save button to create the new User Account and confirm that the message User Details Saved is received in top right of screen.

 

Go to Modules>Setup>Third Party Access Permissions & Logs page to maintain Third Party Accounts access Read Only Permissions for the APIs.

By default, none of the APIs will be enabled for access to newly created Third Party Accounts.

Select the Third Party Supplier’s account in the dropdown to see and manage Permissions to the API entities for that User Account.

Note: The Third Party Supplier should provide you with a list of the API entities they need to access, you will need to enable the specific permissions that they outline. They will be able to provide further assistance regarding this should it be required.

On the same page, you can also view the access logs of this Supplier’s account. Logs are kept for 3 months.

If the Third Party Application is not going to be performing Write Back to the system, please skip to Checking Data Processing Consent.

Set up Write Back permissions

To set up Write Back permissions; we recommend to create a custom Role which only has write-back enabled, please Note that there is already a role for Attendance write-back).

Within the Roles & Permissions page (Config>Setup>Roles and Permissions), create a new Role.

This will take you to the following screen.

After clicking the New button, the Write Back permissions can be found by selecting the Setup module and expanding out the tree to System Security>Security Settings>Third Party Write Back – xxxxxx.

The Third Party should be able to tell you which APIs they are calling to write-back.

Once the new role has been given a name, description and the appropriate Write Back permissions have been assigned, click Save.

Once this role is saved – the School can assign it to specific users on the System Users page.

At this stage; Third parties should be able to access the APIs; however they may not have access to read all the student or staff records.

This is due to GDPR related settings (Data Processing Consent), these are set either at a School level; or at a Student/Staff level.

To set at an overall School level, browse to the Config>Administration>Administrative Defaults.

Within Config>Administration>Administration Defaults, there is a drop down box for Lawful basis for data processing with multiple options.

If you pick any option except Consent, then automatically ALL Students and ALL Staff will become accessible via the APIs.

If you pick any option except Consent and click Save; then you have completed the setup.

If you pick the option Consent, then you will need to set the Consent for Data Processing at a Student/Staff level.

The Student/Staff Modules can be accessed via the side Menu as normal.

From the Student page you can select some Students, press Actions and select Quick Edit.

A popup box should appear, allowing you to pick the attribute Data Processing Consent Granted, and select a value of True/False.

At this point you can click the Update button to set the values as needed. (Review will allow you to review the changes before updating them).

When set to True: the selected Students will have their data accessible by Third Parties.

When set to False: the selected Students will NOT have their data accessible by Third Parties.

Reminder: This is only needs to be set when the Lawful Basis for Data process field is set to Consent and applies to ALL third parties.

The same option can be picked for Staff as well, under the Actions>Quick Edit.

The Data Processing Consent granted field can also be set on a person by person basis within the Key Data panel of the Student Record, or the Personal Details panel of the Staff Record.

Student Page
Staff Page

Troubleshooting
401 Unauthorised: If the third party provider is encountering this error, this will either be due to the permissions on the account provided to them or the username / password combination is incorrect. Therefore please ensure all permissions have been assigned to the account as per the their instructions. If the permissions are correct for the third party account, please navigate to Modules -> Setup -> System Users. Select the account and reset the password.

Please click here for a full list of Bromcom Trusted Partners | Bromcom School MIS
Updated on 5th June 2026

How useful was this article?

Click on a star to rate it!

Average rating / 5. Vote count:

No votes so far! Be the first to rate this post.

Similar Posts

  • Bromcom: Unable to change staff absence end times

    Staff List Page>Choose Staff>Actions>Add Absence (and creating absence via Staff Profile page) How to Record Staff Absence – Bromcom – Documentation Centre You may find, when entering a Staff Absence, whether you select specific time (eg half day, 3/4 day) the time changes to a default time. In order to rectify this, you need to…

  • Bromcom: Bulk Update Class Memberships

    To bulk update class memberships go to Modules > Curriculum > Bulk Group Assignment The drop-down menu allows you to choose Class, Tutor Group, Band and Block In this example I am setting the Art students in Year 8 Next to the Group Name click the Magnifying glass and choose the required classes. Click Done….

  • How to raise and vote for ideas within Bromcom

    Schools can raise and vote on Bromcom Development Ideas by accessing the Portal through the MIS. As they don’t have their own Support Portal account, they can instead request a passcode to raise an idea by clicking on Help & Resources next to their profile photo, then click Development Ideas. The passcode will be sent…

  • Bromcom: Taking PM marks in different periods

    Question: Is it possible to have the PM mark taken at different periods through the week? I.E. P5 the majority of the week but P4 on a Wednesday Answer: This can be setup within Config > Attendance > Registration Update Parameters. If you wanted a different period for each day this would have to be…

  • Bromcom: Blank screen in MCAS

    Issue: A parent is logging into MCAS but is being greeted with a blank screen. Resolution: This is likely to be caused by the contact having 2 records within Bromcom. Go to Others > Contact and search for the contacts name Double click on one of the duplicated contact records and remove the student from…

  • Bromcom: How to create a Phonics CTF for Year 1 and Year 2

    Please check with your LA for CTF requirements. If you are a Devon school- Upload to Devon Transfer (Please note: For Devon this is a combined CTF with all Year 1’s and Year 2 retake pupils in ONE CTF. ONLY INCLUDE YEAR 2’S WHO HAVE RETAKEN PHONICS THIS YEAR) To create a CTF that includes…