LMS Integration - DetectedX
DetectedX ยท Integration guide for institutions

Four ways to put DetectedX in front of your learners

From a single link a lecturer can paste into an existing course, through to a full standards-based integration that signs learners in and writes their reader performance back into your gradebook. All four deliver the same teaching content. They differ in how much your IT team is involved โ€” and in how much comes back to you automatically.

Audience ยท Education leads, LMS administrators, IT Applies to ยท Any LMS, portal or intranet Version ยท September 2026
At a glance

Choose by how much you want back, not by how technical you are

Every option below uses the same library and the same viewer. The practical question is whether results need to arrive in your own systems automatically, and whether your learners should be signed in without a password.

  A ยท Module links B ยท Launch links C ยท Partner API D ยท LTI 1.3
In one line A link per module, pasted anywhere Your own LMS launches them, signed in Your platform creates users and requests links Your LMS and DetectedX talk directly
Work for your IT None None Development on your side One admin registration
Learner signs in Free DetectedX account, once No password โ€” the link signs them in No password โ€” the link signs them in No password โ€” your LMS vouches for them
Lands on the exact module Yes Yes Yes Yes
Runs inside your course page Opens in a tab Opens in a tab Opens in a tab Embedded, or a tab
Results in your gradebook No โ€” results stay in DetectedX Cohort report from us Cohort report or export Automatic, per measure
Joiners and leavers Not tracked You tell us Handled by your platform Handled by enrolment
Typical time to first learner Same day Within a week Weeks โ€” your development Weeks โ€” scheduling and your review
Best for A few modules, informal use A defined cohort, no IT time Your own portal, or an LMS without LTI Programme delivery at scale
Decision guide

Four questions, and you have your answer

Does your LMS support LTI 1.3 โ€” Blackboard, Canvas, D2L, Moodle, Open LMS, Totara and most others?
โ†’ Option D
No LTI, but you have a portal or LMS with a development team who can call an API?
โ†’ Option C
You want a named cohort to start quickly, with no password and no IT involvement?
โ†’ Option B
You simply want a few modules available to whoever follows the link?
โ†’ Option A
Note

These are not exclusive, and you can move between them. A single course can start on Option A while a programme elsewhere runs on Option D, and you can change at any point as your needs change. Nothing you set up early is wasted: the content is the same, and learner accounts, history and CME carry across.

Option A
Module links
No integration Same day

Your lecturer chooses the modules they want. We issue a link for each one. They paste it into a course page, an email, a slide or an intranet โ€” anywhere a link can go. Learners click it and land on that module.

What the learner sees

The module opens in a new tab, on its own page, with its description, duration and CME value. First time only, they create a free DetectedX account; after that the link takes them straight in.

What you provide

  • The list of modules you want
  • Nothing else โ€” no lists, no IT, no accounts

What we provide

  • One link per module, ready to paste
  • Replacement links if content is updated
  • A cohort summary on request, where learners registered with your email domain

Where results live

In DetectedX. Each learner sees their own performance, case-by-case review and certificate, and can download or email their score report.

Choose this when

  • A lecturer wants to add imaging practice to an existing course this week
  • The group is small or informal
  • Nobody needs results in an institutional system

Know the limits

  • Nothing is written back to your LMS
  • We cannot tell you who completed what unless learners register with an identifiable institutional address
  • Anyone with the link can follow it
Option B
Personal launch links
No integration No password

The same idea as Option A, with identity added โ€” and with your own LMS acting as the launcher. You already sign your learners in; we simply give you a specific link rather than a plain one. Placed inside your course, it signs the learner in to DetectedX and opens the module. No password to remember, no account to create, and nothing for your IT team to build.

Why your existing sign-on is enough

1
Your LMS authenticates the learner โ€” with Microsoft 365, Entra, Shibboleth or whatever you use today. That is the front door, and it does not change.
2
The specific link sits behind that door. Only someone already signed in to your course can see it, so your access control decides who reaches DetectedX โ€” exactly as it decides who reaches your other materials.
3
One click, and they are in the module, signed in as themselves, with their history and CME accumulating on one record.
Specific, not simple

The difference between this and Option A is the link. A simple link is public: anyone who has it can follow it, and the learner signs in themselves. A specific link is issued by us for your cohort and is meant to live behind your login โ€” it carries both the identity and the entitlement, which is what removes the sign-in step. Ideal when a handful of modules are in play, and there is no ceiling: we issue as many as you want.

What the learner sees

One click from your LMS, email or portal, and they are reading the case. They are signed in as themselves, so their history, CME and certificates accumulate on one record.

What you provide

  • A cohort list: name, email or your own learner ID
  • Which modules the cohort should have
  • Updates when people join or leave

What we provide

  • The accounts, created in bulk from your list
  • A launch link per module, per learner or per programme โ€” as many as you need
  • Replacement or expiry of any link, on request
  • A cohort report: who started, who finished, how they read

Security

Links are personal and time-limited: they are for the named learner, not for posting on a public page. We can re-issue at any time, and expire any link on request.

Choose this when

  • You have a defined group โ€” a cohort, a department, a course intake
  • You want the experience of single sign-on without an integration project
  • Your IT team has no time to give you

Know the limits

  • Results come back as a report from us, not into your gradebook automatically
  • You maintain the cohort list and tell us when it changes
  • Distribution of the links is yours to manage
Option C
Partner API and user mapping
Your development Any platform

For institutions with their own portal, or an LMS that cannot speak LTI. Your platform calls our API to create learners, place them in the right group, and request a sign-in link at the moment a learner clicks through. Membership, entitlement and leavers are then driven by your system of record rather than a list you send us.

How it works in practice

1
A learner is created in your system. Your integration calls us straight away with their name, identifier and affiliation โ€” the hospital, site or department they belong to. The account exists before they ever click anything.
2
They are placed in the right groups. One group for the institution as a whole, and one for their specific site or programme, resolved through a mapping you own โ€” commonly a table of site codes to groups, which you can update without a release.
3
A link is minted at the moment of the click. Your platform asks for a sign-in link when it renders or follows a DetectedX link, rather than storing one. Links are single-use and short-lived, so nothing durable is ever held in a page, an email or a log.
4
Changes follow the learner. When somebody’s affiliation changes in your system, the same call updates their details and re-evaluates their group membership; when they leave, removing their membership withdraws access.

What the API does

  • Create a learner, keyed on your identifier
  • Create groups โ€” region, hospital, programme
  • Add and remove group members
  • Mint a single-use sign-in link, on demand
  • Update a learner’s details and re-evaluate their access
  • Sign a learner in even if they already have a session open

What you provide

  • Development effort on your side, or your LMS partner’s
  • A small component in your platform that swaps a content link for a fresh sign-in link at click time
  • A mapping from your structure โ€” regions, hospitals, programmes โ€” to DetectedX groups
  • A test environment for us to verify against

What we provide

  • API credentials for test and production
  • Endpoint documentation and worked examples
  • Groups pre-created to match your structure, in test and in production
  • Engineering support through your build and testing

A safeguard worth knowing

Sign-in links can only be minted for learners your integration created. One customer’s credentials can never reach another customer’s accounts, or an account somebody registered themselves.

Choose this when

  • Learning is delivered from your own portal rather than an off-the-shelf LMS
  • Your LMS has no LTI support but does have developers
  • Group and regional entitlement rules matter to you

Know the limits

  • It is a development project on your side, with the timeline that implies
  • Results are exported or reported rather than written into a gradebook, unless you also build that leg
  • Every new platform you adopt needs the client rebuilt โ€” which is the argument for Option D where it is available
Option D
LTI 1.3 Advantage
Recommended No plugin Grades return

The standards-based route, and the only one where results arrive in your gradebook without anybody doing anything. Your administrator registers DetectedX once as an external tool. From then on, every lecturer adds DetectedX modules the way they add any other activity, every learner arrives signed in, and every result comes back.

What your administrator does

Registers DetectedX on the external-tool screen of your LMS: three URLs and a key. No plugin is installed, no server access is needed, and there is no downtime. Your LMS then issues us an identifier, which we configure on our side.

What each lecturer does

Adds an activity, picks a module from our library inside their own course editor, and saves. Nothing is copied, and the module stays current.

What the learner sees

They click the activity and are reading the case โ€” signed in, inside the course page, with no password and no second website. Their account is created on their first click, entitled to the module their lecturer chose.

What comes back

One gradebook column per measure โ€” sensitivity, specificity, lesion sensitivity, ROC and JAFROC where the module produces them โ€” with the case counts in the feedback. Not a single mark: the reader-performance profile that imaging education is actually about.

Choose this when

  • Your LMS speaks LTI 1.3 โ€” most do
  • You are delivering a programme, not a one-off
  • Tutors need to see performance without asking learners for screenshots

What it removes

  • No second user list to maintain, and nothing to deprovision
  • No identity-provider integration: your existing sign-on already covers it
  • No licence codes to distribute โ€” enrolment is the entitlement
  • No exports, no retyping, no chasing
Identity and access

Your sign-on stays where it is

In options B, C and D the learner never types a DetectedX password, and we never see one. Your institution authenticates the person the way it already does โ€” Microsoft 365, Entra ID, Shibboleth, Okta or a local account โ€” and your system then hands them to us with a statement of who they are. This is the same mechanism that already signs learners in at our partner universities and industry customers.

To be precise about what that does and does not mean: DetectedX does not offer a “Sign in with Microsoft” button, and we do not federate directly with your identity provider. We do not need to. Your system has already established who the learner is before they reach us, which is why there is nothing for your identity team to configure, no metadata to exchange and no consent cycle to schedule โ€” usually the slowest part of any onboarding.

Who the learner is

Identity is keyed on the identifier your system already uses, not on an email address. An address can be edited or reused; this cannot, so a learner can never be landed in somebody else’s record. Where your privacy settings withhold the email entirely, everything still works.

What we are told

Name, an identifier, and โ€” where you release it โ€” an email address. Optionally the course and role, so we can show the right thing to a lecturer. Nothing else is requested, and nothing is passed to third parties.

Is this Microsoft SSO?

No, and it does not need to be. There is no direct integration between DetectedX and Microsoft 365, Entra ID or any other identity provider, and none is required. Your LMS or portal authenticates the learner โ€” quite possibly with Microsoft โ€” and vouches for them to us. If your security team asks what we connect to their tenant, the answer is nothing.

What we do not do

Your learners are not added to our marketing lists and are not contacted by us for anything other than the service they are using. Their data is not sold, shared or used to profile them outside their own performance record.

Ending access

Remove someone from the course or the LMS and they can no longer launch, so access ends immediately with no action on our side. Their record is retained by default so their history and certificates survive, but it has no way in.

Deleting records

Records can be removed entirely, by agreement and on request. The order matters: withdraw the course or the learners in your LMS first, so nothing re-creates the accounts, then ask us in writing and we delete the personal records and their performance history. Certificates and CME already issued stop being retrievable from us at that point, so most institutions export what they need first. Only anonymised figures that cannot identify anybody are kept.

Links and tokens

Sign-in links are single-use and short-lived, minted at the moment of the click rather than printed into a page. Launches are signed and verified against your platform’s published keys. We can expire any link or credential on request.

Results and reporting

What a DetectedX module produces, and where it goes

A self-assessment module does not produce a mark out of ten. It measures how a reader reads, against confirmed findings: their true and false calls, and the measures that describe diagnostic performance. Every option keeps the deep report โ€” case-by-case review, annotated answers, certificates, and the learner’s position against a peer group they choose โ€” inside DetectedX, where there is room to read it. What differs is the summary you receive.

Options A and B

The learner holds their own results and can download or email a score report and certificate. For Option B we provide a cohort report โ€” who started, who finished, and how the group read โ€” on a schedule that suits you.

Option C

As Option B, plus programmatic access: your platform can request results for the learners it created, and present them in your own dashboards.

Option D

Automatic. Each measure becomes its own gradebook column in the course, with the case counts carried in the feedback, arriving shortly after the learner finishes โ€” without the learner or the tutor doing anything.

Getting started

What we need from you

For Option A

  • The modules you want
  • Where the links will be published, so we can check they behave there

For Option B

  • A cohort list: name, email or your identifier
  • The modules or programme for that cohort
  • A named contact for joiners and leavers
  • How you would like the cohort report, and how often

For Option C

  • Which platform will call the API, and who will build it
  • Your group structure โ€” regions, hospitals, programmes
  • A test environment and a technical contact
  • Expected volumes, so we can size limits sensibly

For Option D

  • LMS product and version
  • Whether it is cloud-hosted or self-hosted
  • An administrator who can register an external tool
  • Confirmation that grade return should be enabled
  • For self-hosted: that your LMS is reachable from our servers, so results can be written back
Timing

The technical work is small in every option. What takes the time is calendar time โ€” getting the right people in a room, and your own review. Options A and B can be live in the same week you ask for them. Option D is a short administrator session plus an exchange of identifiers between the two systems and a test launch, but in practice it runs over a few weeks once diary time, a security questionnaire and any procurement step are included โ€” and those are almost entirely your side, not ours. Option C is a development project on your side, scoped with your team. We would rather set that expectation now than quote you hours and spend the first call explaining the difference.

Cloud or self-hosted

What changes if you run your own LMS

Less than most people expect. The registration screen is the same, and no plugin is installed either way โ€” which matters, because the most restricted hosting tiers do not permit plugins at all. The real differences are who holds the administrator rights, and whether your network team needs to be in the room.

 Cloud-hosted LMSSelf-hosted or on-premise
ExamplesBlackboard SaaS, Canvas Cloud, D2L Brightspace, MoodleCloud and Moodle partner hosts, Totara CloudYour own installation of any of them, on your servers or in your private cloud
Who sets it upYour LMS administrator, aloneYour LMS administrator, sometimes with IT alongside
Plugin requiredNoneNone
Server access requiredNoneNone
NetworkNothing to doYour LMS must be reachable from our servers so that results can be written back
Plugins Usually impossible on managed tiers โ€” and unnecessary here Possible, but still not required by us
Who holds admin rights Your own staff, or your hosting partner on request Your staff, directly
Version and upgrades Upgraded for you; tell us the tier and we confirm compatibility You control the version โ€” worth telling us before setup, and before you upgrade
Typical effort One short admin session One short admin session, plus a firewall conversation if the LMS is entirely internal

If you are on a managed or cloud tier

Nothing is installed and nothing is opened up. Your administrator registers us on the external-tool screen and that is the whole technical task. Restricted tiers that forbid plugins are the easiest case of all, because our integration never wanted one.

If you host it yourself

Identical setup, with one extra check: results are written back by our servers calling yours, so your LMS needs to be reachable from outside. Publicly reachable installations need nothing further. Fully internal ones need your team to allow our traffic or route it through the gateway you already use for external services.

If you are not sure which you have

Tell us the address your staff use to sign in and who supports it. That is usually enough for us to tell you which case you are in and what, if anything, your IT team needs to do.

Worth raising early

The network line is the only item that ever delays a go-live. Where an LMS sits entirely inside a private network, your team either allows our traffic through or points us at your existing gateway. It is routine, but it is better discovered in week one than in week four.

Commercial model

How each option is charged

Pricing is confirmed per institution in a separate quotation. The structure is consistent, so you can see what drives cost before you ask for numbers.

OptionCharged onWhat is includedSet-up fee
A ยท Module links Per module link, per period Access to the linked modules, link maintenance, learner support None
B ยท Launch links Per learner, per period โ€” or per cohort Bulk account creation, personal links, cohort reporting None
C ยท Partner API Per learner, per period API credentials, documentation, engineering support during your build Integration support fee
D ยท LTI 1.3 Per learner or per programme, per period Registration, the whole library or an agreed subset, automatic grade return Registration and validation fee

Content is licensed the same way in every option: either a named set of modules, or the full library. Moving from one option to another does not re-start the licence, and learner records carry over.

Questions we are asked

Frequently asked

Do we have to install anything on our LMS?

No โ€” in any option. For Option D the integration uses LTI 1.3 Advantage, which every modern LMS supports natively. We deliberately demonstrate on a hosted LMS tier that cannot install plugins at all, so there is no doubt on the point.

Does this require single sign-on with our Microsoft 365 or Entra ID?

No. Your learners sign in to your LMS or portal exactly as they do today, and that system tells us who they are. There is nothing to federate between DetectedX and your identity provider, and nothing for your identity team to approve.

What happens when a learner leaves?

Remove them from the LMS or the cohort and they can no longer reach DetectedX. No separate deprovisioning step is needed. Their record is retained so their certificates and history remain valid, but it cannot be signed into.

Can our learners’ records be deleted when we finish with the service?

Yes, by agreement and on written request. Remove the course or the learners in your own LMS first so that nothing re-creates them, then tell us and we delete the accounts and their performance records. Export any certificates or reports you want to keep beforehand, since they cannot be retrieved afterwards. We retain only anonymised figures that cannot identify an individual. Retention periods and the deletion process can be written into your agreement.

Can lecturers choose modules themselves?

Yes. In Option D they pick from the library inside their own course editor. In the other options they tell us which modules they want and we issue the links, usually the same day.

Which LMS versions are supported?

Any LMS that implements LTI 1.3 Advantage โ€” Blackboard Learn, Canvas, D2L Brightspace, Moodle, Open LMS and Totara all do, as do most others. We confirm your specific version and edition during setup, and validate the connection with a test launch before your learners see it.

Where is our data held, and what do you store?

Case images and content remain on DetectedX infrastructure; your LMS keeps enrolment and grades, which it already owns. From you we hold only what is needed to identify a learner and record their performance. Nothing is migrated in either direction, and nothing is shared with third parties.

Can we start small and change later?

Yes, and most institutions do. Learner accounts, history and CME carry across, so moving from links to a full integration does not reset anything or ask learners to start again.

DetectedX ยท Integration options, September 2026. This document describes how DetectedX content is delivered into an institution’s own learning environment. Specific module sets, learner numbers, reporting formats and pricing are confirmed per institution in a written quotation. For a technical conversation with your LMS administrator or IT team, we are happy to join a call and answer directly.