The school comes from the host, not from a picker
Tenancy is resolved from the subdomain and carried on every request, so a user never selects which school they are looking at and cannot be in the wrong one by accident. The alternative — a dropdown and an id in application state — makes the tenant a thing the client decides, and the first bug you get is somebody's data appearing under somebody else's letterhead.
Kiosk as a mode inside the app, not a second application
It shares the same routes, services and session plumbing rather than being built and deployed separately. A second app would have meant two release cycles and two copies of the attendance logic drifting apart. The cost is that the kiosk lives inside a build that also contains the admin panel, which is a boundary that then has to be defended deliberately rather than by architecture.
Two layers of identity on one tablet
The device is unlocked once by the school, and each person at it identifies themselves separately — a parent by email and a four-digit PIN or a scanned code, a teacher from the roster. Asking a parent at a doorway to type a password would take longer than the drop-off itself; a device with no identity at all cannot tell you who signed the child in.
Logout flushes before it clears
Ending a kiosk session pushes any pending attendance before wiping the session keys. Clearing first is the obvious order and quietly discards the check-in that was mid-flight — the exact event the whole surface exists to record.