Automate the routine. Govern the exceptions.
A vendor-neutral reference architecture for identity, roster feeds, role-based access, parent consent, secure reminders, retention, auditing, incident response, and automatic offboarding.
One account lifecycle. Several authoritative sources.
All integrations shown are simulations. No specific platform is represented as a participating district system without verification.
District SSO + JIT
Authenticated entry creates the account only when needed.
SIS · LMS · HR
Courses, rosters, staff roles, transfers, and status changes.
RBAC + consent
Minimum-necessary access, guardian decisions, Support Circle scope.
Role workspace
Pre-populated dashboard, consolidated digest, exception queue.
Transfer, role change, consent revocation, Support Circle removal, and offboarding must recalculate access across the app, exports, reminders, and external links—not only the main screen.
Compare three implementation approaches.
The recommended hybrid design is a starting point. Each district confirms its authoritative systems, integration contracts, and operational capacity.
Hybrid recommended
District SSO establishes identity; SIS/LMS supplies students, courses, sections, and enrollment; HR supplies staff role/status; approved guardian and athletics sources add bounded relationships.
Define the contract before connecting the system.
Every item below is a future secure-pilot requirement—not an implemented integration or claim about district systems.
| Authoritative source | Minimum fields | Protocol target | Cadence | Acceptance criterion |
|---|---|---|---|---|
| Identity provider | Opaque user key; authentication state; approved groups | OIDC or SAML; JIT after district validation | Sign-in + lifecycle events | No local password; failed/offboarded identity cannot regain access |
| SIS / LMS | Course, section, enrollment, school, term; minimum necessary | OneRoster 1.2 or approved vendor API | Event where available + scheduled reconciliation | Transfer and withdrawal update every dependent permission and reminder |
| HR / staff authority | Staff key, status, job/assignment—not broad personnel records | Approved HR feed or secure mapping | Daily + urgent disable path | Role change and separation remove old access within the approved service level |
| Guardian / consent | Verified relationship, consent purpose/scope/version/status | District-approved guardian and e-sign workflow | On decision + revocation event | Revocation blocks sharing, reminders, exports, and future access |
| Athletics / support | Verified assignment and approved milestones only | Approved API/file or governed exception queue | Scheduled + human exception | No family finance, contracts, counseling notes, or unrelated records |
Security + privacy
TLS 1.2+ in transit; approved encryption at rest; managed secrets; least privilege; tenant separation; data-flow inventory; no model training on district data; tested deletion and backup handling.
Logging + detection
Tamper-evident access, export, consent, configuration, AI-draft, human-decision, exception, and admin logs—with role-limited visibility, alerts, retention, and review ownership.
Incident + recovery
Named severity levels, disable switch, token revocation, job stop, output quarantine, evidence preservation, notice/communications path, rollback, recovery target, and after-action review.
Earn technical release in stages.
This sequence cannot begin with real data while the project remains HOLD / REMEDIATE. Dates begin only after written district authorization and named owners.
Inventory + govern
Confirm systems and owners; map data/purpose; threat model; legal/privacy/accessibility review; architecture decision; acceptance criteria; incident roles; synthetic baseline.
Configure + test
Build sandbox connectors; test identity and offboarding; validate RBAC/consent; run PII, export, translation, accessibility, load, failover, backup/deletion, and shutdown exercises.
Shadow + decide
Use only approved bounded data; no autonomous writeback; measure workload and exceptions; rehearse incident response; resolve every Stop; document residual risk and release decision.
No connector, SSO, roster, message, storage, telemetry, model call, or district-system write is operating in this public walkthrough.
What educators should never have to maintain.
The success criterion is no net added burden—not merely a feature checklist.
No duplicate users
Accounts, rosters, assignments, and role changes flow from approved sources.
No parallel updating
Known district data is pre-populated; staff correct exceptions once.
No alert avalanche
Role-relevant items arrive in a prioritized digest with quiet hours and escalation.
No mystery data
Each field shows source, reporting period, evidence type, owner, retention, and use.
No lingering access
Transfer, removal, or offboarding revokes permissions and reminders automatically.
No silent automation
Every consequential action requires the authorized human at the point of decision.
account creation
manual work
burden review cadence