Not based on a specific customer deployment. The company, figures, decisions, and outcomes below are a constructed example that shows how Intended’s mechanism applies to this kind of problem. They are not measured results from a named customer. Where we publish a real, attributed customer outcome, we will say so explicitly.
FERPA-Aware Governance for AI Student Services
Consider a university system whose AI agents handle enrollment processing, academic advising, grading assistance, financial aid calculations, and student support chatbots — all subject to FERPA rules for student data protection.
01 · the challenge
The kind of problem this addresses.
02 · how it works
See the difference.
Student asks AI advisor about aid
"What financial aid am I eligible for?"
AI accesses full student record
GPA, enrollment, financial data, disciplinary records
Oversharing in response
AI references disciplinary record in aid context
No FERPA-compliant log
Cannot demonstrate legitimate educational interest
03 · the solution
What they deployed.
- — Installed Education Operations domain pack with FERPA-specific intent classifications
- — Configured scope-limited authority tokens: each query only accesses relevant record categories
- — FERPA legitimate educational interest documentation generated automatically
- — Student consent tracking integrated with Intended authorization chain
- — Quarterly FERPA compliance reports generated automatically for each campus
04 · implementation
From zero to governed.
Week 1
Assess
Mapped all 8 AI agents and their student data access patterns. Identified 12 access categories subject to FERPA.
Week 2
Configure
Installed Education Ops domain pack. Defined scope rules per intent: advising gets academic records, financial aid gets financial records.
Week 3
Deploy
Rolled out across all 4 campuses. Connected SIS, LMS, financial aid, and student support systems.
Week 4
Validate
FERPA compliance officer verified access controls. Generated first automated compliance report.
05 · illustrative outcomes
What this is designed to deliver.
Modeled figures for this scenario — what the workflow above is built to achieve, not measured results from a named customer.
0%
AI access scope-gated
Each query reaches only authorized record categories
0%
Access events logged
Legitimate educational interest documented
0-min
Token TTL
Read-only, scope-limited, auto-expiring
0-click
FERPA reporting
Compliance reports generated from the audit chain
06 · decision replay
Example decisions, full trace.
Sample decision records that show the shape of the evidence Intended produces. Illustrative, not drawn from a live customer’s logs.
edu.student.financial-aid-queryRISK: 18/100ALLOW22msAI advisor looks up financial aid eligibility for student ID: STU-48291
Resolved by: Policy: student-initiated query, financial scope only
edu.student.grade-accessRISK: 24/100ALLOW18msAI grading assistant accesses current semester grades for STU-48291
Resolved by: Policy: academic scope, legitimate educational interest
edu.student.bulk-record-exportRISK: 85/100ESCALATE28msAI analytics agent requests bulk export of all student GPA data for reporting
Resolved by: Registrar (approved de-identified export only, in 22m)
edu.student.disciplinary-accessRISK: 92/100DENY14msAI chatbot attempts to access disciplinary records during enrollment query
Resolved by: Policy: disciplinary records not in scope for enrollment intent
the takeaway
FERPA compliance for AI is not just about logging access — it is about proving that every AI interaction only touched the specific records it was authorized to see. Scope-limited authority tokens make that provable rather than asserted.
Why this pattern matters — not a customer quote.
Start protecting student data
Free to start. See every AI decision from day one.