Skip to main content
Custodia.network

Records custody / Vendor access / Accountable review

A clear account
of who needed access.

Begin with a precise purpose. Keep the evidence in scope. Give the next person an explanation they can actually review.

Custodia is the vendor-access and records-custody member of the network. This public workbook helps administrators and school partners prepare access questions, understand the described trail, and handle a responsible handoff. It displays no live student records and performs no account or retention actions.

Start with the scope
Vendor scope, stated plainly.

It does not log reads by your own teachers, advisers or office staff. Your school's internal access is yours to govern. Retention scheduling is specified but unavailable; this page runs no schedule.

01 / The boundary

A vendor trail has a precise edge.

Custodia concerns the custody of records and the evidence surrounding platform-side access. Start with the smallest accurate statement: the described vendor-access trail concerns named Stanley Studios platform administrators. It does not log reads by your own teachers, advisers or office staff. A school should never use an empty vendor trail as evidence that nobody at the school opened a student record. Those are different populations and different review responsibilities.

Bring three inputs to the first conversation: the record category under discussion, the person or role believed to have accessed it, and the question the school needs answered. “Who used our data?” is a reasonable concern, but it contains several investigations. A support administrator opening a record, an adviser reviewing a class list, and a family viewing its own information require different evidence. Classify the question before looking for a reassuring number.

The output of this first step is a scope statement that an ordinary reader can challenge. For example: “We are reviewing platform-administrator access associated with a support inquiry about one incorrectly associated portrait.” That sentence identifies the activity without naming the child on a public page. It also makes clear that classroom access, a school's paper copies, and another vendor's exports remain outside this particular review. A shorter statement that drops those limits is less useful.

The described platform-administrator read path couples its access record to the read in the same transaction: a read that cannot be logged does not happen on that audited path. That is a meaningful design boundary, not a promise that every route, identity, or deployment has been examined here. This public workbook does not inspect a school's live environment. Ask an authorized operator to identify the environment and route covered by any evidence they provide.

Do not turn “append-only” into a claim about the entire life of a record. It describes constraints on changing or deleting the access trail; it does not prove that every relevant event entered that trail, that a person's stated purpose was appropriate, or that a screenshot remained private after download. Completeness, authorization, and later handling need their own questions. Custody improves when the review names each of those questions separately.

The practical result is a two-column responsibility map. One column belongs to the vendor's platform access review. The other belongs to the school's internal access governance. Give each column a named owner and an evidence source. When a question crosses the line, preserve the original question and hand it to the second owner instead of forcing an answer from the wrong record set. The family should receive an intelligible explanation of that handoff.

If a vendor trail is empty, can we tell a family that no one accessed the record?

No. Say which vendor scope and period were examined, what was observed, and what remains outside that evidence. Ask the school to investigate its own staff access separately. An empty result with an unexplained scope is not an answer to a broad access question.

02 / A useful request

State the purpose before naming the record.

An access review starts before somebody opens the sensitive material. The request should explain the problem in operational terms: a duplicate association, an incorrect label, a missing permitted output, or an unexpected record view. Describe the failed result and the result that would count as a resolution. A request that only says “please investigate” makes it difficult to distinguish necessary examination from a broad tour through a school's information.

Use a non-sensitive reproduction when one can answer the question. A fabricated example with the same field shape may reveal a formatting problem without opening a real student record. Remove actual names, photographs, birth dates, contact details, and incidental notes from the example. The point is not to disguise a real record while keeping every identifying detail; it is to retain only the structure needed to understand the defect.

If the issue requires a real record, identify the narrow object through the school's approved private channel. On this public page, keep the reference abstract: one record, one organization, one inquiry. Record why the synthetic example was insufficient. That explanation gives the later reviewer a way to assess necessity. It also helps the operator stop when the necessary fact is known instead of continuing into adjacent records out of convenience.

A usable request includes a school contact, a vendor contact, the requested purpose, the permitted record category, a review period, and the expected handoff. These are planning inputs for the people using their authorized systems; completing a worksheet does not grant permission. A district's own procedures determine who may request or approve a review. Custodia's public surface provides no approval button and creates no access entitlement.

Write an explicit stop condition. “Confirm whether the association points to the intended class, then report the discrepancy without copying the portrait” is more reviewable than “look into the class.” If a second issue appears, preserve that observation as a separate question. Expanding a support request silently makes the original scope inaccurate and leaves the approving person unable to understand what happened under their request.

The output should fit in a short case brief that another authorized reviewer can read without opening the underlying student material. Include the question, necessity, boundary, responsible people, and completion evidence. Mark missing inputs visibly. A request without an identified school owner stays incomplete; it should not acquire credibility merely because somebody assigned it a reference number. The reference helps find a decision, but it is not the decision itself.

Wouldn't it be faster to send the entire roster and let support find the problem?

It may shorten the first message while greatly widening the material that must be protected and reviewed. Start with the smallest useful example. If broader access is necessary, explain the additional need, identify its owner, and use the approved private process before expanding the request.

03 / Identity and context

A name needs a role and a reason.

A named actor makes an access record more accountable than an unexplained shared identity, but the name alone does not settle the review. Ask which organization and role the actor was operating under, what task required the access, and whether the person was authorized for that task. The same human may participate in several workflows. Evidence about one role must not be casually used to explain activity performed under another.

The Custodia boundary is especially important here. The described audited path is the platform-administrator scope. Studio, school, adviser, parent, representative, and system scopes are not interchangeable with that scope and should not be presented as covered by this vendor read trail. A readable report should use the actual category instead of flattening everything into “staff.” That one word can conceal precisely the distinction a family is trying to understand.

Inputs for identity review include the named actor reference supplied through the approved channel, the relevant role, the organization context, and the case purpose. Avoid circulating additional personal details about the operator merely to make the report look thorough. An authorized reviewer may need a stable internal reference to distinguish people with similar names. A family-facing explanation may need a role and accountable organization without publishing the operator's private contact information.

Produce a context statement alongside the actor attribution. In a worked example, an administrator reviewing a portrait-association defect acts for the vendor in a bounded support task, while the school adviser validates the corrected class membership through the school's own process. Those are complementary responsibilities. The vendor's named access evidence does not establish that the adviser took a particular action, and the adviser's confirmation does not replace evidence of the vendor's access.

If an actor cannot be explained, stop short of assigning motive. An unfamiliar identity could indicate a legitimate person using an unexpected role, a stale authorization, an incomplete mapping, or an issue requiring escalation. Preserve the uncertainty and request clarification from the accountable owner. “Unknown in the evidence supplied” is an honest result. A guess based on a familiar name can direct the investigation toward the wrong person.

Keep identity changes in view during a longer case. A person moving teams or leaving an organization may change who is permitted to continue the work. A case brief should name the current responsible owner and identify any handoff that matters to the review. This workbook cannot revoke accounts or verify employment status. Its role is to make those dependencies visible so that the people with authority can verify them before relying on an old attribution.

Does a named access entry prove that the named person's purpose was appropriate?

It provides attribution within the recorded scope. Appropriateness requires the request, authorization, purpose, and surrounding evidence. Review the entry against those facts. Do not turn a technically attributable read into an automatic finding that the access was justified.

04 / Authorization review

Permission is a decision, not a checkbox.

An authorization review asks whether the proposed access fits an approved purpose and an appropriate decision maker. Bring the scoped request, the relevant organizational policy, the data category, and the person accountable for approving the work. These inputs belong in the school's and vendor's established private processes. This guide does not replace those processes, determine legal authority, or grant an exception because a support matter feels urgent.

Separate an approval to investigate from an approval to copy or distribute. A person may need to inspect an association without taking a screenshot, or verify a field without exporting the surrounding record. Write down the permitted handling explicitly. Otherwise an operator may interpret a broad “yes” as permission for several downstream actions that the school contact never considered. Each additional copy creates another custody question.

A useful authorization statement names the purpose, scope, responsible operator category, review boundary, and expiry or reconsideration condition. That condition can be an event, such as completion of a specific diagnosis, rather than an invented timer on this page. If the case changes, the authorization needs to be reconsidered in the actual system of record. No countdown shown on a marketing surface would revoke a real credential.

The output is a decision with enough context to review later: approved within a described boundary, declined with a reason, or incomplete because a necessary fact is missing. Keep those outcomes distinct. An incomplete request is not an accusation against the requester. A declined request does not prove the underlying problem is unimportant. Clear outcomes make it possible to pursue a safer alternative without erasing why the first proposal was unsuitable.

Consider a support inquiry that begins with a single incorrect class assignment and then uncovers a pattern affecting several classes. The original purpose may still be relevant, but the proposed data scope has expanded. Return the new scope to the accountable owner. Offer a non-sensitive count or structural description where possible. The reviewer can then decide whether a broader investigation is justified without receiving the entire expanded data set first.

An objection often arrives as a deadline: a proof must be approved today, or a family expects an answer before dismissal. Record the deadline because it helps prioritize the work, but keep it separate from authorization. A time pressure can justify a faster review by the appropriate person; it does not turn the public guide into an emergency access route. When authority is unclear, the concrete next step is to contact the designated owner through the existing approved channel.

Can we record approval here and ask an operator to proceed from that record?

This page does not store approvals or communicate with an access-control service. Use the organization's approved private process and verify who can make the decision. The review structure is useful preparation, but reading it or opening a disclosure creates no operational permission.

05 / The working session

Keep the investigation inside its brief.

Before an authorized operator begins, the case owner should be able to state what is being examined and what would end the examination. The inputs are the accepted case brief, the relevant authorization, the environment being investigated, and an agreed way to report the result. A chat message saying “take a look” lacks too much context. A prepared brief reduces the chance that the operator must improvise the boundary while already viewing sensitive information.

During the session, distinguish observations from interpretations. “The selected association points to a different class” is an observation that can be supported by appropriate evidence. “Someone deliberately changed the class” is an interpretation requiring additional facts. Record the first without promoting it into the second. This distinction matters when an initial support diagnosis later becomes part of a school's explanation to a family or an investigation of contested access.

Use the minimum amount of student detail required for the authorized task. When reporting progress, refer to the case and the specific issue rather than repeating names or embedding screenshots in every message. Repetition produces new copies without necessarily helping the next person make a decision. If a visual example is essential, establish who may receive it, how it will be protected, and what should happen to it after its purpose ends.

A scope change has a practical signal: the operator would need another record category, another group of people, a new use, or a different handling action to continue. Stop at that signal and explain the proposed change. The output may be a revised request, a narrower alternative, or a decision that the remaining question belongs to another team. A tidy case summary should preserve the change rather than presenting the whole investigation as if it had always been approved.

At the end, record the conclusion and its evidence boundary. A resolved association problem is not the same as a completed access review, and a completed access review is not a certification of every surrounding control. Identify which question was answered, what evidence was considered, and what remains open. The school contact should be able to take that handoff without guessing whether the operator expects further access.

This page cannot open or close a support session, inspect credentials, or observe a live record. It offers a disciplined sequence for a conversation using authorized tools elsewhere. A reviewer should ask the operator how the real session ended, how any temporary permission was handled, and where the bounded completion record lives. Those answers belong to the actual environment and should not be inferred from a polished illustration in a product guide.

If the original problem is fixed, is the access review automatically complete?

No. Confirm the result, then close the custody questions: what was examined, whether the scope changed, what material was copied, and who owns any remaining action. A successful repair can coexist with unanswered questions about the handling of the records involved.

06 / Reading the evidence

Ask what an entry can actually establish.

An access entry is useful when the reviewer can connect it to a specific question. Start with the named actor attribution, the recorded activity, its time context, the organization boundary, and the case purpose supplied through the approved process. Do not assume that a displayed row contains all of those facts or that every export uses the same shape. Ask the operator to explain the evidence actually provided, including any missing fields or conversions.

Time deserves careful handling. A recorded time may be displayed in a different zone from the school's calendar, and a report may use a period whose endpoints are not obvious to the reader. State the zone and the examined interval in the review note. If a family asks about an afternoon event, translate the question into the evidence's time convention explicitly. Do not use a near match to imply certainty about two events that may be unrelated.

The described access trail is append-only, with restrictions on updating and deleting its entries. Treat that as a property of the trail's handling, not as a substitute for investigating coverage. A record may be resistant to later alteration while still answering only the platform-administrator portion of a broader question. A reviewer needs both ideas: what protects the recorded evidence, and which activities were eligible to produce that evidence in the first place.

A useful output is an evidence statement with three parts: observation, interpretation, and limit. An illustrative statement might say that a named vendor administrator's access appears within the supplied review interval, that it is associated with the stated support inquiry according to the case owner, and that the material does not cover the school's own staff reads. The separation allows another reviewer to challenge the interpretation without losing the underlying observation.

Avoid counting entries as if they were automatically distinct incidents, people, or student records. The meaning of a count depends on what an entry represents and how the query was scoped. Several entries may relate to one permitted investigation; a single entry may not answer every question about that investigation. Ask for an explanation of the counting method before presenting a total to a family, administrator, or oversight group.

This public workbook displays no live entries and supplies no access-history export. Its examples illustrate how to read evidence when an authorized party provides it. If the evidence is incomplete, preserve the gap as part of the result. “Unable to establish the answer from the supplied record set” is more accountable than filling in the missing story from a product description, a familiar staff name, or an HTTP response that merely shows a page loaded.

Does an append-only entry prove that nobody could ever have accessed the data another way?

No. It addresses the handling of that entry. Coverage of other roles, routes, systems, and copies requires separate evidence. Keep the review tied to the actual audited scope and ask explicitly about any route that matters to the concern being investigated.

07 / Chain of custody

The explanation needs a traceable handoff.

Evidence becomes harder to interpret when it moves without context. An isolated screenshot may show a value but omit the review period, the source environment, the person who produced it, and the question it was meant to answer. A custody handoff should preserve those facts alongside the material. The purpose is practical: the next authorized reviewer should understand what they received without requesting an unnecessarily broad replacement export.

Begin with an inventory of the artifacts actually needed for the case. That might include the scoped request, an authorized evidence extract, a redacted explanation, and a completion note. Name an owner for each artifact and identify the intended recipients. The inventory does not require copying the student's full record into the case. In many reviews, a precise reference and a limited explanation are sufficient for the next decision.

When an artifact is transformed, record what changed. Redaction, time-zone conversion, sorting, translation, and summarization can each be useful, but each creates a different representation of the original. A summary should say that it is a summary. A redacted copy should identify the kind of material withheld without revealing it in the explanation. Do not silently replace the original evidence with a more convenient presentation and leave the next reader assuming nothing changed.

The output is a handoff record that links the source, permitted purpose, transformation, recipient, and next responsibility. This is a review discipline, not a claim that Custodia currently supplies a transfer portal or cryptographic evidence service. Use the organization's approved tools to keep the artifacts protected. If a recipient cannot safely receive the proposed material, change the handoff method or provide a narrower explanation through an appropriate channel.

Consider a family-facing explanation derived from a vendor access review. The school may need enough detail to answer the family's concern while protecting unrelated students and private operator information. Keep the relationship between the restricted evidence and the readable explanation clear. The family should understand the scope and conclusion, while an authorized reviewer retains the ability to examine how that conclusion was reached. Privacy should not become an excuse for an unexplained assertion.

A break in the chain is a fact to investigate, not a reason to invent continuity. If a screenshot's origin is unknown or a spreadsheet cannot be tied to the supplied interval, mark it as unverified and ask its provider for context. Do not discard it merely because it is inconvenient, and do not treat it as conclusive because it looks official. Its usefulness depends on what can be established about the material and the decision it supports.

Can we forward the same evidence bundle to everyone involved so they share the context?

Determine what each recipient needs and is authorized to receive. A school investigator, a support operator, and a family may need different representations. Preserve the relationship between them, but avoid distributing sensitive source material simply to make a discussion easier.

08 / The school's own access

Keep the second responsibility visible.

A family may ask a single question about who saw a child's information, while the answer crosses several organizations and roles. The vendor-access trail is only one part of that inquiry. Custodia does not log reads by your own teachers, advisers or office staff. The school's internal access is yours to govern. This exclusion belongs beside the product explanation, not in a footnote a worried parent must discover after receiving a reassuring summary.

The school-side inputs are the roles involved, the systems used, the period under review, and the local policies that govern access. The school's authorized owner should identify the evidence available for those systems. Some questions may involve an application, others a downloaded file, a printed sheet, or a verbal disclosure. A vendor trail cannot account for all of those activities simply because the original record once existed on the platform.

Create a school access map without inventing observability. For each relevant activity, record the owner, the available evidence, and any known limit. If a local process has no reliable record of individual reads, say so in the review. The absence of such evidence may affect the conclusion, but it is not permission to label every possible access as proven or to declare that no access occurred. Uncertainty should remain specific.

A practical example is an adviser who downloads a permitted class list and later prints a working copy for an approved task. Questions about who received that printout belong to the school's handling process. A vendor administrator's access history does not reveal the printout's circulation. The review should identify the relevant school owner and the actual handling evidence, while keeping the vendor investigation available for the distinct platform-side question.

The output can be one coordinated response with clearly separated evidence sources. Use ordinary labels such as “vendor platform access reviewed” and “school staff handling reviewed.” Explain unresolved portions without forcing the family to understand internal role names. A joined response is helpful when it preserves the boundaries; it becomes misleading when it merges different levels of evidence into one broad claim that everything was checked.

Internal governance is more than a retrospective investigation. Schools can use the question to review who needs access, how role changes are handled, where copies accumulate, and how staff recognize an inappropriate request. This guide does not prescribe a legal retention period or provide employee monitoring. It offers a way to identify the decisions the school owns and to prevent the vendor's narrower trail from displacing those decisions in a policy discussion.

Should we hide the exclusion because families may find two responsibility areas confusing?

Explain the distinction in plain language and provide a coordinated handoff. Hiding it creates a simpler sentence at the cost of a false impression. Families can understand that the vendor and the school have different evidence when each owner states what was examined and what remains open.

09 / Exceptions and urgency

Pressure does not erase the boundary.

An urgent request still needs a purpose, an accountable owner, and a defined action. Begin by separating the operational deadline from the reason sensitive access is necessary. A looming print deadline may require a fast decision about a page, but it does not automatically require opening every underlying student record. Identify the smallest safe action that addresses the immediate problem while the broader question receives an appropriate review.

The inputs for an exception discussion are the normal process that cannot be followed, the reason it cannot be followed, the proposed alternative, and the person authorized to decide. Do not treat the word “emergency” as self-explanatory. Describe the concrete consequence and the time available. An accountable decision maker can evaluate those facts; a public page cannot assess a live emergency or authorize a new route around an access control.

Custodia provides no break-glass control here. There is no hidden override, no emergency credential, and no button that grants access while postponing accountability. If an operator cannot use the approved path, the next step is to contact the established responsible person and document the blockage in the authorized process. A failed access attempt should not become an invitation to use someone else's account, an unrelated scope, or a copied credential.

A useful output may be a reduced operation rather than an expanded permission. For example, a school might pause a disputed item from a proof while the association is checked through a permitted route. That decision addresses the publication risk without assuming a new data-access capability. The actual school owner must decide what is appropriate for its circumstances. The example illustrates a question to consider, not an automated response supplied by this site.

If an exception is approved elsewhere, the subsequent review should retain its reason, authority, scope, duration or stop condition, and completion evidence. Do not rewrite it as an ordinary request after the deadline passes. The exception's context is part of what a reviewer needs to understand. Repeated exceptions may reveal a process problem that deserves a separate operational decision instead of becoming an informal permanent bypass.

A refusal also needs a usable handoff. State which prerequisite is missing, which owner can address it, and whether a less sensitive alternative can proceed. “No” without a path can push people toward unreviewed workarounds. A clear refusal protects the boundary while helping the requester pursue the underlying need responsibly. This is why an unavailable route should be described honestly rather than represented by a decorative control that appears to promise an override.

Can a senior person's message substitute for the established authorization process?

Verify that person's authority for the particular action and use the approved process. Seniority alone does not identify the data scope, permitted handling, or stop condition. Preserve the actual decision and its context so that urgency does not leave the later reviewer guessing what was authorized.

10 / A contested access

Investigate the question without inventing the story.

When a person disputes an access, begin with the concern in their own terms and then translate it into investigable questions. The initial input may be an unfamiliar name, an unexpected time, a suspected disclosure, or a mismatch between a support explanation and an observed result. Preserve the original concern. Narrowing the technical question should help answer it, not replace it with an easier question that leaves the person unheard.

Identify the period, organization, record category, and possible actor scope without asking the family to post sensitive details publicly. An authorized private channel should carry the actual references. This site has no complaint submission form, record lookup, or incident intake backend. Use the established school or vendor contact appropriate to the concern, and ask that person to explain where the inquiry will be tracked and who will provide the response.

Build a simple distinction between established facts, plausible explanations, and open questions. A named vendor access within a period is a fact only when supported by the relevant evidence. A relationship to a support case may require a separate explanation from the case owner. A claim about intent demands still more context. Keeping these categories apart prevents an early hypothesis from becoming the final narrative merely through repetition.

The review output should state what was examined, what was found, the evidence limits, and the next action. If the question involves school staff, include the school-side owner rather than implying the vendor evidence resolves it. If the period or source is incomplete, explain the effect on the conclusion. A reader should be able to distinguish “the evidence does not show this” from “the review establishes that this did not happen.”

Consider a family who notices an unexpected correction after a support inquiry. The correction alone does not establish who read the record or why. The reviewer may need to examine the scoped vendor evidence, the support brief, and the school's own actions. The result could identify an authorized correction, reveal a process error, or remain incomplete. The method should allow each outcome instead of assuming the product must be vindicated by the investigation.

Close the communication loop even when the technical work takes several handoffs. Identify the current owner and explain the next decision without promising a deadline that has not been agreed. Do not expose another student's information to make the explanation more persuasive. A thoughtful response can describe the process, boundaries, and findings at an appropriate level while preserving a route for an authorized reviewer to examine the underlying material.

Should an unexplained entry be called a breach or dismissed as ordinary support?

Neither label should be inferred from the entry alone. Preserve the evidence, investigate purpose and authorization, and involve the accountable owner. This guide makes no legal determination. The response should reflect established facts and clearly identify what remains unresolved.

11 / Retention decisions

A schedule needs authority before automation.

Retention planning connects a record's purpose to the conditions under which it should be kept, reviewed, archived, or removed. The scheduling capability is specified but unavailable; Custodia does not run a retention calendar from this page. Reading a retention example does not start a timer, place a hold, archive a record, or delete anything. The first useful task is to identify the organization's actual policy owner and the record categories involved.

Bring a record inventory, the purpose for each category, the applicable organizational policy, and any relevant preservation instruction to the planning discussion. The correct period may depend on circumstances that this page cannot determine. Do not infer a universal number of days from a product illustration. A school should obtain the appropriate professional and organizational guidance for its decision, then express that decision clearly enough for an authorized operator to apply it.

Separate the student record, the support case, the vendor access trail, and any exported evidence. They may serve different purposes and have different handling requirements. Treating them as one object can produce contradictory instructions, such as deleting the explanation needed to review a disputed access while retaining an unnecessary duplicate photograph. The planning output should describe each category individually and identify the dependencies that must be checked before any action.

An illustrative retention worksheet includes the category, owner, purpose, governing instruction, review trigger, exception condition, and evidence of the completed action. It is a decision aid, not an active policy configuration. Mark an undecided period as undecided. Do not fill it with a convenient default merely to complete the table. An explicit unresolved decision is easier to govern than a confident number that nobody actually authorized.

Preservation questions deserve a separate review before routine disposal. If an inquiry is active, an authorized owner may need to determine how the relevant material should be handled. This guide does not create or release a legal hold and offers no legal conclusion about preservation duties. Its practical point is narrower: do not let an unexamined routine instruction silently decide the fate of evidence that a responsible person is actively reviewing.

When an authorized action occurs through a real system, the completion evidence should identify the action, scope, responsible party, and any residual copies or limitations. A calendar entry saying “delete” is not evidence that deletion occurred. A removed view is not proof that every backup or downstream copy disappeared. Ask what the actual operation covered, and carry that boundary into the final explanation rather than offering an absolute erasure guarantee.

Can we enter a retention period on this page and rely on Custodia to enforce it?

No. Retention scheduling is unavailable here, and this guide stores no policy. Establish the decision with the proper owner, identify the real tools and their limits, and require evidence of any completed action. A planning worksheet is not an enforcement mechanism.

12 / Ending a relationship

Close access and custody as separate tasks.

Offboarding asks two related questions: who should retain access, and what should happen to the material already held. Removing a person's permission does not automatically account for a prior export, a support attachment, or a working paper copy. Begin with the relationship ending, the responsible organizations, the active cases, and the known artifacts. A useful review includes both the future access decision and the custody of existing material.

The school and vendor should identify their own accountable owners. The vendor's platform-administrator trail does not replace the school's review of teachers, advisers, office staff, or other local roles. A staff departure, a studio transition, and the end of a support engagement have different boundaries. Describe the specific transition instead of using one broad “offboarded” label that leaves readers unsure which permissions and copies were considered.

Create a handoff inventory of open work before concluding that the relationship is closed. An unresolved access inquiry may need a new case owner even when the original operator leaves. A pending correction may require the school to validate an output. A retained evidence package may need a designated custodian. The output of the inventory is a responsibility assignment, not an excuse to retain every artifact indefinitely in case someone might want it.

Verify actual access changes through the systems authorized to make them. This page cannot revoke a session, remove a role, disable an account, or inspect whether a credential remains usable. A disabled button would not prove any of those outcomes. Ask the responsible operator for the relevant completion evidence and its scope. Keep a distinction between a request to remove access and confirmation that the specific change occurred.

For existing copies, apply the organization's approved retention and handling decision. Identify where a copy is held, why it remains necessary, who is responsible for it, and how its eventual disposition will be reviewed. Do not make a blanket destruction promise that overlooks another recipient or a required preservation decision. Equally, do not use uncertainty about one copy to avoid making a clear decision about the others.

A final offboarding note should allow another reviewer to resume any remaining work. State which relationship ended, which access changes were confirmed, which artifacts were addressed, and what remains assigned to a named owner. If the evidence is incomplete, mark the transition as incomplete in that respect. The purpose is a reliable handoff, not a celebratory status label that conceals unresolved custody responsibilities.

Does closing the support case prove that temporary access and every copy were removed?

No. Case closure is a workflow outcome. Access changes and artifact handling require their own evidence from the responsible systems and people. Ask for those specific confirmations, and preserve any limits on what the confirmation actually covers.

13 / Worked case

One portrait association, three separate conclusions.

Imagine a fictional school discovering that a portrait appears under the wrong class during a review. The school wants the association corrected and also wants to understand whether vendor support needs to view a student record. This example contains no actual student data and describes a review method, not an event observed on the platform. Its value is in showing why the operational repair, the access question, and the final explanation require distinct conclusions.

First, the school owner describes the mismatch with a non-sensitive example of the expected and observed relationship. If that example cannot reveal the cause, the owner identifies the narrow private reference through the approved channel. The request states the intended task: examine the association needed to diagnose the mismatch. It excludes unrelated classes, broad roster export, and reuse of the portrait for any other purpose. Those limits are part of the request's usefulness.

Second, the responsible people establish the appropriate authorization in their actual workflow. The vendor operator's role matters because the described Custodia trail covers the platform-administrator path, not every possible role. The school adviser who validates the class assignment remains part of the school's own access governance. A reviewer should not merge those actors into a single “staff access” category and then assume one trail accounts for both.

Third, the authorized investigation produces a bounded observation and a proposed correction. The school validates the corrected result using its own appropriate process. That validation answers whether the association now matches the intended class. It does not independently establish which vendor records were opened, why every access was appropriate, or whether any copied evidence was handled correctly. Those questions return to the scoped access evidence and the custody handoff.

The final review therefore has three outputs. The product result states whether the association question was resolved. The vendor access statement describes the platform-administrator evidence examined and its limits. The custody note describes the material shared during the inquiry and its assigned handling. A family-facing explanation can summarize these outputs in plain language without including another student's details or suggesting that the vendor trail covers the adviser's local activity.

Now change one fact: the operator discovers that the pattern affects an entire grade. The original single-association brief no longer describes the proposed examination. The responsible owner must evaluate a revised scope or a less sensitive diagnostic method. That is the decision point this example teaches. A problem becoming larger does not silently make the permission larger, and a helpful operator should not have to guess whether a school intended that expansion.

What if the school only wants the correction and does not ask about access?

Keep the work bounded and preserve the relevant accountability in the authorized process. A lack of questions does not broaden the purpose. The school can receive a concise operational result while the responsible parties retain an appropriate explanation of the access and handling involved.

14 / The review desk

Choose the next question from the evidence you have.

Use the disclosures below as a small review desk: open the question closest to the situation, read the decision boundary, and carry the relevant inputs to the accountable owner. Opening a disclosure changes only what is visible in your browser. It stores no answer, sends no message, and makes no access decision. The tool is useful because it organizes the next conversation without collecting the sensitive details that conversation may involve.

If you have a support request but no access evidence, begin by checking the request's scope and the actor category. Ask the authorized operator what evidence can address the platform-administrator part of the question. Do not label the case “no access” simply because the request contains no attached trail. The absence of an attachment tells you about the material in front of you, not about everything that happened in another system.

If you have an access entry but no clear purpose, ask for the associated operational explanation through the established review process. Preserve the entry's attribution and time context while marking the purpose as unresolved. Do not fill the gap with a guess based on a recent support conversation. Two events being close in time can help form a question, but the relationship still needs evidence or a responsible explanation.

If your question concerns a teacher, adviser, or office staff member, route it to the school's internal access owner. Custodia's vendor trail cannot answer that question by itself. Keep the vendor evidence if it is relevant to another part of the inquiry, but do not force the school-side question into the wrong scope. A clear handoff identifies the school contact, the specific concern, and the evidence the school should assess.

If you have a retention instruction but no completion evidence, distinguish the decision from its execution. Ask which authorized system or person performs the action and what confirmation it produces. The retention scheduler is unavailable here. A date written in a plan does not establish deletion, and a record disappearing from one view does not establish the handling of every copy. The next question should name the specific category and action being checked.

If you have several partial answers, build a concise open-questions list instead of turning them into a false whole. Assign each question to the owner who can actually answer it. The output may be a coordinated response with a few remaining limits rather than a single definitive label. A useful review desk reduces ambiguity about the next step; it does not manufacture certainty from incomplete material or treat every unknown as proof of misconduct.

Can I use this page as the official record of my review?

No. This is a public reading and preparation surface. Use your approved private system for the real case, its evidence, and decisions. The disclosures remain local presentation controls; they do not identify you, save a case, or notify an accountable owner.

15 / Explicit refusals

No invented controls behind the surface.

This page is a custody and access-review guide. It is not connected to a live audit query, permission service, retention scheduler, or case-submission backend. It cannot grant, revoke, save, send, export, archive, or delete a school record. That boundary should be visible before a person relies on the page. Native disclosure controls help readers inspect a question; they do not perform an operational action or create evidence that such an action occurred.

Money actions are off on this surface. There is no checkout, invoice payment, payout request, refund control, or Stripe connection flow. A product discussion about costs would not itself collect money or establish that a payment provider is configured. Do not treat a link, an interest in a service, or a prepared case brief as a completed financial transaction. Any real financial workflow requires its own configured service, authorization, and verifiable result.

AI processing is also unavailable here. The page sends no student record, portrait, access entry, or free-text inquiry to an AI provider. An unconfigured or unavailable provider must be treated as a refusal to run that operation, not as permission to fabricate an answer. No generated output is automatically applied to records through this surface. A human-readable explanation of evidence should remain tied to the actual evidence and accountable review.

Face recognition is not wired in the shipping configuration; no face template is computed from a photo. A custody discussion must not imply that the system identifies a student from a portrait to reconstruct an access history. Record attribution, person identity, and image interpretation are separate questions. When a school needs to validate an association, use the approved human review process and the permitted information for that task instead of assuming a hidden recognition capability.

The page makes no compliance certification, guaranteed legal outcome, or claim that every possible access is observable. It describes the vendor scope carefully and gives the school a practical method for its own questions. Policies, deployment configuration, and actual evidence must be evaluated in the environment that matters to the review. A trustworthy product boundary can be narrow. It becomes less trustworthy when a marketing sentence stretches beyond the evidence it can support.

The refusal itself should help the reader proceed. For a real inquiry, identify the accountable school or vendor owner and use the approved private channel. For a retention decision, establish the governing instruction and the actual operator. For an access concern, state the actor category and review period. The useful output of this page is a better prepared question with fewer unnecessary disclosures, not an imitation success message suggesting work occurred behind the scenes.

Why show a product guide when live access and retention actions are unavailable here?

The difficult work includes defining the question, recognizing the evidence boundary, and preparing a responsible handoff. This guide makes that work concrete. It should never impersonate the separate authorized systems and people needed to execute a real action.

16 / A reviewable finish

Leave the next person a clear account.

A finished review should be understandable to someone who did not attend the conversations. Begin the handoff with the original question, the scoped version investigated, and the organization responsible for each part. Explain any difference between the original and investigated questions. This prevents a technically accurate narrow answer from being mistaken for a resolution of a broader concern that still matters to the school or family.

Name the evidence considered and the boundaries that affect the conclusion. For the Custodia vendor trail, keep the platform-administrator scope explicit and retain the exclusion of teachers, advisers, office staff, and other unaudited roles. Identify the period and environment supplied by the authorized operator. If the review used a summary or redacted representation, describe that fact. The next reviewer should not have to reverse-engineer the evidence's origin from its appearance.

State the conclusion in language proportionate to the evidence. “The supplied vendor evidence supports this explanation within the examined scope” leaves room for the actual boundary. “Everything is secure” does not answer the concrete question and cannot be established by a limited access review. A concise explanation can be confident about an observed fact while remaining clear about unresolved areas. Precision is more useful than a sweeping reassurance.

List remaining actions as decisions with owners. A school-side access question needs the school owner; a missing vendor explanation needs the vendor owner; a copy-handling issue needs the artifact's custodian. Give the recipient enough context to act without redistributing the full sensitive material. If a date has been agreed in the real process, carry it accurately. This page invents neither a response commitment nor an automated reminder service.

Before sharing a family-facing account, read it from the perspective of someone who does not know the platform's internal roles. Replace unexplained technical labels with a clear description of the responsible organization and activity. Keep the important exclusion. Check whether an ordinary reader might wrongly conclude that their own teachers' reads were included, that deletion occurred, or that an operator's purpose was verified solely because a name appeared in an entry.

Finally, identify where the approved review record and its evidence belong under the organization's actual handling rules. Do not leave sensitive material scattered across a presentation, a personal inbox, and an unassigned local file merely because the discussion has ended. The final product is an accountable explanation and a responsible handoff. Custodia's public workbook helps structure those outcomes while leaving live authorization, evidence retrieval, and record handling with the systems and people empowered to perform them.

What is the smallest useful result we can take away today?

Write one precise question, identify whether it concerns vendor or school access, name the owner who can supply the relevant evidence, and state the next decision. Keep sensitive references in the approved private channel. That is concrete progress even when the broader review remains open.

A useful next step

Bring a question.
Leave unnecessary data behind.

Use the review desk to identify the owner and evidence your question needs. Carry actual student references only through the approved private process. This workbook stores no case, creates no permission, and sends no inquiry.

Return to the review desk