Across campuses
Sorted by how far it reaches, because scope is your daily question
A single school thinks about who can open something. A network thinks about how far it travels: one campus, the whole network, or outside it entirely. The second filter is the one only a publicly funded school needs. Every choice is an ordinary link, so this works with nothing switched on.
Narrow it
How far it reaches
What kind of record it is
Showing 6 of 6.
- Working
One campus cannot read another
The daily fact of a multi-campus operator, and the wall that has to hold without anybody thinking about it.
Who it reaches. Campus staff see their campus. Network staff see what their role permits across the campuses they are responsible for. Those are different permissions rather than one permission with a wider label.
- Working
The network view
What an operations lead actually needs, which is rarely photographs of children.
Who it reaches. Network operations, by role. It is worth designing your roles so that the person doing this job does not need to see student imagery to do it, because the least risky access is the access nobody needed.
- Working
Reporting to your authoriser
The obligation nobody else in this family has, on a schedule you do not set.
Who it reaches. Outside your network entirely, which puts it in the highest-care category by default. Anything leaving for an authoriser should be assembled deliberately rather than exported.
- Your call, not ours
A public-records request
The question a private school never faces, and the one this site exists to raise.
Who it reaches. Potentially anybody, which is precisely why it belongs on a product page rather than in a footnote. A request that arrives with a deadline is not the moment to be forming a position for the first time.
- Working
Your own family-facing agreement
Your document, not a district's, and frequently the same one across every campus.
Who it reaches. Each campus, for its own students, from one network-level document. The permission itself is held per student, defaults closed, and is consulted at the moment of use rather than remembered from signing.
- Closed by the age floor
Enrolment marketing
Charters recruit, which makes this a live problem rather than a theoretical one.
Who it reaches. Nobody, outward, for students under the floor. Your campuses, your classrooms in use, student work without a name, and staff with their own agreement are all available and are what a serious enrolment collection is actually made of.
The network view
- What it is
- The network-level question is almost never “show me the students”. It is whether every campus ran its picture day, how many students are still unphotographed in week six, and which campus has a permission-collection problem. Those are counts and states rather than imagery, and they can be answered without anybody at the central office opening a photograph at all.
- Who it reaches
- Network operations, by role. It is worth designing your roles so that the person doing this job does not need to see student imagery to do it, because the least risky access is the access nobody needed.
- Where it stops
- A network dashboard that quietly grants image access to everybody at the central office is the most common way a multi-campus operator ends up with more exposure than a single school. Worth checking what your current systems actually permit.
The design question worth asking about your own roles
Filter for the whole network and you get one entry, and it is deliberately the least imagery-heavy thing on the list.
The network-level job is almost never “show me the students”. It is whether every campus ran its picture day, how many students are still unphotographed in week six, and which campus has a permission-collection problem. Those are counts and states. They can be answered without anybody at the central office opening a single photograph.
So the question worth putting to your own systems is not what they permit, it is what they grant by default. A network dashboard that quietly gives every central-office account image access across all campuses is the most common way a multi-campus operator ends up with wider exposure than any of its individual schools would have on its own. Most operators have never checked.
The least risky access is the access nobody needed. That is not a feature we sell you; it is a role design you do, and it is worth an afternoon regardless of what software you end up with.
Why the record-type filter exists at all
Because a privately funded school never has to categorise its material this way, and you do.
A student’s own education record and an operational record of the school are different things with different rules attached, and imagery can be either depending on what it is and why it was made. A photograph attached to a student’s record is one thing; a photograph of a classroom in use, taken to document that a programme exists, is another.
The third category is the honest one: genuinely unsettled. Whether a photograph of an identifiable student is reachable by a public-records request varies by state, by material and by the specific request. We have given it its own value in the filter rather than quietly sorting it into one of the other two, because a product that resolved that ambiguity on your behalf would be making a legal judgement it has no standing to make.
What we will say is the operational half. Holding imagery as records with permissions attached is what lets you answer such a request precisely. The alternative — producing a folder against a statutory deadline — is a much worse position, and which one you are in is decided long before any request arrives.
What this list is not
It is our description of our own capability. There are no students’ photographs on this site, no example records, no sample rosters and nothing resembling any real child’s data. Nothing typed into the address bar reaches what you are reading.
A demonstration against your own network is a different thing: real setup work, after a conversation with a person, never before.