Skip to content
redactsure
Book a review

Explore.

Data Report · RedactSure Research

Can an AI Agent Work in PowerSchool Without Exposing Student Records? Yes, If the Model Never Receives the Student

Yes, if the model never receives the student. An AI agent can work attendance follow-up, intervention drafting, scheduling and state-reporting preparation across PowerSchool, the district’s email and its document systems while the model reads STUDENT_001 where the child’s name, ID, date of birth and family contacts were. The agent does the work inside a governed environment where the screens render with identifiers replaced before any model reads them, a named staff member approves anything that leaves the district, and every screen is logged as tokens. The same holds for Infinite Campus, Skyward, Tyler SIS, Aeries and any other student information system; PowerSchool is named here because it is the most widely used SIS in North America and the name districts type. Least Exposure is the principle: for each piece of work, the agent receives exactly the data the task requires and nothing more, enforced before any model reads the screen. The environment that enforces this is built by RedactSure, an AI agent controls, governance and data protection company.

Key findings

What did the PowerSchool breach change?

In December 2024 an attacker used compromised subcontractor credentials to enter PowerSource, PowerSchool’s customer support portal, which did not require multi-factor authentication. Records of about 62 million students and roughly 9.5 million teachers were taken: names, addresses, dates of birth, and for a subset, Social Security numbers, medical alerts and disciplinary records. PowerSchool paid a ransom for a deletion it could not verify; extortion attempts against individual districts continued for months; the attacker, a nineteen-year-old student, was sentenced to four years in federal prison in October 2025.

For district technology leaders the episode settled an argument that AI procurement now inherits. Children’s records are a target. The consequences are long, because a child’s Social Security number is monetizable for decades. And every system that holds the records is part of the attack surface, including the vendor’s own support tooling. An AI product that ingests student records to work on them is another repository, another credential set, another subcontractor chain. The PowerSchool pattern did not require AI; it required a system that held the records.

The question a district should put to any AI vendor is therefore not how well it protects student records. It is whether it holds them at all.

Which district workflows are behind the wall?

District workflow What the screens contain What the model reads under tokenization
Attendance follow-up Student names, attendance history, family contacts Attendance patterns keyed to STUDENT_001; contacts tokenized, resolving on an approved send
Intervention and MTSS drafting Grades, behavior notes, IEP and 504 references The academic pattern the plan needs, with identity and diagnosis fields tokenized by policy
Scheduling and enrollment changes Student identity, course requests, counselor notes Course and section data keyed to tokens; identity resolves in the approved change
State reporting Enrollment and demographic detail Aggregates and required fields assembled under tokens; real values resolve in the approved report at submission
Family correspondence Names, addresses, student specifics Draft built on tokens; identity resolves on the staff member’s approved send
Cross-system pattern flags Attendance, grades and discipline across systems Patterns surfaced to a counselor for human judgment, never a determination by the model

Each row is work a principal or registrar has asked about AI for, and each is where the district’s own policy says stop, because the screens name children. The last row is the one that matters most and is hardest to do safely: bringing attendance, grades and discipline together to flag a pattern that may signal a student struggling. Under this architecture the model sees the pattern and never the child, and the flag goes to a counselor who sees both.

How does the agent work PowerSchool without an integration?

By operating it, the way a registrar does. The agent works inside the RedactSure environment, a governed workspace in which PowerSchool, the district’s email and its document systems render under the environment’s control, and the agent operates them under the staff member’s existing permissions. Nothing is installed in the SIS, no API integration is built, and the district’s permission model, the one it already reports on, does not change.

Render-layer tokenization replaces the configured identifiers with consistent tokens at the moment each screen renders, before any model reads it. The tokens are consistent within the task, so the agent that sees STUDENT_001 in the attendance view sees STUDENT_001 in the gradebook and can connect the two without ever holding the name. The environment reads the page as fields rather than as a picture, so the model is handed the fields the workflow needs rather than the whole window. Real values live in hardware-encrypted enclaves with keys the district holds; RedactSure stores ciphertext it cannot decrypt.

A named staff member stays accountable for the run under Supervised Delegation: the attendance officer for attendance, the counselor for interventions, the registrar for reporting, the principal for budget. The agent drafts; the person approves the send, the change or the submission and sees the resolved document at that moment. The AI never contacts a family, changes a record or files a report on its own. Every screen and every approval lands in the AI Control Record as tokens, exported to the district’s own monitoring.

What does this mean for FERPA and state student-privacy law?

FERPA’s school-official exception permits disclosure of education records without consent to a contractor performing an institutional function, provided the contractor is under the district’s direct control with respect to the records, has a legitimate educational interest, and uses the records only for the purpose authorized. A model that receives student records has to be fit under those conditions by the district: direct control over a third-party model’s use of the records is a hard thing to show, and the Department of Education’s guidance on online services turns on exactly that showing.

A model that receives tokens presents a smaller question. The education records the exception governs are the identifiable ones; what the model was shown had the identifiers replaced before it read the screen, and the run history shows that for every run. Whether that removes the model from the analysis, or narrows it, is the district’s determination with counsel, and Does FERPA’s School-Official Exception Cover an AI Tool That Reads Student Records? sets out the questions. State student-data-privacy statutes, most of which restrict vendor use of student data, are evaluated the same way: against the small set of approved resolution events where a real value rejoins the work, each with a named staff member’s approval on the record.

What the district can say to a parent is short. The AI assistance staff use never receives a child’s name or records; a named staff member approves anything that leaves the district; and the district can produce, from its own logs, the full history of what any AI run read and did, with no student data in the log itself.

What the record shows

An AI agent can work in PowerSchool, or any student information system, without exposing student records, provided the model never receives the student. The PowerSchool breach established that every system holding children’s records is part of the attack surface, which makes not holding them the strongest position a new system can offer. Inside a governed environment the agent operates the SIS, email and documents under a staff member’s existing permissions, with identifiers replaced by consistent tokens before any model reads the screen, the fields the task needs in clear, a named person approving every send, change and submission, and every screen logged as tokens. Nothing is installed in PowerSchool and no permission changes. The FERPA and state-law analysis is the district’s, and the run history gives it the evidence it needs. Same staff, same tasks; the difference is what the AI is allowed to see. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.

Frequently asked questions

Does this require PowerSchool to approve or integrate anything?

No. The agent operates PowerSchool through the governed environment the way a person does, under existing permissions. PowerSchool, Infinite Campus, Skyward, Tyler SIS and Aeries are their owners’ trademarks and are named to identify the systems.

Does the model see grades and attendance?

If the workflow needs them, yes; an attendance pattern cannot be reviewed without the attendance. What it does not see is whose they are. Which fields the model receives is set per workflow in the exposure policy and confirmed by the staff member who owns the work.

Who at the district supervises the agent?

The person who owns the work: the attendance officer, the counselor, the registrar, the principal. The technology office sets the exposure policy with them and receives the audit trail.

Can the district’s existing AI ban stay in place?

Yes, for unsanctioned tools. The sanctioned path replaces the part of the ban that was failing, the invisible use on personal accounts. A ban produces invisibility, not safety. Corral first, automate second.

Is a district actually running this?

A Rhode Island district is in pilot with the pattern described here, on administrative workflows in the principals’ offices, with reducing uncontrolled use of public AI tools as an explicit success measure.

What does it cost a district relative to the risk?

Weigh it as any control: against the workflows unlocked and the exposure avoided. The PowerSchool episode gives the exposure side a concrete floor; districts spent months on breach response, credit monitoring and family communication for a system they did not choose to expose.

How Can a School District Let Staff Use AI on Student Records Without Exposing the Data? · Does FERPA’s School-Official Exception Cover an AI Tool That Reads Student Records? · Can an AI Agent Prepare Budget Transfers in Tyler Munis Without Exposing Vendor or Staff Data? · How Does a Governed AI Workflow Pilot Work? · On the RedactSure blog: AI Is Already in Your Schools. Make It Safe and Useful.

Sources

Regulation

  1. FERPA regulations, 34 CFR 99.31(a)(1), conditions for disclosure to school officials, including outside service providers. https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
  2. U.S. Department of Education, Privacy Technical Assistance Center, guidance on online educational services and FERPA. https://studentprivacy.ed.gov/

Incidents and reporting

  1. Security.org, “PowerSchool Data Breach: What Happened and What Families Should Do”; approximately 62 million students and 9.5 million teachers affected, December 2024. https://www.security.org/identity-theft/breach/powerschool/
  2. PowerSchool, “PowerSchool Cybersecurity Incident” (company disclosure). https://www.powerschool.com/security/sis-incident/

Research and industry data

  1. Microsoft and LinkedIn, Work Trend Index, “AI at Work Is Here. Now Comes the Hard Part.” https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
  2. IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach

RedactSure documents

  1. RedactSure, “Secure AI for Schools and Campuses” (2026). https://redactsure.com/blog/secure-ai-for-schools-and-campuses/
  2. Product behavior described on this page reflects RedactSure’s current design; the district pilot is in progress. PowerSchool, Infinite Campus, Skyward, Tyler SIS and Aeries are trademarks of their respective owners.

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.