Admin and IT training: system configuration, user provisioning, data import/export, security settings.
Teacher and staff training: daily workflows, attendance, grading, schedules, communications.
Student user training: basic navigation, accessing courses, submitting assignments.
Self-paced and live formats:
Self-paced e-learning modules with quizzes
Live webinars and instructor-led sessions
On-demand video tutorials and knowledge base
Training materials:
User guides and admin guides
Quick-start checklists
In-app guided tours and contextual help
Change management support:
Stakeholder workshops
Adoption coaching and pacesetter programs
Communication templates for rollout
Security Measures
Data at rest: encryption (e.g., AES-256) for databases and storage
Data in transit: TLS 1.2/1.3 for all network communication
Identity and access management:
SSO (SAML, OpenID Connect) and MFA options
Role-based access control (RBAC) and fine-grained permissions
Least privilege and separation of duties
Data residency and sovereignty:
Options for data localization by region
Clear data retention and deletion policies
Data governance:
Data lineage and provenance
Data minimization and schema governance
Compliance:
FERPA (U.S.), GDPR (EU), and other region-specific privacy requirements
Audit trails and immutable logs for security-relevant events
Security testing:
Regular vulnerability scanning and penetration testing
Third-party risk assessments and SOC 2/ISO 27001 alignment (if applicable)
Incident response:
Defined incident response plan with RACI
Notification SLAs for data breach or security incidents
Updates
Release cadence (typical)
Regular product updates: monthly or quarterly patches with bug fixes
Major releases: every 6–12 months, introducing new modules or significant features
Emergency/critical patches: as needed outside the regular cadence for zero-day vulnerabilities or critical defects
How updates are managed
Delivery model: SaaS SaaS-first with zero-installation client-side updates; on-prem/private cloud may require scheduled maintenance windows
Update channels:
In-app release notes and release dashboards
Notifications within the admin console and via email
Impact assessment:
Compatibility checks for integrations and customizations
Migration/upgrade guides and data model compatibility statements
Testing and staging:
Pre-release environments or beta programs for customers
Backward compatibility and deprecation schedules communicated in advance
Change management:
Feature flags to enable/disable new capabilities during rollout
Optional training for new features in each release cycle
Support implications:
Updated support matrices aligned to major/minor releases
End-of-life timelines for deprecated features
Data Ownership and Portability
Ownership assertion: The customer retains ownership of all data created by or uploaded to the platform (students, grades, transcripts, enrollment records, etc.).
License to use data: The vendor typically has a limited, revocable license to host and process data for the purpose of providing the service.
Data access rights:
Customer has the right to access and export their data in common, machine-readable formats.
If applicable, a data export API or regular data dumps (e.g., CSV, JSON, IMS Global formats) should be available.
Data retention on termination:
Clear policy on data retention after contract end (e.g., 30–90 days grace period for export, then deletion).
Ability to request data destruction with verifiable proof of deletion.
Data usage restrictions:
Data may not be used for marketing or training external models without explicit consent.
Prohibition on selling or sharing PII outside the scope of service delivery, unless anonymized and aggregated.
Scaling Up / Down
Scaling up (growth)
Capacity planning: Clear thresholds for when to scale (e.g., concurrent users, storage, API quota).
Pricing implications: tiered or usage-based pricing with predictable increments; potential for volume discounts.
Migration/enablement process: streamlined onboarding for additional campuses, users, modules; timeline and dependencies clearly documented.
Service levels: escalation paths and dedicated resources during scale-up (e.g., CSM, SA).
Scaling down (reduction)
Notice period: required advance notice to reduce seats, storage, or services (commonly 30–90 days).
Data retention during scale-down: policies for how long historical data remains accessible and the process to export.
Decommissioning process: orderly decommissioning of modules; impact on integrations and downstream systems.
Cost adjustments: proration or credits for unused time or seats; transition assistance if discontinuing modules.
The terms & conditions for contract renewal and cancellation
Term length: typical SaaS terms are 1–3 years with auto-renewal unless canceled.
Price adjustments: annual increases, CPI adjustments, or step-ups tied to usage or feature-set.
Renewal notice: advance notice window to opt out or renegotiate (e.g., 60–90 days before term end).
Service level alignment: renewal includes updated SLAs, support tiers, and outage credits.
Feature and roadmap disclosures: whether price includes access to upcoming features or requires separate renewals.
Voluntary termination:
Notice period and termination deadline.
Impact on access to data and the ability to export data post-termination.
Involuntary termination:
Vendor-initiated termination rights (e.g., breach of contract) and cure periods.
Data return and deletion:
Obligation to provide a final data export in a machine-readable format.
Timelines for data deletion after termination, and confirmation of deletion.
Migration assistance post-termination:
Optional paid or included services to help move to another system.
Fees on termination:
Early renewal penalties, deconversion fees, or non-cancelable commitments (if any).
Escrow and continuity options:
Availability of data escrow or service continuity arrangements in case of vendor insolvency.
Compliance
FERPA (u.S.): protection of student education records; data handling and access controls.
GDPR (EU/EEA): lawful basis for processing, data subject rights, cross-border transfers.
CCPA/CPRA (California): consumer data rights and protections where applicable.
SOC 2 Type II / ISO 27001: information security management and controls; independent audit reports.
HIPAA (if health data is involved): not typical for K-12, but relevant if health records are stored.
ISO 27001 / 27701: privacy information management and PIMS.