A set of questions to walk into a vendor or compliance review already knowing what to ask about access, sharing, records, and exports. It is a planning checklist, not legal advice: district policy and counsel make the final call, but these phases keep the review concrete instead of generic.
Phase 1: access control
Ask the access questions before anyone imports a large roster: who can view a student, who can create charts, who can transfer ownership, and who can see district rollups. Confirm the answers map to role-based permissions you can actually enforce. These questions matter most early, because broad access is hard to walk back once a roster is loaded.
Phase 2: parent sharing and revocation
Review how parent links are created, what families can see in the portal, and whether teacher notes appear in family-facing views. Confirm how links are revoked and that revocation is immediate. Ask whether link activity can be reviewed. Being able to audit who has access keeps the sharing model defensible if a complaint surfaces.
Phase 3: exports and records
Clarify which artifacts (PDF progress reports, communication logs, evidence exports) become part of the student record under your district's policy. The software can support the workflow, but the district defines what counts as a record and how long it is kept. Pin this down before exports start circulating in meetings.
Phase 4: policy fit and the right people in the room
Confirm how the tool fits your district privacy policy, and bring the people who can actually judge that. Technology staff should be there for SSO, data access, and security documentation; teachers should be there so the review reflects the real classroom workflow. Treat NDPA, DPA, FERPA, and your state addendum as the floor, and remember the real value is that good daily data becomes an objective, timestamped record that holds up when a meeting turns adversarial.