Security & IT
What an RFP should say about implementation, security, and multi-campus operations
A practical guide to what an RFP should say about school software implementation, with clear owners, evidence, exceptions, and review points.
Describe the implementation problem
An implementation RFP should state the school outcomes sought: accurate records, safer access, reliable integrations, faster reporting, stronger recovery, lower manual work, consistent campus operations, or better support.
Define identity, students, staff, households, campuses, devices, workflows, integrations, local requirements, security, privacy, records, safeguarding, accessibility, internal capacity, timeline, fallback, and exit.
Require observable behaviour
Ask vendors to demonstrate new user, offboarding, transferred student, changed role, duplicate record, failed sync, lost device, phishing report, outage, restore, export, and urgent safeguarding or privacy escalation.
Record expected and observed result, permission, audit, alert, support response, recovery, manual work, limitation, configuration, dependency, evidence date, and acceptance test.
Specify responsibility and lifecycle
Request ownership for discovery, data cleaning, migration, configuration, integrations, security, training, support, accessibility, privacy, records, safeguarding, backup, recovery, campus variation, incidents, renewal, data return, deletion, and exit.
Separate supplier capability from school responsibility for local policy, data quality, professional judgement, qualified review, and safe operation.
Make scoring fair
Publish criteria, weights, evidence requirements, assumptions, limitations, conflicts, implementation capacity, fallback, acceptance tests, owner, approval, and review date.
At 30, 60, and 90 days compare actual cost, adoption, data quality, access exceptions, failed integrations, incidents, recovery, support, campus variation, manual work, and outcome.
Make the next implementation step testable
Use this guidance to improve one bounded part of what an RFP should say about school software implementation. Name the owner, implementation record, evidence, correction route, support path, and review date so staff can apply it consistently.
Check ordinary work and one meaningful exception. If either depends on undocumented knowledge, add the missing definition, validation rule, permission, approval, accessible instruction, security control, or escalation route.
Record what changed, what remains manual, and who reviews the result before the next implementation, campus, security, support, or reporting cycle.
Keep the decision beside its evidence so the next implementation colleague can understand the rule without relying on informal memory.
Use the review to decide whether the change should be expanded, repaired, narrowed, consolidated, or held.
Recheck the boundary when a user, campus, device, integration, calendar, report, supplier, or local requirement changes.

