AI agents for education

Admissions, advising, and aid — with student records that stay protected.

Education agents triage applications, answer student questions, and support financial-aid teams — under FERPA-shaped permissions where protected fields stay locked, aid decisions pend for human sign-off, and every answer cites its source.

Aligned with FERPA · COPPA · GDPR · SOC 2

Object Explorer
filestriggershas · restrictedStudentobjectApplicationobjectCourseobjectstudent_ssnread denied
ontology ▸ education · published · object · property · action permissions
The regulatory pressure

Student records are a protected class — an agent must treat them that way.

FERPA makes education records federally protected, COPPA raises the bar for minors, and a financial-aid decision is a life-changing outcome no institution wants an unsupervised model making. Cortex locks protected fields at the property level, gates aid actions behind human approval, and grounds every advising answer to a citable source.

FERPACOPPAGDPRSOC 2Title IVNIST AI RMF
Regulatory pressure
FERPACOPPAGDPRSOC 2Title IVNIST AI RMF
Typed objectsStudent · Application · Course · AidPackage · Transcript
Restrictedstudent_ssn / disability_statuslocked
frameworks ▸ encoded as policy · gated · sealed
Use cases

From the admissions office to the registrar, governed end to end.

The catalog ships 12 education roles × 18 agent patterns — admissions, advising, aid, registrar, enrollment analytics — on the systems campuses already run.

Admissions triage
  • Classifies and routes applications with explained rankings — ambiguous files flag for a human reader, and every disposition is recorded with its reasons.
  • Classification + audit
Student advising
  • Answers program and policy questions grounded in the catalog with citations — while disability status, SSNs, and protected fields stay locked away from the model.
  • Ontology permissions
Financial aid
  • Assembles aid packages and eligibility checks where every disbursement action pends for a human aid officer — the agent prepares, the officer decides.
  • Oversight modes
Registrar & records
  • Processes transcript and enrollment requests against typed Student objects, with property-level permissions enforcing who sees what — agent included.
  • Trust Ledger
Enrollment analytics
  • Forecasts enrollment and yield under hard budget caps, on de-identified views the ontology carves out for analytics.
  • Cost governance
FERPA-shaped permissions

The advisor-bot reads the course plan — never the disability file.

Permissions live on the ontology, not in the prompt. An advising agent reads Course and Plan objects but a read on disability_status or student_ssn returns a 403 before any model runs. Aid disbursements pend for the aid officer, and every advising answer carries its citation into the ledger.

  • Protected fields locked deny-by-default (403 on read)
  • Aid disbursements pend for human approval — always
  • Every advising answer grounded and cited, sealed in the ledger
  • Analytics run on de-identified views under hard budget caps
Object Explorer
filestriggershas · restrictedStudentobjectApplicationobjectCourseobjectstudent_ssnread denied
ontology ▸ education · published · object · property · action permissions
Prove it — don't just claim it

The verdicts a registrar and an auditor will see.

Literal runtime responses — student-record access fails closed.

runtime · verdicts
Aid disbursementlife-changing action · pendsHOLD · approval
student_ssn readFERPA-protected property403 denied
Analytics overspendprojected > 30-day cap402 budget
Advising answergrounded · cited · sealed200 sealed
fail-closed ▸ challenge it and it denies, on the record
  1. 01

    Model the domain

    Map the work to typed ontology objects — Student, Application, Course, AidPackage, Transcript — with restricted fields like student_ssn / disability_status locked at the property level.

  2. 02

    Encode the rules

    Translate the obligations above into Policy-as-Code and Action Fabric approvals — the gates fail closed, returning a precise code, not a guess.

  3. 03

    Prove the outcome

    Every run lands in a hash-chained Trust Ledger with signed receipts and 10-hop provenance — a record you can hand the regulator.

100%Aid actions held for human sign-off
8 gatesOn every student-facing run
10-hopProvenance on every decision
5 modesAutonomy tuned per agent and action
Security & compliance

Built for the floor FERPA sets — and the trust students expect.

Property-level record permissions, human-approved aid actions, DLP on every conversation, and a sealed audit trail are shared across admissions, advising, and the registrar — mapped once to FERPA and Title IV obligations. Aligned with, never claiming a certification you don't hold.

FERPA · recordsCOPPA · minorsTitle IV · aidGDPR · intl studentsSOC 2 · auditNIST AI RMF · Manage
FAQ

AI agents for education — questions, answered.

Is Cortex FERPA compliant for student records?

Cortex is built to align with FERPA: education-record fields are locked at the ontology property level, access is logged in a tamper-evident ledger, and protected reads return a 403 before a model is invoked. Alignment is enforced by the runtime — certification claims are never made on your behalf.

Can an AI agent make financial-aid decisions?

No — aid disbursements and package changes always pend for a human aid officer under oversight modes. The agent assembles eligibility, drafts the package, and prepares the file; the officer decides, and the ledger records both halves.

How do advising agents avoid seeing sensitive student data?

Permissions live on the data, not in the prompt: an advising agent reads Course and Plan objects, while disability status, SSNs, and other protected properties are deny-by-default. There is no prompt-engineering way around a 403.

What education agents are in the library?

Twelve education roles — admissions counselor, registrar, academic advisor, financial aid officer, enrollment analyst, student services and more — each in 18 agent patterns, wired for systems like Banner, Canvas, Workday Student, Blackboard, and Salesforce Education Cloud.

More industries

One governed runtime, every regulated vertical.

The controls are the same — the obligations they satisfy differ. Explore another vertical, or see the full set.

Help every student faster — and protect every record.

See FERPA-shaped permissions, human-approved aid actions, and cited advising answers on your own student systems.