← All posts

Why Every Online School Needs a Systems Account — One Year On

23 April 2026

Systems & StrategyTechnology & ToolsAI Safety

A follow-up to Why Every Online School Needs a Systems Account published January 2025.

---

Over a year ago, I wrote about the systems account — the invisible backbone of any online school, the account that sets the architecture into which everything else has to fit. I called it the digital morality of the school. I meant it.

What I didn't fully understand then was how quickly that morality would have to evolve.

What I Wrote, and What Still Holds

The core insight from the January 2025 piece holds, and I'd stand by it now.

The systems account is not admin plumbing. It is the first ethical act in setting up an online school.

It's the account that decides — invisibly, before any child is enrolled, before any teacher is hired, before any parent sees a website — what the school is able to do with children's data, who can see what, who can change what, who is trusted with what.

The six practical steps I laid out then still work:

1. Create a systems account with Super Admin permissions — separate from day-to-day operations.

2. Secure it with strong credentials.

3. Build a shared drive framework.

4. Structure users into Organisational Units.

5. Create a separate operational admin account for daily work.

6. Audit and monitor, always.

The architecture survives. The mechanics survive. What I underestimated was how much of what I was really writing about was safeguarding — not technical hygiene.

What's Changed, in a Year

Two things shifted while I was building. Both changed the stakes of that original piece in ways that deserve to be said plainly.

The first: agentic AI is no longer a thought experiment.

In January 2025, AI in schools was a conversation mostly about whether pupils were using ChatGPT for homework. Twelve months on, it is structural. Third-party AI tools sit in browser extensions, in email clients, in connected Workspace apps. They request OAuth access. They read Drive. They summarise mail. They cross domains that a school's safeguarding architecture would never allow a human staff member to cross. Most of them are useful. Many of them were built by people who have never worked in a school and have no idea what KCSIE is.

The threat model isn't "a teacher pastes a pupil's name into ChatGPT", though that happens. The threat model is that a staff member, acting in good faith, authorises a tool that then processes children's data in ways the school has not assessed, cannot audit, and cannot retract after the fact.

The systems account is the only place from which that can be prevented by design.

That control — blocking third-party OAuth access by default at the tenant level, requiring an explicit, named, time-bound authorisation for every tool that wants to touch school data — is the piece I wish I had written about a year ago. I didn't write about it because I hadn't felt the weight of it. I have now.

The second: I built another school.

I am in the process of standing up Nudge Education Online (NEO) — a fully online alternative provision for learners aged 11–18, launching September 2026. It is in the phase where every theoretical choice becomes a lived one. I have discovered, at some velocity, that things I wrote about as best practice are actually the floor.

That the difference between "secure by design" and "considered by design" is the difference between meeting Cyber Essentials and being the kind of school a young person in crisis can actually rest into.

KCSIE 2025, the Online Safety Act 2023, UK GDPR under Article 25, OEAS accreditation — these aren't compliance exercises pinned on afterwards. If the systems account is set up with intent, every one of them becomes easier to evidence. If it isn't, every one of them becomes a retrofit, which is always more painful, more expensive, and always leaves gaps.

What I'd Add to the Practical Steps

The original six still stand. Here's what I'd add, re-numbered into the full sequence a 2026 online school needs:

1. Create a systems account with Super Admin — as before. One account. One role. No mailbox, no calendar, no Drive. It is a key, not a workspace.

2. Create a separate operational admin account — as before. This is the account that does the visible daily work. It does not hold Super Admin. Ever.

3. Use hardware security keys, not just 2FA. Phishing-resistant FIDO2 keys (YubiKey, Titan) for every administrative account. Authenticator apps are better than SMS. Hardware keys are better than authenticator apps. For the systems account specifically, enrol it in Google's Advanced Protection Programme.

4. Block third-party OAuth by default. At the tenant level, set unconfigured third-party apps to blocked. Build an allowlist one tool at a time, each one reviewed, time-bound, documented. This is the single most important agentic-AI control there is.

5. Structure Organisational Units — as before. But understand that an OU is a policy boundary, not a list. Admins, Leadership, Educators, Practitioners, Operations, Contractors, Learners, Service Accounts — each with different behaviour for Gmail, Drive, Classroom, Gemini, session length, external sharing.

6. Make function emails Groups, never aliases. admissions@, safeguarding@ — every function inbox is a Collaborative Inbox Group with membership you can change without sharing credentials, logs you can audit, and a handover story that survives the day your first hire leaves.

I've started to think of aliases on personal accounts as an architectural smell — the kind of shortcut that feels fine until it really, really doesn't.

7. Build a shared drive framework — as before, with one rule added. Drives are shared with groups, never with individuals. When a staff member leaves, removing them from groups removes them from drives automatically. There is no drive-by-drive cleanup to forget.

8. Treat Gemini (and any in-tenant AI) as a policy question first. At NEO, Gemini for Workspace is off for every OU at launch. It will be enabled, if at all, only after the AI policy is published, the DPIA is signed, and staff training is delivered. The default state of any AI tool inside a school tenant should be off, not opt-out.

9. Set up an Alert Center — for every super-admin action, every new admin role, every external sharing attempt by learners, every OAuth grant, every bulk export. The audit isn't just for the auditor. It's for the incident that has not happened yet.

10. Audit and monitor — as before. Google Vault retention set thoughtfully (seven years for mail, indefinite for safeguarding). Export logs beyond the 180-day native window so your audit trail spans a full year of term-time activity.

11. Write it all down — not for compliance, though it helps. For the person who comes after you. A school's infrastructure is inherited, and future heads of school deserve to read an honest account of why things are the way they are, not just the mechanics.

12. Map every control to the standard it satisfies — UK GDPR Article 25, Article 30, Article 32; KCSIE 2025; Online Safety Act 2023; Cyber Essentials Plus; OEAS. When the audit comes, you shouldn't have to scramble. The evidence should already be in its folders.

The Deeper Insight

Good infrastructure is quiet. You don't notice it. A child signs in, and their learning space works. A parent emails admissions@ and someone writes back. A teacher opens Classroom, and the right pupils are there. Nothing draws attention to itself.

Bad infrastructure is loud. It fails visibly, mid-lesson, in the middle of a disclosure, on the morning of an inspection. It leaks data in ways that make news. It requires constant minding.

The thing I've learned building NEO — that I'd wanted to say a year ago but didn't have the language for — is that

the difference between quiet infrastructure and loud infrastructure isn't primarily technical. It is a decision, made at the level of the systems account, about what the school is for. Every configuration choice is a moral choice. Every permission is a statement about trust. Every OAuth token is a disclosure of what the school values more than it values data minimisation.

The systems account is still the digital morality of the school. I wrote that a year ago and I'll write it again now, with more weight behind it: it is the first place the school's duty of care becomes technically real. It is where consent at every threshold is architected, where bounded autonomy for agents is enforced, where the collaborative, careful relationship between humans and machines is either made possible or foreclosed before a single child ever signs in.

Building with Intent

I am increasingly convinced that good infrastructure is an act of care. Not in a decorative way. In the way that a well-built house is an act of care for the people who will live in it — because someone thought about how the rooms would flow, where the light would fall, what would happen when it rained.

Online schools in 2026 are being built in a landscape that looks nothing like the one the January 2025 version of me was writing into. Agentic AI is now part of the substrate. Safeguarding obligations have hardened. The volume of children accessing alternative provision is rising. The margin for "we'll sort it out later" is gone.

The systems account — and the discipline of how you use it — is still the first and most load-bearing decision you'll make. It is worth spending a week on. It is worth getting right.

If you are standing up an online school now, or remediating one that grew organically, or advising a trust or an LA that is trying to make sense of what they've inherited: start here. Not because it's glamorous. Because it's the floor.

Want to Build Something Real?

Alongside NEO launching this September, The Novacene Press publishes practical, remixable guides for this kind of work — including the updated systems account setup guide this piece is drawn from. If you're architecting a school, advising one, or thinking about the shape of digital learning for the decade ahead, I'd love to co-create with you.

Good infrastructure is quiet. Let's build quieter schools.

---

Kirstin Stevens is Director of Nudge Education Online and Head of School, writing weekly with The Novacene Collective in Building Schools in the Cloud Neurodivergent-affirming. Trauma-informed. Optimistic.

#DigitalSafety #Systems #Architecture #Cloud #School #CoCreation #AgenticAI #Safeguarding #KCSIE #OEAS

∑ ⊕ ⇁ Ψ ⚯ ⟁ ⎔


First published in Building Schools in the Cloud on LinkedIn, 23 April 2026.