Match text on school-managed accounts against the district's approved terms, assemble the alert around the words that triggered it, and route it to the on-call counsellor, who assesses risk.
Ingest text from school-managed accounts and devices inside the monitoring window the district configured.
02
Normalise the source surface — document, message, search or draft — and carry the timestamp forward.
Reason
03
Match against the district-approved term list, and against nothing outside it.
04
Apply the scope, hours and exclusions configured for the district.
05
Attach the matched words with the text around them, so the trigger can be read rather than inferred.
Decide
06
Label the context class — coursework, creative writing, journalism, message — or mark it unresolved.
07
Route the alert to the named on-call member of the counselling or crisis team.
Out
08
Retain the trigger, the routing, the acknowledgement and the assessment against the alert.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent delivers an alert; a counsellor, psychologist or crisis clinician assesses risk, and the district stays the decision-maker.
Example workflow
One alert, trigger to assessment
AgentHuman
1Text matched in scopeSchool document, school mail, managed search or classroom message
2Signals assembledThe matched words, the text around them, the surface and the time, each with its named source
3Alert packet draftedMatched text, context class, source surface and confidence
4Suppression checks runScope and hours checks, excluded-term checks, context labelling and confidence threshold
No human action required
The first four stages run unaided, and nobody is contacted at any of them — the agent is assembling a packet, and the counsellor's lane opens at the confidence gate.
5DecisionSplits at the triage threshold
Low concern
Goes to the on-call counsellor to read.
Elevated concern
Adds a crisis-team triage read first.
Counsellor assessment
The alert is held with its matched text, its context class and the time it fired.
Acknowledge · Close · Refer to the crisis team
Assessed — recorded against the alert▼
6Case record updatedOnly where write access and routing policy allow it
7Alert evaluatedClosure rate, cohort alert rates, context-class accuracy and time to acknowledge
Downgrades
Each alert a counsellor closes is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Contacting police, a resource officer or emergency services.
Notifying a parent or guardian.
Deciding that a welfare check should happen.
Assessing risk, or deciding a threat is credible.
Automation boundaryAgent acts unaided
✓Match text against the district-approved term list for the named owner.
✓Assemble the packet.
✓Label the context class, or mark it unresolved.
✓Deliver to the named on-call recipient and log the acknowledgement.
Any write happens inside the boundaries agreed at implementation, never ahead of assessment.
Disciplining, excluding or removing a student from class.
Disclosing under the health-and-safety-emergency exception.
Extending the scan to personal accounts, devices or off-hours.
Adding, removing or reweighting a monitored term.
Example output
One alert, annotated
Everything the agent sends is attached to the text it was drawn from.
Alert output · single triggerIllustrative example
Alert
Matched text
Fired at
Source surface
Confidence
Context class
Term-list match
The narrator says he wants all of it to stop
09:14 local
Shared class document
76%
Creative-writing draft
As receivedTaken from the school document and the district's term list — nothing on this side is decided by the agent.
Context suppliedThe paragraph around itThe assignment it sits inSurface, device and time
Why this context classThe line sits inside a submitted assignment, not a message to anyone.
ActionAcknowledgeCloseRefer to the crisis team
What the score decidesBelow the configured threshold the alert picks up a crisis-team triage read before.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every alertFrom school-managed accounts
03Matching
Match the district's list
Work from the approved term list and the scope, hours and exclusions the district configured.
01Approved path
Route it to a person fast
The packet reaches an on-call counsellor without anyone watching a queue.
02Human review
Give the counsellor the words
The matched text and its context class travel with the alert, so the read starts at the sentence.
04Build an evidence trail
Every alert keeps its trigger, its routing and the person who assessed it.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Safety alertingGaggle · Bark for Schools Lightspeed Alert
Filtering and activityGoGuardian · Securly ManagedMethods
Productivity and LMSGoogle Workspace for Education Canvas · Microsoft
Agent
Student safety monitoring
Reads the surface Assembles the alert Routes to a person
Rostering and casesPowerSchool · Clever Counselling case systems
Break the alert rate down and the cohort names itself Nestack reports it by slice rather than in aggregate The cohorts that carry it are named, not averaged away Nestack reports it by slice rather than in aggregate..
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Students writing about identity
7.8%
2.7×
Review
Creative writing and journalism
6.1%
2.1×
Review
Students in mental-health support
5.2%
1.8×
Watch
Students in none of these cohorts
2.6%
0.9×
Normal
Bar: alert-rate lift vs. the all-alert baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
A cycle ends in the suite
The cycle closes on a test, not a write-up — one the next release has to pass That suite is what the following detection is measured against..
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Alert rate rises in one student cohort.
02Diagnose
Which moved — the term list, the context labelling or the scope? The alerts are read back until one answer survives.
03Improve
Version, reviewer and the alerts behind the change stay together.
04Verify
Re-run the affected cases; a fail holds the release.
05Learn
A standing test, plus a change to the escalation protocol.
Learn → DetectThe return edge. Each later detection is measured against a longer suite.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, surfaces, alert workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Escalation protocol discovery and boundary definition.
02Account, device and surface-scope assessment.
03Term-list, scope and monitoring-window mapping.
04Surface ingestion and text normalisation.
05Matching logic and context labelling.
06Confidence scoring and on-call routing.
07Counsellor assessment workflow.
08Case-system and rostering integration.
09Alert regression cases.
10Guardrails and routing controls.
11Alert-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne district, one surfaceProductionProduction case systemsAdvancedMultiple districts / surfaces
Introduced at Pilot
Matching to your list and scope✓✓✓
Counsellor assessment✓✓✓
Alert-quality baseline✓✓✓
Introduced at Production
Reporting by trigger class—✓✓
Routing workflow in your systems—✓✓
Approved write-back—✓✓
Case-system integration—✓✓
Introduced at Advanced
Multi-district and multi-state rules——✓
Multi-stage crisis-team routing——✓
High alert volume——✓
Enterprise escalation controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, alert volume, routing controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your escalation protocol and on-call roster→Escalation mapping and on-call routingWeek 1
02Representative alerts from your surfaces→Matching baseline, context labelling and packet assemblyWeek 2
03Your approved term list and its exclusions→Term-list, scope and monitoring-window mappingWeek 1
04Access to relevant APIs, feeds or exports→Account, device and surface assessment, then integration setupWeek 2
05Alerts that were not a risk→Alert cases and failure-mode testingWeek 4
06What an alert must reach before anyone is contacted→Confidence scoring, on-call routing, guardrails and escalation controlsWeek 3
07Named counsellors on the on-call roster→Counsellor assessment workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Each band spans the weeks its work is named in, and week 5 carries two because both genuinely run.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Escalation discovery, term-list mapping and the automation boundaryW2Surface integration and the matching baselineW3Alert workflow, confidence logic and routing controlsW4Evaluation suite, cohort alert-rate checks and failure-mode testingW5Case-system integration, a pilot alert window and targeted correctionsW6A month of alerts triaged by the counselling team, then handover
Reading the bandBands sit on the weeks the work is named in and nowhere else. The doubled fifth week is real.
At the end of W6Hand-over happens against a verified alert window, not a demo.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Education AI agent
Build a safety-monitoring agent around your district's escalation protocol.
Show us your surfaces, your term list and your on-call roster. Your counselling lead tells us where an alert has to land, and we map the routing, set the automation boundary and name what stays with a person.