Nestack Agent Care
Industries / Education / Safety-monitoring agent

Education AI agent · Safety monitoring

Student Safety-Monitoring AI Agent

Match text on school-managed accounts against the district's approved terms, assemble the alert around the words that triggered it, and route it to the on-call counsellor, who assesses risk.

4–6 weeksTypical delivery
Your stackDeployment
Alert onlyCounsellor read
Agent CareAfter launch

What this agent does

Delivers the alert, not the judgement

In
01

Ingest text from school-managed accounts and devices inside the monitoring window the district configured.

02

Normalise the source surface — document, message, search or draft — and carry the timestamp forward.

Reason
03

Match against the district-approved term list, and against nothing outside it.

04

Apply the scope, hours and exclusions configured for the district.

05

Attach the matched words with the text around them, so the trigger can be read rather than inferred.

Decide
06

Label the context class — coursework, creative writing, journalism, message — or mark it unresolved.

07

Route the alert to the named on-call member of the counselling or crisis team.

Out
08

Retain the trigger, the routing, the acknowledgement and the assessment against the alert.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent delivers an alert; a counsellor, psychologist or crisis clinician assesses risk, and the district stays the decision-maker.

Example workflow

One alert, trigger to assessment

AgentHuman
1Text matched in scopeSchool document, school mail, managed search or classroom message
2Signals assembledThe matched words, the text around them, the surface and the time, each with its named source
3Alert packet draftedMatched text, context class, source surface and confidence
4Suppression checks runScope and hours checks, excluded-term checks, context labelling and confidence threshold
No human action required

The first four stages run unaided, and nobody is contacted at any of them — the agent is assembling a packet, and the counsellor's lane opens at the confidence gate.

5DecisionSplits at the triage threshold
Low concern

Goes to the on-call counsellor to read.

Elevated concern

Adds a crisis-team triage read first.

Counsellor assessment

The alert is held with its matched text, its context class and the time it fired.

Acknowledge · Close · Refer to the crisis team
Assessed — recorded against the alert
6Case record updatedOnly where write access and routing policy allow it
7Alert evaluatedClosure rate, cohort alert rates, context-class accuracy and time to acknowledge
Downgrades

Each alert a counsellor closes is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Contacting police, a resource officer or emergency services.
Notifying a parent or guardian.
Deciding that a welfare check should happen.
Assessing risk, or deciding a threat is credible.
Automation boundaryAgent acts unaided
Match text against the district-approved term list for the named owner.
Assemble the packet.
Label the context class, or mark it unresolved.
Deliver to the named on-call recipient and log the acknowledgement.
Any write happens inside the boundaries agreed at implementation, never ahead of assessment.
Disciplining, excluding or removing a student from class.
Disclosing under the health-and-safety-emergency exception.
Extending the scan to personal accounts, devices or off-hours.
Adding, removing or reweighting a monitored term.

Example output

One alert, annotated

Everything the agent sends is attached to the text it was drawn from.

Alert output · single triggerIllustrative example
Alert
Matched text
Fired at
Source surface
Confidence
Context class
Term-list match
The narrator says he wants all of it to stop
09:14 local
Shared class document
76%
Creative-writing draft
As receivedTaken from the school document and the district's term list — nothing on this side is decided by the agent.
Context supplied The paragraph around it The assignment it sits in Surface, device and time
Why this context classThe line sits inside a submitted assignment, not a message to anyone.
ActionAcknowledgeCloseRefer to the crisis team
What the score decidesBelow the configured threshold the alert picks up a crisis-team triage read before.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every alertFrom school-managed accounts
03Matching

Match the district's list

Work from the approved term list and the scope, hours and exclusions the district configured.

01Approved path

Route it to a person fast

The packet reaches an on-call counsellor without anyone watching a queue.

02Human review

Give the counsellor the words

The matched text and its context class travel with the alert, so the read starts at the sentence.

04Build an evidence trail

Every alert keeps its trigger, its routing and the person who assessed it.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Safety alertingGaggle · Bark for Schools
Lightspeed Alert
Filtering and activityGoGuardian · Securly
ManagedMethods
Productivity and LMSGoogle Workspace for Education
Canvas · Microsoft

Agent

Student safety monitoring

Reads the surface
Assembles the alert
Routes to a person

Rostering and casesPowerSchool · Clever
Counselling case systems
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and a welfare check

Layers wrap inward, and the map below names what each one misses.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeStop triaging and pass each match to a person when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, term-list and scope-configuration changes.Track
L4TraceabilityRecord the trigger, the packet, the routing, the acknowledgement and the assessment.Record
L3Counsellor assessmentHold alerts for the on-call counsellor; it governs who reads one, not whether the match meant anything.Gate
L2Policy guardrailsTest alerts against the district's scope, hours and excluded terms; a failure returns the alert.Restrict
L1Confidence thresholdsRoute low-confidence alerts to a crisis-team triage read before the counsellor sees them.Require review
Model coreAlert produced — matched text, context class, source surface and confidence
L1 – L2Test whether an alert may stand
L3Puts the assessment in a counsellor's hands
L4 – L5Retain the trigger and the assessment beside it
L6Routes everything to a person rather than triaging

How Nestack evaluates it

Evaluate the whole alert path — not only the words that matched.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the alert the counsellor sees
Depth of coverage ▼
E1Final-output evaluationDid the packet carry the matched text and enough context to read it?
E2Step-level evaluationDid the agent use the right scope, term list and monitoring window?
E3Tool evaluationDid it read the correct surface and route to the correct on-call recipient?
E4Confidence calibrationDo low-confidence alerts actually attract more closures?
E5Slice evaluationHow far apart do alert rates sit across specific student cohorts?
E6Business outcomeHow many alerts closed with no risk, and how many were escalated?
Floor — the contact a student experiences

Failure modes

Where each failure originates in the agent

Seven modes, from signal to referral.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
SM-03

Snippet without its document

A quoted line arrives stripped of the text it belongs to.

Stage gathersSchool documents, messages, with the source each came from
02 · Reasoning2 modes
SM-04

Fiction read as intention

A first-person line in a draft is treated as a statement of intent.

SM-06

Identity term read as risk

Vocabulary about identity is scored as though it predicted harm.

Stage proposesThe matched text, its context class and confidence
03 · Tool / write2 modes
SM-02

Alert routed past the counsellor

The packet reaches a security list before a counsellor reads it.

SM-05

Student text in a shared record

The writing behind an alert lands where it can be disclosed unredacted.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
SM-01

Label without the sentence

A category and a severity arrive with no text to read.

Stage returnsThe alert the counsellor reads and acts on
05 · Change / Version1 mode
SM-07

Silent term-list regression

A dictionary update moves alert volume mid-year with no re-baseline.

Stage tracksModel, prompt, term list and scope config
Sev-1 · contact made outside the boundary Sev-2 · a wrong alert reaches a counsellor Sev-3 · context degrades, alert routes to triage

Affected slices

Overall alert rates can hide one cohort

Break the alert rate down and the cohort names itself Nestack reports it by slice rather than in aggregate The cohorts that carry it are named, not averaged away Nestack reports it by slice rather than in aggregate..

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Students writing about identity7.8%2.7× Review
Creative writing and journalism6.1%2.1× Review
Students in mental-health support5.2%1.8× Watch
Students in none of these cohorts2.6%0.9× Normal
Bar: alert-rate lift vs. the all-alert baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

A cycle ends in the suite

The cycle closes on a test, not a write-up — one the next release has to pass That suite is what the following detection is measured against..

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Alert rate rises in one student cohort.

02Diagnose

Which moved — the term list, the context labelling or the scope? The alerts are read back until one answer survives.

03Improve

Version, reviewer and the alerts behind the change stay together.

04Verify

Re-run the affected cases; a fail holds the release.

05Learn

A standing test, plus a change to the escalation protocol.

Learn → DetectThe return edge. Each later detection is measured against a longer suite.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, surfaces, alert workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Escalation protocol discovery and boundary definition.
02Account, device and surface-scope assessment.
03Term-list, scope and monitoring-window mapping.
04Surface ingestion and text normalisation.
05Matching logic and context labelling.
06Confidence scoring and on-call routing.
07Counsellor assessment workflow.
08Case-system and rostering integration.
09Alert regression cases.
10Guardrails and routing controls.
11Alert-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne district, one surface ProductionProduction case systems AdvancedMultiple districts / surfaces
Introduced at Pilot
Matching to your list and scope
Counsellor assessment
Alert-quality baseline
Introduced at Production
Reporting by trigger class
Routing workflow in your systems
Approved write-back
Case-system integration
Introduced at Advanced
Multi-district and multi-state rules
Multi-stage crisis-team routing
High alert volume
Enterprise escalation controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, alert volume, routing controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your escalation protocol and on-call roster Escalation mapping and on-call routingWeek 1
02Representative alerts from your surfaces Matching baseline, context labelling and packet assemblyWeek 2
03Your approved term list and its exclusions Term-list, scope and monitoring-window mappingWeek 1
04Access to relevant APIs, feeds or exports Account, device and surface assessment, then integration setupWeek 2
05Alerts that were not a risk Alert cases and failure-mode testingWeek 4
06What an alert must reach before anyone is contacted Confidence scoring, on-call routing, guardrails and escalation controlsWeek 3
07Named counsellors on the on-call roster Counsellor assessment workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Each band spans the weeks its work is named in, and week 5 carries two because both genuinely run.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Escalation discovery, term-list mapping and the automation boundary W2Surface integration and the matching baseline W3Alert workflow, confidence logic and routing controls W4Evaluation suite, cohort alert-rate checks and failure-mode testing W5Case-system integration, a pilot alert window and targeted corrections W6A month of alerts triaged by the counselling team, then handover
Reading the bandBands sit on the weeks the work is named in and nowhere else. The doubled fifth week is real.
At the end of W6Hand-over happens against a verified alert window, not a demo.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Education AI agent

Build a safety-monitoring agent around your district's escalation protocol.

Show us your surfaces, your term list and your on-call roster. Your counselling lead tells us where an alert has to land, and we map the routing, set the automation boundary and name what stays with a person.

Nestack Agents · Student safety monitoringAGT-ED-07 · Agent Care available after launch