Trusted Portable Learning Context

Why It Matters for Institutions and Policymakers

 

A 1EdTech companion to the "Principles of a Trusted Portable Learning Context" Request for Comment (RFC). Where the RFC sets out the architecture, this brief speaks to the institutional and policy stakes that architecture is meant to serve.

 

 

What This Is About

Increasingly, agents intervene in students’ education. They might recommend what to study next, draft instruction, flag who needs help, or advise on a pathway. That agent is now often artificial, but the word covers the human case just as well. A tutor, an advisor, a teacher all act as agents in a student's learning. When any agent acts in a student's education, three questions follow that every educator, administrator, and policymaker already knows how to ask about a human being who does the same work:

  • Does it know enough about this student to help them well? 
  • Is it prevented from seeing what it has no business seeing? 
  • Can anyone tell, afterward, that both of those things were true?

The wrinkle AI brings is the need to trust a different kind of agent, one that isn’t human. AIs are often owned by different parties that we may trust differently, act more or less reliably in ways that affect our trust of them, and may pass on context to other agents who we don’t know about. An AI “agent” doesn’t just answer questions; it acts, often in concert with other agents. Trust now needs to be auditable and portable.  

Trusted portable learning context (tplc) is a set of principles for edtech systems to ensure that responsible parties can readily answer those three questions about any context that is released in service of supporting a learning moment. It is designed to express educational policy about who may see what, for what purpose, and then enforce that policy in the software that moves a student's context from one place to another. The Trusted Portable Learning Context Request For Comment (RFC) describes how such an artifact is assembled and what the systems that produce it must commit to. This brief explains why those commitments are right and what is at stake in getting them right.

The principles of tplc are independent of any particular software, and independent of 1EdTech. The name is in lowercase deliberately; tplc is a set of high-level patterns that could be implemented in standards and products, not something 1EdTech seeks to own in itself. We invite the educational community writ large to discuss, refine, and hopefully adopt these principles wherever they are useful, across future implementations by 1EdTech or others. Patterns whose purpose is to carry policy that communities set for themselves cannot, in good faith, be anyone's private property.

 

 

Two Duties That Meet at a Boundary

It is tempting to treat student data protection as a matter of holding a wall as high as possible by sharing as little as possible, as rarely as possible. Whenever a student's context crosses from one responsible party to another, two responsibilities of care are in play at once. There is the responsibility to protect: Keep private what should stay private, and release nothing the situation does not warrant. And there is the duty to provide: Give whoever is now helping the student enough information to actually help. 

Both duties in concert serve the student. Neglecting either fails the student in different ways. When context is insufficient, the agent may refuse when it should help, give a generic answer that is wrong for this particular learner, or invent a confident answer with no grounding in anything real. These are not defects peculiar to machines. They are what anyone does when asked to act in a student's education without being told enough, like a substitute teacher handed a class with no notes, an advisor meeting a transfer student with no record, or a tutor who has never met the child. Too little context is its own way of failing a learner. It renders the students themselves unseen, generalized, or guessed at. At the same time, agents receiving context are entrusted with information about human beings we have committed to protect. The agents should receive the minimum needed to perform the job they are entrusted with. 

Seen this way, an enforceable, auditable release policy is what makes sharing learning context safe. When the party responsible for a trust boundary can trust that what the software releases is exactly what policy permits and no more, they can share what genuinely serves the student with confidence rather than withholding out of fear. Enforceability is enabling.

________________________________________________________

Who Is Responsible for a Boundary and Who Decides

Two distinct kinds of policies are relevant for ensuring that learning context can be safely shared. The first is the purely human kind. It is the layered authority of federal law, state or provincial law, institutional rules, and accreditor requirements that determines who is responsible for a given trust boundary. The second is the technical kind. It is the set of concrete rules, readable by software, that enforce decisions about what may be released, to whom, for what purpose. The technical policy enforces the rules that the human policy requires.

When these policies are decoupled, trust boundaries become dangerously unclear. Picture a product sold directly to an individual teacher, advertised as aligned with a privacy regulation that in fact binds the institution. To make the arrangement work, the product asks the teacher to prove their own authority by uploading personal documents, and then to upload protected student records. In this scenario, context that should remain private must be shared to validate the individual’s authority, while context that is needed for learning may not be shared because it is manually entered. Worse, these failures are invisible and untraceable. Once context has been handed over to the AI, there is no record of what was shared, why, and how it is separate from whatever the AI did with it. 

Trusted portable learning context prevents this. An AI agent would query the institutional system: “This is what I would like to know to serve this learning moment.” The institutional system replies: “This is what you may and may not know, according to the enforced policy.” Humans make that policy. A tplc-enabled system makes policy enforcement legible, enforceable, auditable, and faithful to its educational intent as context crosses the boundary. 

________________________________________________________

What the Properties Protect, and for Whom

The RFC describes six properties a tplc-producing service would commit to. They divide cleanly along the two duties of protecting and providing context.

Three principles serve the duty to protect. Consent decides what may be released for the purpose at hand. Sovereignty ensures the party that policy makes responsible is the one that enforces release, at the source, rather than handing that decision to a downstream vendor or model. Provenance lets a recipient verify who assembled a collection of context, under which policy, and when.

The other three principles serve the duty to provide. Realtime assembly means the context reflects the student's situation now, not last night's snapshot. Querying means whoever needs context can efficiently ask for everything the situation requires rather than accepting a fixed payload. Composition means the fragments of a student's situation, scattered across many systems, come together into one coherent picture instead of a per-system fragment.

________________________________________________________

Added Benefits

In addition to addressing the central challenge of sharing all and only the right learning context with AI agents, tplc offers other benefits:

  • Tracking learning progress: A packaged bundle of learning context can include evidence of learning progress. One learning moment enables the next. Agents can reason about how to support a particular learning moment based on the arc of progress. A signed and auditable package of learning progress evidence may be useful well beyond the release of institutionally created context to a single agent. Different agents and institutions can provide evidence of continued learning progress, each of which remains distinct, separable, and auditable. 
     
  • Containing costs: AI agents often ask for many pieces of data to stitch together context. When these are requested one piece at a time, cost balloons. When multiple agents do the same thing, cost explodes. The principles of querying and composition enable agents to ask one question and get one answer, dramatically reducing costs.
     
  • Promoting equity: A world in which educational quality is cost-driven is an inequitable world. Policy-driven trust boundaries support institutions making calibrated decisions that match model capabilities with educational needs and affordability. 
     
  • Managing “bring-your-own AI”: Different institutions may have different policies about students using their own AIs. Those policies should be enforceable at a more detailed level than “yes/no”. Policy enforcement that can recognize different classes of agents enables different organizations to create policies that suit the particular needs of the people they serve.

________________________________________________________

The Invitation

None of this is settled. 1EdTech is releasing these principles in the form of a Request for Comment so that the educational community can grapple with them and refine them together. 

For institutional leaders and for policymakers, the stakes are direct. The balance between protecting students and serving them—a balance that will be struck in policy, and then carried by machinery like this—is being set right now. The configuration that will govern your institution, your jurisdiction, and your students gets shaped by whoever shows up to shape it. If the people who carry responsibility for students are not in the room, the answers will be set without them.

1EdTech is asking members of the educational community to review the Trusted Portable Learning Context Request for Comments document and join the discussion to help us answer those questions and determine the best course of action to meet those needs together.

Anyone interested in hosting a larger discussion or convening around the trusted portable learning context, please contact support@1edtech.org