Meet your AI assistant
Lumen
Every AI feature in SupportStudioK12 (suggested replies, the troubleshooter,
KB drafting, change-risk assessments, exec summaries) is Lumen doing the work.
The name is Latin for light: bring clarity, help your team see what matters,
stay out of the way when you don't need the help.
The rest of this page is Lumen's operating manual: what Lumen will and won't do,
what data it can see, and the guardrails that are always on.
What AI does in SupportStudioK12
AI features are designed to save your team time, not to collect data, profile users, or build products from your information.
What AI does
- Suggests responses for techs based on similar resolved tickets in your tenant only
- Helps users troubleshoot issues before submitting a ticket
- Drafts knowledge base and documentation articles
- Assesses change risk and drafts backout plans
- Generates executive summaries from your reports
- Answers questions about how SupportStudioK12 itself works, from our own
product documentation — that mode does not read your district's
records
- If your administrator turns it on, answers questions
from your district's own data — “what happened to my
projector request?”, “what is unassigned?”, “how
do we reset the copier?”. It reads tickets, knowledge base
articles, internal Tech Docs, the change log and the incident log. It
is a separate switch, off by default, and you can decline it while
keeping every other AI feature.
Each person only gets answers from records they could already
open themselves, using the same permission rules as the rest of
the product: Tech Docs and changes only for technicians and
administrators, incidents only for administrators, security staff and
auditors. Internal notes are included only for people who can already
read them. The matching text is sent to the AI provider to answer the
question — ticket subjects, descriptions and replies, article
text, change records, and an incident's title, description, affected
systems and resolution. Tech Docs are sent as written,
so anything a team has stored in them travels with the answer.
An incident's reporter is not named. The name of the staff member a ticket is
assigned to is sent, so questions like “how many open
tickets does our network admin have?” can be answered;
the name of the person who submitted a ticket is never
sent, because students can submit tickets here. It can read
and explain; it cannot assign, close or reply to anything.
- Powers smart search with synonym matching (no AI call, just smarter search)
What AI does NOT do
- We do not train any AI model on your data, ever
- We do not share your data with other tenants or organizations
- We do not store AI conversations beyond the immediate
request. One narrow exception, spelled out because it is an exception:
when you ask Lumen a question about the product and Lumen cannot answer
it, we keep that question so we know which guide to write. We keep the
question and your district, never your name, and never the questions
Lumen could answer.
- We do keep one record about the District data mode, and
it is deliberately not the conversation. When the assistant
answers from your district's data we log which tickets, articles,
change records and incidents were shown, to whom,
when, and whether internal notes were included — so your district
can audit what the assistant disclosed. The question and the
answer are not stored. It is your record, kept with your data,
included in your export and deleted with your district. We do not
analyse it.
- We do not send student PII to AI: only ticket subjects, descriptions, and staff-authored content such as articles, change records and incident descriptions
- We do not make automated decisions; AI suggests, humans decide
- We do not use AI for surveillance, profiling, or behavioral analysis
How it works technically
By default, AI features use OpenAI's GPT-4o mini via their API. Per OpenAI's
Enterprise Privacy policy,
API data is not used to train their models and is not retained beyond 30 days.
Your data stays in your tenant's database. AI calls include only the minimum context needed for the specific task
(e.g., a ticket subject and description), never bulk data exports, never user directories, never student records.
Bring your own API key (optional)
You don't have to bring anything. AI features work out of the box on every plan using our platform key; zero configuration required. BYOK exists for districts that prefer the AI spend on their own account.
When you do want it, any district can route AI calls to its own account: OpenAI, Google Gemini, Azure OpenAI,
or any OpenAI-compatible endpoint (self-hosted vLLM, Together, Groq, Ollama). Configure it once in
Admin > Integrations > AI Provider: paste a key, pick a model, done.
When a tenant has its own key configured, every AI call for that tenant bills to that account and never touches
our platform key. Districts already procuring AI through Google Cloud or Azure can keep that relationship intact, with no new vendor review, no new data processing agreement to negotiate, no new subprocessor to disclose.
Remove the key at any time to go back to the platform default; AI keeps working without interruption.
Keys are stored encrypted at rest (Fernet / AES-128-CBC + HMAC-SHA256) in the tenant's row, not in environment
variables or logs.
Per-tenant AI customization
Each district can provide custom context about their environment (device types, software stack, network vendor, etc.)
through Admin > AI Protocols. This context is included in AI prompts so responses are tailored to your specific
district: a Chromebook district gets different troubleshooting steps than a MacBook district.
This custom context is stored in your tenant's database and is never shared with other tenants or used outside of
your AI requests.
You're in control
AI features can be enabled or disabled per tenant at any time through Admin > AI Protocols.
When disabled, all AI-powered features are hidden and no API calls are made. The help desk,
knowledge base, documentation, and change tracking all work fully without AI.
Questions about our AI policy? We're happy to discuss it.
This policy was written to be understood, not to protect us from you.
Back to SupportStudioK12