Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -22,3 +22,6 @@ npm-debug.log*

# wizard scratch (generated manifests, funnel log, test CSVs)
/.wizard

# rendered forms (regenerate with npm run render:form)
/out
7 changes: 7 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -227,3 +227,10 @@ Building locally on macOS can trip the "access data from other apps" prompt;
(`modals.ts`). There is no middleware doing this centrally — anyone who can
see the alert channel can click a button, so a new handler that forgets the
check is open to the workspace. Findings name students.
- **Files are recorded as metadata, never fetched.** `record.ts` stores
`{id, name, mimetype, size}` and the bytes stay in Slack. That an image was
shared is the policy-relevant fact; the image itself is a minor's photograph,
and downloading it would put content in the team's custody that the
content-blind rules never need. Slack retention is set to keep everything, so
an investigation that genuinely needs the file gets it from Slack. Do not add
file download.
195 changes: 195 additions & 0 deletions docs/consent-form.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,195 @@
# Parental Consent — Team Communication on Slack

**Form version 2027.1 · 2027 season**
Questions, records requests, and withdrawals: **contact@redhawkrobotics.org**

<!--
Source content for the signed form. Rendered to PDF by the build; the signed
copies are filed outside this repo and referenced from consents.document_ref.
Bump the form version on any change to the substance of this document — it
is recorded with every signature so we know what each family agreed to.
Not parent-facing: keep this a comment so it never reaches the rendered form.
-->

---

## What this is

Melrose Red Hawk Robotics Educational Foundation Inc. ("the team") uses
**Slack** for team communication. Slack is the platform where team business
happens: announcements, build season planning, subteam coordination, and
scheduling. This form tells you how it works, what we record, and who can see it
— and asks your permission for your student to take part.

Please read the section titled **How direct messages are handled**. It describes
something most communication tools don't do, and we would rather you learn it
here than discover it later.

This form covers Slack only. Photo and media permissions are handled on a
separate form, and you can decline those without affecting your student's
participation.

## What we are asking you to permit

1. **Creating a Slack account for your student**, which shares their name and
email address with Slack, the company that operates the service.
2. **Recording and keeping direct messages between your student and adult
mentors**, as described below.

Both are conditions of taking part in team communication. If you would rather
not, tell us and we will arrange another way to keep your student informed.

## How direct messages are handled

_FIRST_ Youth Protection Policy prohibits one-to-one private communication
between an adult and a student. Slack does not let us switch direct messages off
at the service level we can afford, so instead of blocking them, we record them.

**What is recorded.** Every direct message between your student and an adult
mentor — in both directions — is saved to a database the team operates,
including the message text, who sent it, and when.

**What is not recorded.** Direct messages between your student and other
students are never recorded. We do not record messages in team channels beyond
what Slack itself keeps and what every member of that channel can already see.

**Who can read the recorded messages.** Two screened adults who administer the
team's Slack workspace. Nobody else — not other mentors, not the school
administrator who holds a seat in our workspace, not other parents or students.

**When they read them.** Only when there is a reason to. The system flags a
conversation automatically based on **who was in it** — for example, an adult
and a student messaging with no second adult present — and never based on
anything a message says. Nothing scans messages for content, and no
administrator browses the archive out of curiosity. A person reads a
conversation when it has been flagged, or when a specific concern has been
raised.

**What we cannot keep private.** Team mentors are mandated reporters under
Massachusetts law. If something indicates a child may be at risk of abuse or
neglect, we are required to report it to the Department of Children and
Families, regardless of this agreement.

## What is collected, and who can see it

**Slack keeps everything, for as long as our workspace exists.** That is how
Slack works, and it is true of every workspace, including all the parts nobody
on the team will ever look at. Slack stores your student's name, email address,
display name and profile photo if set; every message, file, and reaction they
post, in channels and in direct messages alike; and technical information such
as IP address, device, and timestamps. We have deliberately set our workspace to
keep edited and deleted messages as well, so that the record cannot be quietly
changed after the fact.

**On top of that, the team keeps a much smaller copy of its own.** Only these
things:

- The text and details of direct messages between your student and adult
mentors.
- A note that a file was shared in one of those conversations — its name, type,
and size. We do not keep the file. If your student sends a photo, we record
that a photo was sent, not the photo itself.
- Your student's roster information, and this consent.

That is the entire list. The team's own records contain no channel messages, no
student-to-student messages, and no files.

**Where the team's copy is stored.** On a server the team controls, hosted with
a commercial cloud provider in the United States (currently Linode), and in a
monthly archive kept in the team's own Google Drive. The same two screened
administrators control access to both.

**Who else may receive it, and when:**

- **You**, on request, for your own student.
- **_FIRST_**, in a Youth Protection investigation.
- **Melrose Public Schools**, if a concern involves a district employee or a
student-safety matter. The school administrator seated in our Slack workspace
can see the channels they join and **cannot** read recorded direct messages.
- **The Department of Children and Families or law enforcement**, as described
above.
- **A court**, if we are legally compelled.

**What we never do:** we do not use any of this for advertising, we never sell
it, we do not share it with anyone for marketing, and we do not pass team
records to the school for routine academic or disciplinary purposes.

## How long we keep it

**Slack's copy lasts as long as our workspace does.** Slack gives us no way to
remove one student's messages from it, so we cannot promise you that anything
posted on Slack is ever fully deleted. This is true of Slack generally, not of
anything particular to our team.

**The team's own copy is deleted two years after your student's last day on the
team** — both the database and the monthly archive.

## Seeing, correcting, and withdrawing

**Seeing what we have.** You may ask to see the recorded messages involving your
student at any time, by writing to contact@redhawkrobotics.org. We will respond within ten
business days. Where a conversation included other students, we will remove
their messages before sharing it — those belong to their families.

**Correcting our records.** Tell us and we will fix any error in your student's
roster information or your contact details. We cannot edit the message log
itself; it is kept unchangeable on purpose, because a record that can be edited
is not a record. If you disagree with something in it, you may give us a written
statement, which we will keep with the record and share whenever the record is
shared.

**Withdrawing consent.** You may withdraw this consent at any time in writing.
Your student's Slack account will be closed and they will no longer take part in
team communication on Slack. Messages already recorded will not be deleted —
they are kept on the schedule above and deleted with everything else. We keep
them because a record that could be erased on request could not do the job it
exists to do.

**We will ask again next year.** This consent lasts one year. We collect it
again each season rather than letting an old signature stand indefinitely.

---

## Parent or guardian

I have read this form. I understand that direct messages between my student and
adult mentors are recorded and kept, and who can read them.

I confirm that:

- I am the parent or legal guardian of the student named below.
- My student is **thirteen years of age or older**.

I permit the team to create a Slack account for my student, to share their name
and email address with Slack for that purpose, and to record and keep their
direct messages with adult mentors as described above.

| | |
| ----------------------- | --------------------------------------------- |
| Student's full name | ............................................. |
| Student's email address | ............................................. |
| Parent/guardian name | ............................................. |
| Parent/guardian email | ............................................. |
| Signature | ............................................. |
| Date | ............................................. |

## Student

I know that my direct messages with adult mentors on the team's Slack are
recorded, and that a screened adult may read them if a conversation is flagged
or if there is a concern.

| | |
| ----------------- | --------------------------------------------- |
| Student signature | ............................................. |
| Date | ............................................. |

---

<small>

**Team use only.** Filed at: ................................ ·
Recorded by: ................................ ·
Form version 2027.1

</small>
98 changes: 74 additions & 24 deletions docs/moving-team-communication-to-slack.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,24 +6,24 @@ Slack, and the policy analysis behind it. hawk-mod implements §4 and §6.
carries it, records which ones are deliberately manual, and notes two places
where later reading of the FIRST rules corrected what §3 and §7 say here.

Two caveats the original carries in a note to the board rather than in the text:
the nonprofit-pricing/educator-status tension in §5 is unresolved and worth
re-checking at renewal, and clause 1 quoted in §8 is typical language for that
policy family, **not confirmed Melrose text** — the district PDF has not been
read cleanly. If clause 1 turns out not to be in IJNDD, that whole conditional
goes away.
One caveat the original carries in a note to the board rather than in the text
still stands: the nonprofit-pricing/educator-status tension in §5 is unresolved
and worth re-checking at renewal. The other has been settled — the IJNDD clauses
§8 quoted were typical language for that policy family rather than confirmed
Melrose text, and reading the adopted policy showed they are not in it. §8 now
records what Melrose actually says.

---

**Summary:** Slack is workable for our team, legally and under FIRST policy, but only with a specific setup. This post lays out what's required, what it costs, and the one open question we need the district to answer.
**Summary:** Slack is workable for our team, legally and under FIRST policy, but only with a specific setup. This post lays out what's required, what it costs, and how the one district-policy question resolved.

---

- Slack allows students **13+** under its education terms, but only with documented **parental consent collected before students sign up**.
- Our **501(c)(3) will own the workspace**, not the school. This is what lets non-employee mentors participate — the reason we can't just use Google Classroom.
- We need the **Business+ plan** (~$2.25/user/month at the nonprofit discount) so that DMs are auditable.
- **Direct messages between mentors and students cannot be technically blocked.** We manage this with policy and real audits, not software.
- **One open item:** one of our mentors is an MPS employee and is bound by district policy IJNDD. We need written approval from the principal before launch.
- **Settled:** one of our mentors is an MPS employee and is bound by district policy IJNDD, but the text Melrose actually adopted does not bar them from an outside platform (§8). We still want written approval from the principal before launch.

---

Expand Down Expand Up @@ -106,21 +106,70 @@ Independent of everything above, and required regardless of platform:

Keep training completions filed with the consent forms.

## 8. Open item: our MPS-employee mentor

Melrose School Committee policy **IJNDD — Policy on Use of Social Media Sites** (Section I of the district policy manual) binds any MPS employee personally, as a condition of employment. It prohibits "improper fraternization with students using any social media... chat rooms, texts... or other digital means."

Policies in this family typically also contain:

1. _"All electronic contacts with students should be through the district's e-mail, computer and telephone systems, except in emergency situations."_ — **If Melrose's version contains this, our employee-mentor cannot use Slack with students at all**, no matter who owns the workspace. This clause decides the question.
2. _"Team, class, or student organization pages, accounts, or groups will be created only in conjunction with the teacher, coach or faculty advisor. All groups must include the appropriate administrator as a member."_ — This is our remedy.

**Proposed actions:**

- Read IJNDD in full and check for clause 1
- Get **written approval** from the principal or superintendent before launch — email is fine, but in writing, filed with the consents
- **Add an MPS administrator to the workspace as a member.** This satisfies clause 2 on its own terms and turns our Slack from "an outside platform an employee uses with students" into "a channel the district can see." One seat, ~$27/yr — the cheapest risk reduction in this entire plan.
- If clause 1 applies and no exception is granted, that mentor stays in mentors-only channels
## 8. Resolved: our MPS-employee mentor

Melrose School Committee policy **IJNDD — Electronic Communication/Social
Media** (Section I of the district policy manual, adopted June 12, 2018) binds
any MPS employee personally, as a condition of employment, and it does reach
Slack. Its definition of social media covers "chat, text message features of
cell phones... and other electronic or technologically based communication
systems," and clause (i) of _Professional Use_ provides that employees
"including coaches/advisors" who engage with team social media "do so as an
employee of the District." Booster club ownership of the workspace does not put
our mentor outside it.

**The clause that would have decided this against us is not in Melrose's
version.** This section originally quoted two provisions as typical of the
policy family, because the district text had not been read. Both are absent, as
is the "improper fraternization" language the section attributed to IJNDD.
Melrose adopted a locally drafted policy instead, and its operative provision on
individual contact reads:

> Educators who wish to communicate with students or families on an individual
> basis **should**: (a) use their district e-mail account or web portal accounts
> rather than alternative media, and (b) inform families which social media are
> to be used for school business.

"Should" — in a policy that says "shall not" and "must" in the clauses on either
side of it. And half (b) presupposes that non-district platforms do carry school
business, or there would be nothing to tell families about. Nothing prohibits
using an outside platform with students. **Our employee-mentor is not barred
from Slack.**

The remedy this section proposed rested on the second quoted clause — that
student-organization groups must include the appropriate administrator as a
member — which is likewise absent. Adding an MPS administrator is still worth
the $27/yr for district visibility, but as goodwill rather than as compliance
with anything written.

**What Melrose does ask of that mentor:**

- Clause (k): _"All contact and messages by coaches with team members will be
sent to all team members, except for messages concerning medical or academic
privacy matters, in which case the messages will be copied to the athletic
director and the principal."_ Team channels satisfy this. Group DMs do not —
so that mentor works in channels and does not DM students at all. That is
stricter than §4.1, and it is enforced by their obligations under the employee
manual, not by hawk-mod.
- Clauses (e)(b) and (l): parents must be told which platforms carry school
business. Fold this into the consent form, which we are writing anyway.
- **Public records.** Under **M.G.L. c. 66 §10**, IJNDD puts the retention
burden personally on the educator when school business runs through
non-district accounts, and asks them to forward such communications to their
school e-mail so it can be archived. hawk-mod covers the substance — the
messages are retained and producible via `export-conversation` — but the
forwarding expectation should be put to the principal explicitly rather than
assumed satisfied.

**Remaining actions:**

- Get **written approval** from the principal or superintendent before launch —
email is fine, but in writing, filed with the consents. The ask is now
documentation of how we comply, not a request for an exception.
- Settle how the public-records expectation is met for that mentor.
- **Add an MPS administrator to the workspace as a member.** One seat, ~$27/yr,
and it turns our Slack from "an outside platform an employee uses with
students" into "a channel the district can see."

This binds one person, not the booster club or our other mentors. It's a one-person problem with a one-person solution and doesn't threaten the plan.

Expand All @@ -129,7 +178,8 @@ This binds one person, not the booster club or our other mentors. It's a one-per
## Launch checklist

- [ ] Board votes to approve, records the DM-risk tradeoff in the minutes
- [ ] Read IJNDD; send written approval request to the principal
- [ ] Send written approval request to the principal (IJNDD read — see §8)
- [ ] Settle the M.G.L. c. 66 §10 forwarding expectation for our MPS-employee mentor
- [ ] Apply for Slack for Nonprofits (booster club, not the school)
- [ ] Upgrade to Business+; apply for Corporate Export
- [ ] Configure workspace per section 6
Expand Down
Loading
Loading