Ask most IT teams what worries them about a new system, and they’ll list the obvious things: access control, data handling, what happens if it goes down. Ask what worries them about the tools already running at their school, and the list gets longer and quieter. A shared spreadsheet nobody remembers creating. A WhatsApp group with forty parent numbers in it. A departing teacher’s personal Gmail, still full of student records eighteen months later. None of that shows up in an IT audit, because none of it was ever IT’s decision to begin with.
The system you can see is not the risk
A new, evaluated system is the one thing in this picture IT actually has visibility into. It goes through procurement. It gets a security review. Someone owns the relationship. The far bigger exposure is everything that grew up around the gaps in whatever the school was using before: the workaround spreadsheet, the parent WhatsApp group a teacher started because messaging felt too slow, the printed contact list sitting in a staff room drawer. None of it was ever approved. All of it holds real data.
The Blind Spot
You cannot secure, log, or audit a tool you don’t know exists. Every unofficial spreadsheet or group chat holding student data is a system with no owner, no access control, and no way to prove what happened if something goes wrong.
What unmanaged tools actually cost IT
- No offboarding control
When a staff member leaves, IT can revoke their login. It can’t revoke their personal WhatsApp number, and it can’t retrieve what’s sitting in their personal Gmail. Access that was never granted through a system can’t be taken back through one either. - No audit trail when something goes wrong
If a parent disputes what was said or shared, a spreadsheet or a group chat has no log, no timestamp, and no record of who saw what. A managed system does. Schooly logs every change and every access, by role, so there’s an answer when someone asks what happened. - No way to enforce a policy that isn’t visible
IT can write a data handling policy, but a policy only works on systems IT can see. Role-based access control only functions if everyone’s actually using the system it’s applied to. - No consistent security posture
A personal spreadsheet is only as secure as whoever created it. A shared account is only as secure as its weakest password. Regular security testing means nothing if half the school’s data lives outside the system being tested. - No single place to prove compliance
When a data subject request or a GDPR/LGPD query comes in, someone has to be able to say where a family’s data lives and who’s touched it. That’s a straightforward answer with one system. It’s a guessing exercise across a dozen personal tools.
Consolidating onto one IT-approved system doesn’t hand control to a vendor. It’s the only way IT gets control back from the spreadsheets and group chats that already have it. The pitch for a new system usually focuses on what it adds: faster admin, better parent engagement, fewer manual tasks. For IT, the more honest pitch is what it removes: the unmanaged, unlogged, unowned tools already holding your school’s data, whether anyone signed off on them or not.






