One Student, Thirteen Years: A Day-by-Day Look at Life Under School Contact and College Contact

Policy proposals are easiest to argue about in the abstract and hardest to actually picture. So instead of another paragraph about architecture, here’s one student’s identity, followed from her first day of first grade to her first semester of college — under the School Contact and College Contact frameworks, as proposed. Every mechanic described below is drawn directly from the two initiatives’ published white papers and FAQs; nothing here is a live system, and no part of it exists today. It’s a walkthrough of how the proposal is designed to work, not a report of how it does work.

Meet Maya.

Kindergarten Registration Day

Maya’s mother sits down at an enrollment kiosk with her own phone in hand. She enters her mobile number, (619) 555-0192; a one-time code arrives by text; she types it in. That single step activates her verified identity as Maya’s parent — 6195550192@parent.email. She didn’t create an account or memorize anything new. The number she’s had for years just became her school identity, linked to Maya’s record. This is the Bring-Your-Own-Device/Number model the framework proposes for parents specifically: no new identifier issued, no new number consumed from the national pool.

Behind the scenes, Maya is assigned her own number for the first time: a 10-digit identifier drawn from one of four reserved student pools (444, 555, 777, or 999 — together sized for roughly 80 million identities, enough for the country’s entire K–12 population with room to spare). Maya’s happens to be 4448587392. Her first address is 4448587392@elementaryschool.email.

First Grade

Maya’s teacher, Mr. Alvarez, sends the class’s first newsletter home from 2220684592@teachers.email — spoken aloud, if you had to say it to a voice assistant, as “two-two-two, zero-six-eight, four-five-nine-two, at teachers dot email.” The number is built to be unambiguous out loud: no confusion between the character “5” and the spoken word “five,” which matters as much for a voice-controlled classroom device as it does for a parent with a visual impairment managing the account by ear. Behind that short public alias sits a longer administrative address — something like 2220684592@sandiego.california.teachers.email — built from Mr. Alvarez’s state credential number, his role, and his location. Parents never see it. It exists purely for logging, authentication, and oversight, and because it’s never exposed in ordinary conversation, there’s less surface area for anyone to spoof.

Third Grade: A Phishing Attempt That Goes Nowhere

One afternoon, a message arrives in the school’s system claiming to be from the front office: early dismissal today, please arrange pickup by noon. It’s addressed as if from 111 — the range reserved for institutions and agencies. But when the system checks the sender against the national registry, there’s no matching active account behind it. The message never reaches a parent’s inbox. It’s flagged and quarantined at the delivery layer, before anyone has to notice something looked slightly off. This is the specific failure mode the framework is built to close: today, an attacker exploiting a fragmented, unverified landscape can impersonate a school with very little friction. Under School Contact, impersonation fails authentication before it ever becomes a judgment call for a busy parent scanning their inbox.

Sixth Grade: Middle School, Same Number

Maya starts middle school. Her number doesn’t change — it’s still 4448587392. Only the domain updates, automatically, to 4448587392@middleschool.email. Nothing needs to be recreated, no account needs to be relearned by the people who already know how to reach her.

That fall, her math teacher assigns a tutoring app the district has approved. Under most current systems, Maya would type in her real name, her grade, and a personal email address — data the app’s company could combine with information from dozens of other tools to build a detailed profile of an 11-year-old, with little meaningful visibility for her family. Under the proposal’s front-end tokenization model, Maya instead logs in with only her alias. The app learns she’s an authenticated 6th grader in her district. That’s all it receives, and all it needs. Her real name, her location, her activity across other apps — none of it reaches the vendor. Later that week, her mother opens the parent portal and sees exactly which services have accessed Maya’s identifier, when, and why.

Ninth Grade: High School

The domain updates again, automatically, to 4448587392@highschool.email. Maya is now three schools and eight years into an identity that has never once required her, her parents, or her teachers to relearn an address, rebuild a contact list, or wonder whether an old account still works.

Senior Year: The Question Nobody Used to Have a Clean Answer To

Maya turns 18 in the spring of her senior year, a few months before graduation. Under the proposal’s Graduation Release Protocol, her 10-digit number is retired at whichever comes first — graduation or her 18th birthday — and returned to the national pool for a future kindergartener. That doesn’t mean her records disappear. Her transcripts, portfolios, and disciplinary history move to a separate, randomly generated backend identifier, held for exactly five years, so that a university admissions office or a future employer can still verify her transcript without her old, active-looking identifier remaining exposed somewhere it no longer needs to be.

It’s worth sitting with what that design choice is actually doing: the number that made Maya reachable for thirteen years is deliberately allowed to die. Persistence was the point while she was enrolled; retirement is the point once she isn’t.

The Fall After Graduation

Maya starts college, and something that might look like an oversight is actually intentional: her old number does not carry over. There’s no 4448587392@college.email waiting for her. This isn’t a gap in the framework — it’s a designed boundary between two genuinely different systems.

At enrollment, she’s given a choice School Contact never offered her: use her own personal mobile number as her College Contact handle, the same Bring-Your-Own-Device/Number model her mother used years earlier — or take a newly issued 10-digit number from one of five area codes reserved specifically for higher education: 499, 599, 699, 799, or 899. Maya opts for a reserved number. Her reasoning is simple enough — she’d rather keep her college identity separate from her personal phone, the way she’ll want to once she starts job-hunting and doesn’t want a professor and a landlord using the same digits to reach her. A classmate down the hall makes the opposite choice and links his own number instead. Both are valid under the proposal; which one a student picks is left to the student.

School Contact was built around Maya as a minor, with her mother holding most of her privacy and communication rights by default. The moment Maya enrolls in college — regardless of her exact age — FERPA transfers those rights to her directly. College Contact, the companion proposal for higher education, is built around that fact from the ground up: the student is the rights-holder, not the parent, and any family access to her records or communications is something Maya would have to opt into and could revoke, never a default assumption inherited from her K–12 years.

The two systems also solve different shapes of problem. Maya’s K–12 identity assumed she was enrolled at one school at a time, moving sequentially from elementary to middle to high school. Her college professors won’t have that luxury. One of her lecturers teaches at two campuses in the same semester. A researcher in her lab has a joint appointment with a hospital. Her graduate teaching assistant is simultaneously a student and an instructor of record. College Contact’s architecture is built to hold multiple concurrent, independently verified institutional affiliations against a single identity — a structure School Contact was never designed to carry, because K–12 students essentially never need it.

So Maya receives a new identity: a .email address for everyday mail, and a separate .contact verification surface — a place anyone can check whether a sender’s claimed role and institutional affiliation are currently attested, independent of the mailbox itself. When her academic advisor emails her from an address ending in professor.university, that domain name alone isn’t proof of anything; the white paper is explicit that it’s a human-readable signal layered on top of the real authentication underneath, not a substitute for it. Her advisor’s actual rank — full professor, not lecturer or adjunct — is a credential attested by the university itself, not something he could type into a bio.

Second Semester: MIA

By her second semester, Maya is using an MIA — a Machine Intelligence Assistant, the term College Contact proposes for a persistent, identity-aware tutoring and organizing tool. It helps her build a study plan before an exam and organize her notes for a term paper. It does not grade her work, sign off on her degree progress, or make any judgment call about academic integrity — the white paper is deliberate about drawing that line, on the theory that a genuinely useful assistant is exactly the kind of tool whose scope quietly expands over time if the boundary isn’t set explicitly in advance. The MIA can be useful to Maya specifically because it knows, from the identity layer underneath it, which student, which course, and which current affiliation it’s operating within — not because it has broad standing access to everything about her.

What the Walkthrough Is Actually Arguing

None of this is a product tour, because there’s no product. It’s an argument, made concrete: that a 6-year-old’s first school registration and a 22-year-old’s first day of graduate teaching are both instances of the same underlying problem — nobody can currently verify who’s actually on the other end of a message — and that the two ends of that problem are different enough to need two purpose-built systems, not one identity stretched to cover both.

School Contact and College Contact are both proposals from the Department of Technology, a broader initiative advocating for dedicated federal, state, county, and municipal technology departments with the standing to coordinate standards like these at every level of government. It’s worth being direct about what that means and doesn’t mean: the Department of Technology is not a government agency.

It doesn’t exist yet. It’s itself a proposal — an argument that a body like it should eventually exist, made through work like this rather than through any authority it doesn’t have. Nothing about Maya’s story above describes a system anyone can sign up for today. It’s a case for what verified identity in American education could look like, offered for the same pilot evidence, stakeholder scrutiny, and legal review any infrastructure proposal should have to earn before it becomes real.

Comments

Leave a Reply