Campus AI Development Use case scenarios

Use case scenarios 06 of 08

Scenario 06

Faculty member

An instructor builds a practice-quiz tool for their course with the campus AI platform, then shares it with colleagues teaching other sections.

Most governedLeast governed

Questions to consider

Six lenses from the scenario framework. Any answer that raises the stakes moves this scenario toward stricter controls; take your answers to the chooser.

01 Data What it touches and how that data is classified
  1. Does it collect student responses, names or grades?
  2. Where is that data stored, and who can see it?
02 Audience Who relies on it, and what happens if it’s wrong
  1. Will only your students use it, or other sections too?
  2. Does it work for every student, including those using assistive technology?
03 Lifespan How long it lives and who maintains it
  1. Will it outlast the term, and your appointment?
  2. Who maintains it if colleagues depend on it?
04 Reach What it can read, write or break
  1. Is it connected to the LMS gradebook?
  2. Can students affect each other’s results?
05 Verification How you’ll know it’s right, and keep knowing
  1. Have you checked every generated question and answer?
  2. How will students report errors?
06 Accountability Who owns it, approves it and discloses it
  1. Have you told students it’s AI-built?
  2. Does your department need to approve it?

How the work goes

  1. 01BuildUse the instructor’s own course content.
  2. 02Check accuracyReview generated questions and answers before anyone sees them.
  3. 03Check accessibilityRun an accessibility check before students use it.
  4. 04Review data useBefore it collects any student responses, route it through review.

Proportionate controls

T3 · Managed

Governance should match the risk: enough to protect people and data, no more. Each control area keeps its own tier on the five-tier scale, and those are the controls to apply. The baseline is a label for the project as a whole, taken from its highest area.

  1. Review T2 A colleague looks it over before others rely on it
  2. Documentation T2 A short README: purpose, owner, data used
  3. Approval T2 Manager or sponsor is aware
  4. Data T2 Internal data with no restricted fields
  5. Access T2 Team space; no shared credentials
  6. Testing T3 Every path tested, including failures; accessibility check; re-test when the model or prompt changes
  7. Monitoring T2 The owner reviews it each term
Raises the tier
  • It collects grades or student responses
  • Other sections or the department adopt it
Legal triggers that raise it →
Over-governing looks like
  • Formal IT review for a practice tool with no student data
  • Requiring a spec for course content
Excess controls push builders toward unsanctioned tools.
Minimum controls
  • Accessibility as a gate
  • No student records without review
  • Content accuracy review
  • Disclosure to students that the tool is AI-built
Watch for
  • Inaccurate generated content
  • Student data captured by accident
  • The tool disappearing when the instructor leaves
When it moves up

When it collects grades or student data, or a department adopts it, move to agentic coding with review or an LMS integration through IT.