School Connection / Feature
When the whole school runs through the cloud, dependency becomes the decision
Cloud adoption can simplify access and scale, but it also concentrates dependency in identity, connectivity, integrations, provider availability and data portability. The right question is what the school can still do when one of those layers changes.
The answer in brief
The cloud is not one service. It is a chain of dependencies that needs an exit and recovery story.
DfE's cloud standard asks schools to consider reliable connectivity, identity and access, availability, data protection, portability and external backup. That is a useful correction to the idea that moving a service off site automatically makes it resilient.1
For a school or trust, the real service may combine MIS, payment, telephony, safeguarding, learning platforms, identity and reporting integrations. A change in one layer can affect several operating routines, so assurance should follow the dependency chain rather than the product boundary.12
- Map the service people use, not just the application named in the contract.
- Ask what data, identity, integration and network dependencies would fail together.
- Test export, continuity and recovery before renewal pressure removes leverage.
01 / Dependency chain
The application is only one link in the operating service.
A cloud MIS may depend on identity, broadband, APIs, attendance, finance, safeguarding and reporting flows. Cloud telephony may depend on routing, power, local handsets and emergency arrangements. Leaders should draw the chain from user, through access and data, to the service outcome and the fallback.12
02 / Portability and exit
A service is more resilient when the organisation can leave it safely.
DfE's cloud guidance emphasises data portability and export in usable formats. That should be tested before a crisis: which records can be extracted, what metadata and relationships survive, how integrations are rebuilt, how long the provider retains data and how deletion is evidenced after exit?1
- Maintain a data-flow and integration register for every critical cloud service.
- Record provider availability targets, incident communication and support escalation.
- Run a sample export and recovery exercise before contract renewal or migration.
03 / Continuity by function
Recovery should be written in school language.
‘The platform is unavailable’ is not yet a continuity plan. The plan should say how attendance is recorded, how safeguarding concerns are reported, how families are contacted, how staff authenticate, how teaching continues and how records are reconciled afterwards. Each function needs an owner and a workable temporary method.24
Leadership questions
Questions that turn the development into a governing conversation.
Board test
Which school functions depend on the same cloud identity, connection or integration?
Board test
Can we export critical records in a usable form and prove what happens to them on exit?
Board test
What is the temporary operating method for attendance, safeguarding, communication and teaching?
Board test
Who owns the recovery test and the decision to accept residual dependency?
School Connection intelligence lens
What the national Observatory can add, and where it must stop.
The programme follows cloud adoption as an operating change because the visible platform is rarely the complete service. The strongest evidence joins contract, data-flow, identity, network and recovery records without claiming that a provider's marketing description proves local resilience.12
Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.
Evidence boundary
What this analysis does not prove.
- DfE cloud guidance does not certify a provider, contract or school's implementation.
- An availability target does not show how a school will operate during a particular outage.
- A sample export may not prove every integration or recovery dependency works in full.
What we are monitoring next
Publication is the beginning of the watch.
- DfE cloud, IT support and wider digital-standard updates.
- MIS, telephony and safeguarding-platform transition milestones.
- Evidence from recovery tests, incidents, provider changes and material integration changes.
Approved public intelligence
What the live evidence is showing now.
Gigabit is coming to more schools. The connection is only the beginning.
The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.
A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet.
This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.
Sources and methodology
Evidence used in this analysis
School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.
- 01
Department for Education · Updated 8 September 2026
Cloud solutions: core standard
Guidance on cloud assurance, portability, availability, access control, data protection and external backup. - 02
Department for Education · Updated 8 September 2026
Cyber security: core standard
Guidance on cyber risk assessment, training, identity, patching, backups, incident response and continuity. - 03
Department for Education · Updated 8 September 2026
Broadband internet: core standard
Guidance on capacity, full fibre, backup connectivity and the internal-network dependencies behind a usable school connection. - 04
Department for Education · Updated 8 September 2026
Digital leadership and governance: core standard
Guidance on ownership, strategy, reporting, roles and the governance evidence needed to manage digital change.