Current status: Last reviewed August 11, 2026. Validation register updated September 8, 2026: 35 local automated checks passed on Tenet 1.1.127 source. Signed-in vendor control results remain unverified in this register.
Versioned validation register
Register 2026-09-08.1. Evidence checked September 8, 2026, against Tenet 1.1.127 source. The product review date remains August 11, 2026. This register adds concrete local test results and identifies the signed-in vendor checks that are still unverified.
The product-scope table below describes intended supported experiences. This register states what the evidence establishes for each control. No row below certifies current signed-in vendor behavior. An unverified result means evidence is missing or insufficient; it does not by itself mean a feature is broken.
Download the versioned validation register (JSON). Each result is tied to its recorded surface, account context, test date, and Tenet version. A blank value in the download means not recorded, never a passing result.
What the validation statuses mean
- Supported
- The individual control passed on the exact recorded vendor surface, account, and Tenet version, with retained evidence. No vendor control in this register currently meets that evidence threshold.
- Limited
- A named subset or controlled test passed. The row states its boundary; local automated checks cannot qualify a live vendor surface.
- Unsupported
- The exact workflow is outside the declared Tenet Edge scope or has a documented unsupported result. Native mobile and desktop apps and arbitrary vendor API calls remain outside this matrix. A missing test is not an unsupported result.
- Unverified
- No complete, sufficiently current record establishes the individual control on the requested surface, account, and version. Do not treat it as validated for procurement.
Vendor surface and account records
The following are surfaces to validate, not URLs observed in a new live test. Exact account plans, Tenet tiers and roles, and route details must be recorded during qualification. Copilot web and Bing chat, and MagicStudent and Raina, have separate records because one result cannot qualify both experiences.
On narrow screens, scroll each table horizontally to see every field and control.
| Record / product | Surface to validate | Tested account / role | Tested date | Tested Tenet version |
|---|---|---|---|---|
| V01: ChatGPT | chatgpt.com direct chat | Not recorded | Not recorded | Not recorded |
| V02: Claude | claude.ai direct chat | Not recorded | Not recorded | Not recorded |
| V03: Gemini | gemini.google.com/app direct chat | Not recorded | Not recorded | Not recorded |
| V04: Microsoft Copilot web | copilot.microsoft.com direct chat | Not recorded | Not recorded | Not recorded |
| V05: Bing chat | www.bing.com chat; exact active route not recorded | Not recorded | Not recorded | Not recorded |
| V06: Grok | grok.com direct chat | Not recorded | Not recorded | Not recorded |
| V07: MagicSchool MagicStudent | student.magicschool.ai student room composer | Not recorded | Not recorded | Not recorded |
| V08: MagicSchool Raina | app.magicschool.ai Raina educator chat; exact route not recorded | Not recorded | Not recorded | Not recorded |
| V09: SchoolAI Dot | student.schoolai.com/dot/spaces student composer | Not recorded | Not recorded | Not recorded |
| V10: Brisk Boost | app.briskteaching.com student Boost activity; exact route not recorded | Not recorded | Not recorded | Not recorded |
Individual vendor control results
These results apply only to the records above. Files, image inspection, voice, and response controls are tracked separately from typed prompts. A blocked attachment is not proof of successful file redaction; a voice restriction is not proof of audio inspection.
| Record / product | Managed access | Prompt checks | District guidance | Text DLP |
|---|---|---|---|---|
| V01: ChatGPT | unverified | unverified | unverified | unverified |
| V02: Claude | unverified | unverified | unverified | unverified |
| V03: Gemini | unverified | unverified | unverified | unverified |
| V04: Microsoft Copilot web | unverified | unverified | unverified | unverified |
| V05: Bing chat | unverified | unverified | unverified | unverified |
| V06: Grok | unverified | unverified | unverified | unverified |
| V07: MagicSchool MagicStudent | unverified | unverified | unverified | unverified |
| V08: MagicSchool Raina | unverified | unverified | unverified | unverified |
| V09: SchoolAI Dot | unverified | unverified | unverified | unverified |
| V10: Brisk Boost | unverified | unverified | unverified | unverified |
| Record / product | Files | Images / OCR | Voice | Response controls |
|---|---|---|---|---|
| V01: ChatGPT | unverified | unverified | unverified | unverified |
| V02: Claude | unverified | unverified | unverified | unverified |
| V03: Gemini | unverified | unverified | unverified | unverified |
| V04: Microsoft Copilot web | unverified | unverified | unverified | unverified |
| V05: Bing chat | unverified | unverified | unverified | unverified |
| V06: Grok | unverified | unverified | unverified | unverified |
| V07: MagicSchool MagicStudent | unverified | unverified | unverified | unverified |
| V08: MagicSchool Raina | unverified | unverified | unverified | unverified |
| V09: SchoolAI Dot | unverified | unverified | unverified | unverified |
| V10: Brisk Boost | unverified | unverified | unverified | unverified |
Versioned local control validation
35 automated checks passed; 0 failed; 0 skipped on September 8, 2026. These checks executed Tenet 1.1.127 source in local simulated runtimes. They did not load an installed release into signed-in vendor accounts. No real student data was used. The records below are deliberately limited.
L01: Local plain-text file processor in a simulated browser runtime
limited | Tested 2026-09-08 | Tenet 1.1.127
Account context: Synthetic policy and roster fixtures; no signed-in vendor account.
Individual results: 8/8 passed: clean text; email redaction and exact-output verification; refusal on unsupported or oversized input, missing runtime, span overflow, parser error, malformed roster, failed verification, or policy failure.
Boundary: Plain-text processor evidence only. Does not prove a vendor receives the protected file, or validate PDF, Office documents, image OCR, voice, or responses.
L02: Simulated file picker and drag/drop events; scanner outcomes are test doubles
limited | Tested 2026-09-08 | Tenet 1.1.127
Account context: Synthetic client runtime; no signed-in vendor account.
Individual results: 7/7 passed: blocked drag/drop with picker guidance; notice deduplication; drag suppression; picker failure clears input; multi-file forwarding; one rejected file blocks the selection; malformed verification is rejected.
Boundary: Event-contract evidence only. Does not prove native vendor attachment handling, scanning accuracy, or outbound file bytes.
L03: Local sensitive-data decision engine in a simulated browser runtime
limited | Tested 2026-09-08 | Tenet 1.1.127
Account context: Synthetic student and teacher policy fixtures; no verified vendor account.
Individual results: 17/17 passed: sensitive-record decisions; identity findings; rejection of caller-asserted account approval; policy validation; verified text transformation; refusal on residual identifiers and roster-matcher errors.
Boundary: Decision-engine evidence only. Does not establish classification accuracy on arbitrary content or delivery behavior in a signed-in vendor composer.
L04: Local teacher DLP policy resolver and source-route checks
limited | Tested 2026-09-08 | Tenet 1.1.127
Account context: Synthetic teacher policy fixtures; no verified teacher session.
Individual results: 3/3 passed: block/redact/legacy-override selection; active product-specific policy precedence; prompt and upload source routes carry the selected mode and reason-code precedence.
Boundary: Resolver and source-route evidence only. Does not prove live teacher authorization, visible warnings, or vendor submission behavior.
The download records the source revision and test-suite references for reproducibility. Prior adapter-health summaries without a Tenet version or complete control assertions were not promoted into passing vendor results. An August 10 monitoring run stopped before testing any vendor and supplies no compatibility evidence.
What is required to qualify a row
Record the test date, Tenet version and release channel, Chrome version and managed-device context, exact hostname and route, vendor account plan, Tenet tier and role, resolved policy, and expected and observed outcomes for each control. Use synthetic content and retain an evidence identifier without publishing account emails, private room links, conversation text, or credentials.
Check allowed and denied access; clean and policy-restricted prompts; district guidance; sensitive-text handling; each required file format and picker, paste, or drag/drop path; images; voice; and response controls individually. Confirm the vendor received the expected protected content where applicable. Record failures, unsupported paths, and tests that could not run instead of converting them to passes.
A successful local check, a release build, or a vendor's own documentation cannot advance a live compatibility result. Advance the product review date only after the relevant vendor behavior is checked and the qualified rows are updated. Recheck affected rows after material Tenet, vendor-interface, account, or policy changes.
Tenet Edge currently supports ChatGPT, Claude, Gemini, Microsoft Copilot web and Bing chat, Grok, MagicSchool MagicStudent and Raina, SchoolAI student Dot spaces, and Brisk Boost on district-managed Chrome devices. Feature availability varies by product surface, content type, district configuration, and rollout scope.
This is a surface-level compatibility statement, not a claim that every feature inside each vendor product behaves the same way. A district should identify the exact product URL, account type, user role, content type, and required control before treating a workflow as covered.
Last reviewed August 11, 2026. The vendor references on this page confirm product names and web experiences. Tenet compatibility status is based on TrueMadeAI’s current managed Chrome implementation and rollout scope.
A separate layer for unapproved AI interfaces
The supported-product matrix below lists web experiences within Tenet’s declared governance scope. The versioned validation register above separates that scope from evidence for each control. Tenet Basic and Tenet District also include an optional blocking layer for AI chat and writing interfaces that the district has not approved.
| Blocking path | What Tenet checks locally | District-configured result | Boundary |
|---|---|---|---|
| Known-interface signatures | Curated interface patterns for mapped AI panels inside web applications | Block the detected unapproved interface while leaving the surrounding site available | The exact hostname and interface must remain current |
| Multi-signal heuristic | A combination of local interface signals associated with AI chat or generative writing | Block when the detection threshold is met and the district has enabled the control | No heuristic can guarantee detection of every AI interface or vendor change |
Approved products, district allowlists, and bypass domains remain authoritative. Detection happens on the managed Chrome device. A detection does not convert that product into a deeply supported surface and does not imply that Tenet can apply prompt policy, DLP, or response controls inside it.
Grammarly is a current example of why the distinction matters. Its August 2025 product announcement describes an AI-native writing surface with AI Chat and specialized agents. For a validated Grammarly web surface, Tenet can use a known interface signature to block the unapproved AI panel rather than blocking the entire surrounding writing application. Districts should confirm the exact route and behavior during rollout because vendor interfaces change.
Current supported-product capability matrix
The table distinguishes the supported web experience from adjacent features that are not automatically included.
| AI product | Supported web surface | Current Tenet Edge scope | Important boundary |
|---|---|---|---|
| ChatGPT | Direct chat at chatgpt.com |
Managed access policy, supported plain-text prompt checks, district guidance, and on-device DLP on validated text paths | GPTs, voice, canvas, connectors, files, images, and newly released composer experiences require separate validation |
| Claude | Direct web chat at claude.ai |
Managed access policy, supported plain-text prompt checks, district guidance, and on-device DLP on validated text paths | Desktop and mobile apps, artifacts, connectors, files, and other non-chat workflows are not implied |
| Gemini | Direct web chat at gemini.google.com |
Managed access policy, supported plain-text prompt checks, district guidance, and on-device DLP on validated text paths | Mobile apps, Gemini in Chrome, Gems, Canvas, media tools, and file paths require separate validation |
| Microsoft Copilot | Web chat at copilot.microsoft.com and the supported Bing chat path |
Managed access policy, supported plain-text prompt checks, district guidance, and on-device DLP on validated text paths | Copilot inside Word, Excel, PowerPoint, Teams, Windows, Microsoft 365, Edge sidebars, or native apps is not automatically covered |
| Grok | Direct web chat at grok.com |
Managed access policy, supported plain-text prompt checks, district guidance, and on-device DLP on validated text paths | Grok Imagine, X-integrated experiences, voice, native apps, connectors, and files are separate surfaces |
| MagicSchool: MagicStudent and Raina | Student experiences at student.magicschool.ai and Raina educator chat at the supported app.magicschool.ai path |
Managed access policy and direct-text controls on validated student-room and Raina chat composers | Other MagicSchool tools, dashboards, exports, integrations, and newly released room experiences are not automatically covered |
| SchoolAI | Student Dot chat within supported Spaces at student.schoolai.com/dot/spaces |
Managed access policy and direct-text controls on validated student Dot space composers | Teacher and administrator dashboards, other SchoolAI routes, files, PowerUps, and newly released Space features require separate validation |
| Brisk Boost | Student Boost chat in the Brisk web experience | Managed access policy and surface-specific teacher-side enforcement in the supported Boost experience; exact composer behavior is confirmed during district deployment | This does not claim blanket direct-text prompt transformation or coverage for the educator Brisk browser tool, Boost feedback inside Google Docs, whiteboards, files, or every Boost activity type |
Product names are trademarks of their respective owners. Listing a product does not state or imply a vendor partnership, endorsement, or certification.
What the capability labels mean
Managed access policy
A district can include the named product in its approved AI policy and apply managed-device access decisions under the configured Tenet rules. Access eligibility is different from deep control inside every feature of the product.
Plain-text prompt checks
On a validated direct-chat composer, Tenet can evaluate supported plain-text student input against the enabled district rules before the message is submitted. Available checks depend on account role, tier, policy settings, and the active product surface.
District guidance
On supported direct-chat paths, Tenet can apply district guidance to the conversation flow. Tenet Basic uses one district-wide baseline. Tenet District can resolve additional grade, roster, class, teacher, period, and schedule context.
On-device DLP
Tenet can evaluate supported plain-text paths for configured sensitive-data patterns on the managed device. Tenet District can add roster-aware context where supported. This does not mean every file, image, attachment, generated response, or vendor-side feature receives the same inspection.
Basic and District use the same product register
The difference between Tenet Basic and Tenet District is policy resolution, not a different list of vendor products.
| Tenet Edge tier | Policy context | Supported-product effect |
|---|---|---|
| Tenet Basic | One district-wide baseline without grade, roster, class, or teacher policy layers | Apply the baseline across named supported surfaces and optionally block detected unapproved AI interfaces |
| Tenet District | District, grade, roster, class, teacher, subject, period, and schedule context | Resolve more specific rules on named supported surfaces and include the same optional unapproved-interface blocking layer |
Both tiers include DLP on supported and configured paths, plus optional blocking for detected unapproved AI chat and writing interfaces on managed Chrome. Tenet District adds roster-aware context and pseudonymization where supported. Neither tier turns a detected or unsupported vendor feature into a deeply supported one.
Both tiers can send supported general analytics to configured district-controlled destinations through bring-your-own-storage (BYOS) exports. Incident evidence is a separate data class and may preserve conversation text and identifying context for defined safety or compliance events when active for a deployment. Routine prompt and response bodies are not routed through the TrueMadeAI backend. See the privacy notice for the complete hosted-data, provider, analytics, evidence, and alert boundaries.
What is outside this matrix
This page does not claim current Tenet Edge coverage for:
- native mobile or desktop applications;
- unmanaged browsers or personal devices outside the district deployment;
- deep governance of AI assistants embedded inside productivity suites, learning platforms, or operating systems unless that exact surface is named; the optional blocking layer may still detect and stop an unapproved interface;
- every file upload, attachment, image, voice, video, canvas, connector, plugin, custom assistant, or agent workflow;
- every model response or vendor-generated action;
- arbitrary model APIs used by district applications.
Direct-use governance and backend AI governance are separate technical planes. Tenet Edge applies policy on the supported managed-device experiences listed here. Tenet Gateway is a founding-district program for approved backend AI operations inside district applications.
District rollout verification checklist
Before a district calls a workflow supported, verify:
- Device: The user is on a district-managed Chrome device in the intended deployment group.
- Surface: The exact hostname and product route match the supported web experience.
- Identity: The district knows whether the user is a student, educator, or staff member and which account is active.
- Tier context: The expected district, grade, roster, class, teacher, period, or schedule rule resolves correctly.
- Content type: Plain text, pasted content, file, image, voice, or another format is tested separately.
- Decision: Allow, guide, warn, redact, or stop behavior matches the district configuration.
- Vendor change: The workflow is retested after a material vendor interface, account, or feature update.
For the broader operating model, use the K-12 AI governance guide, the AI application register template, and the AI tool vetting template.
Frequently asked questions
Which AI products does Tenet Edge currently support?
Tenet Edge currently supports ChatGPT, Claude, Gemini, Microsoft Copilot web and Bing chat, Grok, MagicSchool MagicStudent and Raina, SchoolAI student Dot spaces, and Brisk Boost on district-managed Chrome devices. Feature availability varies by product surface, content type, district configuration, and rollout scope.
Does supported mean every feature inside each AI product is governed?
No. Support applies to the named web surfaces and validated interaction paths. It does not automatically include every file flow, image tool, voice mode, custom assistant, connector, native application, embedded assistant, or newly released product feature.
Can Tenet block an unapproved AI chatbot that is not in the supported-product matrix?
Yes, on district-managed Chrome when the district enables the optional control and the interface matches a known signature or the local multi-signal detection threshold. Tenet can block the detected AI chat or writing interface while district allowlists and bypasses remain authoritative. Coverage depends on the current web surface and vendor changes.
Does detecting an AI interface mean Tenet deeply supports that product?
No. Detection and blocking are separate from deep governed support. A detected interface can be stopped without claiming prompt controls, DLP, policy guidance, or response monitoring inside that product.
Do Tenet Basic and Tenet District support different AI products?
The named product coverage is shared across Tenet Edge. Tenet Basic applies one district-wide baseline. Tenet District adds grade, roster, class, teacher, period, and schedule context where the selected capability supports it.
Does Tenet Edge support mobile applications or unmanaged browsers?
No. The current Tenet Edge scope is district-managed Chrome devices. A vendor’s mobile app, desktop app, browser sidebar, or unmanaged browser session is not included merely because its web chat is listed.
Does Tenet Edge govern AI used inside district applications through an API?
No. Tenet Edge governs direct use on supported managed-device surfaces. Tenet Gateway is a separate founding-district program for approved backend AI operations inside district applications.
Does Tenet provide DLP for every prompt, file, and model response on every supported product?
No. Plain-text prompt DLP is available on supported paths when configured. File, image, attachment, and response-level behavior varies by product surface and content type and must be validated for the district’s intended workflow.
Product references
These vendor sources document the named product experiences. They do not describe or certify Tenet compatibility.
- What is ChatGPT: FAQ, OpenAI
- Claude access interfaces, Anthropic
- Use Gemini Apps, Google
- Microsoft Copilot and Copilot in Microsoft 365, Microsoft
- Welcome to Grok, xAI
- AI tools for K-12 students, MagicSchool
- Getting Started with Spaces, SchoolAI
- How students use a Boost Activity, Brisk Teaching
- Grammarly launches AI agents and an AI-native writing surface, Grammarly
For procurement, account eligibility, student privacy, retention, training use, and contractual terms, districts should review the vendor’s current documentation and agreement for the selected account and deployment.