Deliver student assessment reports securely, without burdening IT
How Western Kentucky University’s Center for Gifted Studies automated FERPA-compliant delivery of student assessment reports from the R script they already had, without violating security policy.
The situation
The Center for Gifted Studies manages confidential ACT and Iowa Assessment results for fourth through eighth grade students taking above-level tests. Working within the University’s external file sharing process created a lot of time-consuming manual permissions workflows, IT communications, and other process headaches, all of which stood in the way of eager parents, students, and administrators getting access to student data. Meanwhile, federal law (FERPA) means each file must be robustly protected.
The recipe
- Existing scriptThe Center’s R workflow already generated an individual PDF interpretation report per student from the score spreadsheet. That did not change.
- CLIEach PDF is Baked with the Honeycake CLI as the script generates it, granted to exactly the family or educator it belongs to. One line in the R script, one key per recipient.
# called from R for each generated report
honeycake bake report_4821.pdf --grant will.luttrell@example.com --ttl 60d
🍰 Baked report_4821.pdf.cake (keys granted: 1, expires in 60 days) - EmailThe
.cakegoes out by ordinary email. No new portal for families to learn, no shared drive to police. - OpenerRecipients Open the report in the browser, on a phone or a laptop, with nothing to install. Only the intended recipient can Open it, and every Open is logged.
What changed
Compliance
A fully compliant delivery workflow, with confidence that only the intended recipient can Open each report.
IT
No new system to host, no sharing exception to request, no ticket to open. Each report is keyed to one recipient, with an audit trail the Center can pull.
Effort
Encryption built into the existing R reporting scripts. Nobody Bakes by hand.
What it asks of IT
Nothing, which is the point. Honeycake changes what the file is, not what the network allows, so the Center never had to open a ticket, request an exception, or put a new system inside the University’s perimeter.
- Nothing to host. Encryption happens on the Center’s own machine. Honeycake never sees or stores a report, so there is no new system inside the University’s perimeter and no new vendor holding student data.
- Nothing to open up. No new external sharing pathway and no exception to request. A report is keyed to one recipient and is useless to anyone else, forwarded or not.
- Nothing to explain. Every Open, and every blocked attempt, is in the audit trail. If a family says they never received a report, the Center can see whether it was Opened and by whom.
What is next for the Center
Medical and consent forms for student programs: families upload an encrypted PDF through the Uploader, with no app and no login, and it lands Baked in the Center’s own storage.