Use this guide for the microphone-assisted, timetable-linked Lesson Note workflow. It is a product and school-approval checklist, not legal advice or permission to use real student data.
Current App Boundary
When an authorised teacher opens a teaching date, Band Licence:
- finds active scheduled lesson and rehearsal occurrences for that date;
- collapses a group lesson to one session;
- excludes cancelled or removed occurrences;
- stores one name-minimised Prepared Draft per occurrence; and
- gives the teacher a typed workflow plus an optional, separately gated microphone-assisted workflow.
The microphone workflow begins only when the teacher deliberately arms the selected teaching date. One arm covers the combined list of writable lessons and rehearsals for that date and permits each active scheduled session to start and stop locally at its scheduled boundaries. Merely opening the page, preparing a Draft, or reaching a timetable time does not request permission or arm capture.
While armed or capturing, the interface must show a persistent state indicator and immediate Stop and Discard controls. Capture uses only the approved authenticated loopback transcription engine on the app host. It does not use cloud transcription, generative AI, speaker recognition, automatic assessment, automatic sign-off or automatic family delivery.
Normal HTTP, private-network and HTTPS startup remain audio-free. Only an explicit opt-in command such as pnpm start:pilot:lesson-notes, or its approved HTTPS equivalent, may start and enable the local engine. Typed notes remain available if permission, a device, an approval gate or the engine is unavailable.
Deliberate Arming and Scheduled Capture
Arming is a consequential teacher action, not a saved browser preference. Before arming, the page must state:
- which teaching date, lessons and rehearsals are being armed together;
- that scheduled sessions may start and stop automatically after arming;
- which microphone and authenticated loopback engine will be used;
- that audio and raw transcript text are temporary and must not be stored;
- that only a privacy-filtered Candidate Draft may be saved; and
- that the teacher must review and sign off every note before sharing.
The one arm must cover both writable Lessons and Rehearsals in the displayed combined list, while arming one date must not arm another date. Sign-out, school switch, page exit, session expiry, Stop All or Discard must clear the armed state and stop live tracks. The app must not silently re-arm after reload or restart.
What Is Stored
A prepared or edited record may contain:
- school ID;
- lesson or rehearsal type;
- teaching date;
- a privacy-neutral label such as
Individual lesson · 09:00; - an opaque internal occurrence key;
- Draft origin and generation version;
- a privacy-filtered Candidate Draft or teacher-edited Summary;
- teacher-edited and signed-off timestamps when applicable;
- teacher identifier only after a teacher deliberately saves; and
- the sign-off checklist and privacy-safe audit metadata.
The stored label and Prepared Draft deliberately exclude student names, instruments, class, barcode, contact details, membership lists, attendance counts and attendance notes. Teacher-only queue context may show the scheduled title while the teacher is signed in, but that title is not copied into the stored or shareable label.
What Must Never Be Persisted
- microphone audio, encoded chunks or converted audio files;
- raw or partial transcripts;
- voiceprints, speaker labels, confidence tokens or voice metadata;
- temporary typed scratchpad text;
- rejected or filtered transcript sentences;
- engine payloads containing content;
- audio or transcript content in browser storage, logs, analytics, notifications, exports, support records or backups;
- AI-generated teaching observations; or
- automatic family messages.
Temporary content exists only in memory or the engine's private per-request working folder while processing. It must be cleared on success, failure, timeout, Stop, Discard, sign-out, school switch, page exit, component unmount and session expiry. If cleanup cannot be proved, disable microphone assistance and use typed notes.
Prepared, Candidate Draft and Signed Off
Use these labels consistently:
- Prepared: created from timetable metadata; no captured or teacher-entered teaching content has been approved.
- Candidate Draft: produced from temporary local transcription or teacher typing; teacher review is still required and it is not shareable.
- Draft: deliberately saved or edited by a teacher; it remains not shareable.
- Signed Off: the teacher has removed identifiers, checked the declarations and approved the exact wording for a school-approved channel.
Automatically prepared content is attributed to Automatic session setup, not to the teacher who merely opened the page. A microphone-produced Candidate Draft is still automatic working content, not a teacher statement. The teacher identifier is added only when the teacher deliberately saves or signs off.
Lifecycle and Reconciliation
The occurrence key makes preparation idempotent: reopening the date must not create duplicates. Untouched Prepared Drafts may be refreshed when safe timetable metadata changes.
If a scheduled occurrence is cancelled, removed or rescheduled, the app may archive only an untouched Prepared Draft. It must not silently overwrite or archive a microphone-produced Candidate Draft, teacher-edited Draft or signed record. Those records remain available for authorised correction and retention decisions.
Scheduled date, type and privacy-neutral label are read-only in the editor. This prevents an occurrence-linked record being moved to a different date or colliding with another occurrence.
Access Rules
- Only an Administrator or Teacher with access to the selected school may arm, capture, edit or sign notes.
- Read-only accounts may see signed notes only and must not trigger Draft preparation or microphone permission.
- QR, public profile, Student/Player and future Parent/Carer surfaces receive no Lesson Note data.
- Every capture and write route must verify the current account, selected school, feature switches, approvals, authenticated loopback engine and request limits.
- Copy is available only for signed notes and does not include occurrence keys.
- Switching school or losing access stops capture and clears temporary content immediately.
Participant Notice and School Approval
Before real use, the school and legal/privacy owner must document the lawful authority, participant notice, consent position where applicable, physical-room recording indicator, handling of late arrivals and visitors, alternatives for people who do not participate, and the complaint/correction/incident process.
Queensland listening-device and privacy requirements are fact-specific. A teacher being present does not by itself settle education, employment, safeguarding, privacy or school-policy requirements. No app checkbox creates legal or school approval.
Teacher Review and Sign-off
Before signing off, the teacher must confirm that:
- the Candidate Draft contains no student names or identifying details;
- personal stories and unrelated details have been removed;
- it contains only relevant music teaching content;
- no prompt or placeholder remains; and
- the teacher has reviewed and approved every word.
The deterministic privacy filter can block known display names, contact patterns and selected personal-detail terms, but it is not guaranteed anonymisation. It is not AI and must not be described as an assessment. If sensitive information is spoken, Discard the Candidate Draft and use the school's authorised process outside this feature.
Retention, Correction and Deletion
The school must set separate rules for untouched Prepared Drafts, microphone-produced Candidate Drafts, teacher-edited Drafts, signed-off notes, audit records and backup copies.
Audio and raw transcripts have no retention period because they must never become stored records. Discovery of either in app storage, logs, temporary folders after processing, exports or backups is an incident: stop microphone use, isolate the affected path and follow the incident process.
Do not silently erase teacher-edited or signed history. Corrections must preserve accountability and audit evidence.
Verification
After any Lesson Note change:
- run
pnpm lesson-notes:privacy-check; - run the Lesson Note workflow, persistence, privacy, startup and migration tests;
- test Teacher and Read-only accounts across two schools;
- confirm normal start commands launch no transcription process;
- confirm only the explicit Lesson Notes start mode enables the local engine;
- verify a page open or scheduled time alone never requests microphone access;
- deliberately arm one teaching date and verify each scheduled individual lesson, group lesson and rehearsal in the combined list starts/stops once at the correct boundaries;
- verify a persistent indicator plus Stop and Discard while armed/capturing;
- verify sign-out, school switch, navigation, unmount, permission failure, engine failure and timeout stop every track and clear temporary content;
- search database, browser storage, engine folders, logs, backup samples and exports for fictional audio/transcript canary content;
- confirm only the privacy-filtered Candidate Draft is stored;
- confirm teacher review/sign-off is required and nothing is shared automatically; and
- confirm practice logging still has no microphone recording or automatic practice detection.
Static checks are useful evidence, not certification. Record the build, date, tester, fictional scenario, device/browser, school scope, result and follow-up owner.