An agent tutoring a student or touching a student record is handling data with its own legal protections, and most schools have no record of what it actually accessed.
Every run scored for quality, performance and risk, and checked against the activity schema you define.
Every education agent run gets watched, evaluated for quality and risk, and checked against the rules you set. One record answers what any agent did, with evidence ready for review.
For the instructors, admissions officers, and edtech teams behind a tutoring or admissions agent, the stakes are student records the agent can reach and answers a student will act on as if they were correct.
Agents reach records with their own legal protections, and minors are often involved.
A wrong answer sends a student down the wrong path, and it reads as correct.
Few schools can show, for a given answer, which course material it actually came from.
Instrument the agent frameworks you build on, and ingest the systems those agents touch as custom spans. Every run, score and signal lands in one place.
A record of what the agent did, and a check before it goes further. Each step below closes one of the problems above.
The same record, read the way each team needs it.
Instrument the education agents you already run — no gateway in the request path, no re-architecture.
For developers →Ship education features without regressions — every run scored before a customer ever sees it.
For product teams →One portfolio view of every education agent — its owner, cost and risk in a single place.
For heads of AI →Audit-ready evidence for every decision a education agent makes, ready when a regulator asks.
Security & governance →Hypothetical, but grounded in how education teams deploy agents today.
A Claude Agent SDK agent answers a student's homework questions by pulling from the course's approved textbook and lecture material, escalating to a human instructor when a question falls outside that material.
An instructor sees which course material backed a specific answer, and every time the agent escalated instead of guessing.
A LangChain agent reviews applicant files in the student information system, summarizes each application against admissions criteria, and drafts a recommendation for an admissions officer to review.
An admissions office can confirm the agent read only the fields it was scoped to see at each stage, and stop a run that did not.
Runs stay isolated — terminate one without touching the rest of your fleet via the kill switch → · Prefactor vs. observability tools →
Agents fail quietly and the first signal is a complaint, not an alert.
How it gets caught →Stuck at POCThe pilot worked; sign-off takes months because risk has no evidence.
How it gets caught →No kill switchWhen an agent misbehaves, nothing can stop it short of stopping everything.
How it gets caught →Book a demo and we'll walk through span-level scoring and audit evidence on a fleet like yours.
Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.