Seen · The noticing engine for the adults who serve kids · Free for the school · 2026

Every child deserves to be seen

Seen is the noticing engine for the adults who serve kids — not a student app. Coverage shows which children have never appeared in any publication this year. Letters is the human-written witness letter, with no AI path by architecture. Keepsake is the parent-compiled, family-owned artifact, revocable at any time. Free for the school. No student logins. No streaks, no rankings, no leaderboards.

Illustrative · Synthetic data · No real students

Alex M.6 appearances
Casey F.4 appearances
Drew K.8 appearances
Jordan L.3 appearances
Morgan A.5 appearances
Riley N.7 appearances
Sam G.2 appearances
Taylor P.4 appearances
Quinn B. 0 appearances · all year

The algorithm suggests. A human decides.

1 gap list · every publicationyearbook · newspaper · news-site · literary magazine on one report
0 AI pathsin the witness letter — structural, by architecture, guard-enforced
0 student loginszero student-facing surfaces — Seen is for advisers and families only
0 counts or scores to familiesthe Keepsake is qualitative and family-owned; every numeric aggregate is structurally omitted
3 wallson every Keepsake request — tenant · rep-deny · guardian, re-checked fresh each time
3 faces · one lawCoverage · Letters · Keepsake — the institution is audited; the child is never profiled

Three faces of Seen

One product. One law. Three shipped faces.

Every capability below is shipped and in production. The printed Keepsake is honest-off (digital export is free and works). No adoption metrics, no fabricated statistics. Copy only from what is verifiable in the repo.

Coverage

Which students have never appeared once — school-wide, across every publication

The Coverage face answers the question every adviser dreads too late: “Did we miss anyone?” A single report spans the yearbook, the newspaper, the news-site, and the literary magazine in one view. Every student who has not appeared once anywhere — across all of them — shows up on the list. The report breaks down by grade and homeroom, so a whole class that was systematically overlooked shows up as a pattern, not just a list of names. It works from names and counts only; it never passes a child’s photo to the report. It is for editorial staff, school administrators, and district administrators only — a parent, student, or studio rep cannot reach it. A surface with nothing tagged says so plainly; no number is invented when the data is not there.

Shipped · adviser and staff only · ea57afea

Letters

The human-written witness letter — no AI path, by architecture

The Letters face produces a witness letter written by a staff adviser who knows the child. The only processing the platform applies is substituting a closed set of six merge tokens (first name, last name, preferred name, and three pronoun forms). An unknown merge token fails the whole letter closed — the letter is withheld, never auto-filled with blank praise. There is no AI path by architecture: a guard test asserts that no export has generation semantics, every export is synchronous (an AI call is inherently async — sync-only proves no live inference), and no AI-package identifier appears anywhere in the module’s source. A human adviser signs off at every stage: the letter lives in draft → in review → final, and the platform emits nothing until a human marks it final.

Shipped · no AI path by architecture · a5afaf2f

Keepsake

The parent-compiled, family-owned artifact — consent at assembly and at delivery

The Keepsake face is a collection of your child’s year assembled by you, owned by you, and revocable at any time. Only a verified guardian can reach it: three fail-closed walls (tenant isolation, rep-hard-deny, and a guardian check re-resolved fresh on every request) keep it entirely private. Consent is checked when the keepsake is assembled and again at the moment of export — an appearance whose grant lapsed since assembly time is dropped at delivery, not included. No counts, ranks, or scores ever cross to a family: the family view type structurally omits every numeric aggregate. Group photos with mixed consent are remediated (blurred, cropped, or split) before display; a fully blocked photo is dropped. The digital keepsake is free to export. The printed keepsake is not enabled yet: every order intent is queued and not sent, and no money moves. FERPA release-at-majority transfers ownership to the student at graduation.

Digital export shipped · printed keepsake not enabled · a5afaf2f

Seen → Coverage

See which children have never appeared once — school-wide, across every publication

The Coverage face answers the question every adviser fears asking too late: who did we miss? A single report spans the yearbook, the newspaper, the news-site, and the literary magazine. Every student who has never appeared anywhere — across all of them — is on the list. The list breaks down by grade and homeroom, so a whole class that was systematically under-covered shows up as a pattern, not just a list of names.

The report works from names and counts only. It never passes a child’s photo or image reference to the dashboard. A student who appears as a bylined author (their name under a story) never has that authorship inflate their appearance count — authorship and depiction are tracked separately. A surface with nothing tagged says so plainly: no number is invented when the data is not there.

The Coverage face is for editorial staff, school administrators, and district administrators only. A parent, a student, or a studio representative cannot reach it — enforced at the route level and tested in the readonly-guard test. The dashboard is framed as an opportunity, never a deficit: a student on the “never appeared” list is not labelled a failure — they are a gap the adviser can now close.

Seen → Letters

Written by a human who knows your child. There is no AI path, by architecture.

The Letters face produces a witness letter written by a staff adviser — a real person who has watched your child this year and has something to say about it. The only processing the platform applies is substituting a closed set of six merge tokens: first name, last name, preferred name, and three pronoun forms. An unknown merge token fails the entire letter closed — the letter is withheld, never auto-filled with blank praise.

There is no AI path by architecture. A guard test asserts this on the dependency graph — not in a policy document, on the actual code: no export has generation semantics (generate, complete, synthesize, autocompose); every export is synchronous (an AI call is inherently async, so sync-only proves no live inference); no AI-package identifier appears in any function’s source. If someone adds an AI path, the guard test fails. The commit is blocked.

A human adviser signs off at every stage. The letter lives in draft, then in review, then final. The platform emits nothing until a human marks it final. The emitted shape carries only the letter body: zero numeric aggregate fields. No performance data, no appearance count, no score.

Seen → Keepsake

The family compiles it. The family owns it. The family can revoke it at any time.

The Keepsake is a collection of your child’s year assembled by you, owned by you. A verified guardian selects which appearances to include, approves the result, and can export it. Three fail-closed walls protect every request: tenant isolation, a hard-deny for studio representatives, and a guardian check re-resolved fresh on every request — a revoked or transferred guardianship goes dark on the next call, not the next day.

Consent is checked twice. At assembly: only the explicit compilation consent authorises a cross-year compilation — a publication grant or a picture-day grant does not. At delivery: a grant that lapsed since compile time drops that appearance at export. Fail-closed means the family gets less, never more, than what was consented.

No counts, ranks, or scores ever cross to a family. The family view type structurally omits every numeric aggregate. A guard test enforces it at the type level. The Keepsake is qualitative and family-owned — your child’s year, seen, not scored.

The digital keepsake is free to export. The printed keepsake is not enabled yet: every order intent is queued and not sent, and no money moves. FERPA release-at-majority transfers ownership to the student at graduation.

The law as the product — why Seen is built the way it is

Seen audits the institution. It never profiles a child.

Every recognition system that shows data about individual students creates a profiling surface. Seen does not. The Coverage face shows advisers which children are missing from publications — it shows staff who to look for, not data about those children to anyone else. The Keepsake shows a family their own child’s year, nothing about anyone else. Letters are addressed to a family, written by a human who knows the child, and carry zero aggregates.

The absence of engagement mechanics is deliberate and stated proudly: no streaks, no rankings, no leaderboards, no student logins, no student-facing surface at all. Seen is not a growth-hacked student app. It is a tool for the adults who serve kids: advisers, staff, principals, and families. The students are the subject — not the audience.

The algorithm suggests. A human decides. This is on the page because it belongs on the page, not buried in terms. Seen writes nothing, awards nothing, publishes nothing on its own. It hands an adviser a gap list and routes them to the existing place lane. A human closes the gap.

How it works

Four steps, one law

Every step traces to a shipped capability. Seen surfaces the gap. A human acts. A teacher contributes. The family owns the result.

Step 1 · Seen surfaces the gap

The Coverage face produces a school-wide report: every publication you run this year, every student who has not appeared once in any of them. The list breaks down by grade and homeroom. An adviser sees the pattern — not just names, but which whole grade or homeroom is under-covered — and can act while the year still has time left in it. The report works from names and counts only; it never passes a child’s photo or image reference to the dashboard.

Step 2 · A human adviser acts — the algorithm suggests, the adviser decides

Seen exposes no write, award, rank, notify, or publish method. Every output is a read-only aggregate an adviser acts on through the existing place lane: a student on the “never appeared” list is an opportunity to place them — not a decision the platform makes on anyone’s behalf. The guard test is structural: it asserts that the engine exports no method with award or rank semantics. The algorithm surfaces the gap. A human closes it.

Step 3 · A teacher contributes a photo — consent before candidacy

Any staff member can contribute a photo through the teacher contribution pipeline. Before a contributed photo can even be a candidate for placement, the platform checks consent: an untagged photo goes to held; a consent conflict goes to held; a held photo can never be picked. “Held → picked” is forbidden by the state machine — a consent-held photo never enters the picked pool. Even once a photo is a candidate, adviser approval is the only publish path. The contribution pipeline is shipped (83bca642).

Step 4 · The family compiles and owns the keepsake — revocable at any time

A verified guardian compiles the keepsake by selecting which of their child’s appearances to include. Consent is checked at assembly (only the explicit compilation consent authorises cross-year compilation — a publication or picture-day grant does not) and again at delivery (a grant that lapsed since compile time drops that appearance). The family can revoke the keepsake at any time; revocation cascade-deletes all egress tokens. No counts, ranks, or scores appear in the family view — the keepsake is qualitative and family-owned.

Who it’s for

Two audiences. One product. One law.

Advisers, staff, and principals

Coverage and Letters are for the adults inside the school: the yearbook adviser who wants to know which students have never appeared, the English teacher who wants to write a witness letter for a student nobody else noticed, the principal who wants to know whether an entire grade is being overlooked. The Coverage dashboard is for editorial staff, school administrators, and district administrators only. A student cannot reach it. A studio representative cannot reach it. The report returns names and counts — never a child’s photo.

Families

The Keepsake is for a verified guardian. A family compiles their own child’s year, approves it, exports it, and can revoke it at any time. No counts, ranks, or scores appear in the family view — the Keepsake is your child’s year, seen, not scored. Three fail-closed walls protect every request. Consent is checked at assembly and again at delivery. The digital keepsake is free; the printed one is not yet enabled.

What is shipped and what is not — plainly

Three faces shipped. Printed Keepsake not enabled. No live checkout.

Coverage is shipped and in production (ea57afea): the school-wide cross-publication gap report, the per-lens equity breakdowns, the “never appeared once” list, the Gini coefficients, the suggests-not-awards guard, and the staff-only wall are all live. Letters is shipped (a5afaf2f): the human-written letter with the closed merge-token set, the no-AI guard test, and the draft → in-review → final sign-off lifecycle. The Keepsake is shipped (a5afaf2f): compile, approve, export, revoke, transfer-majority, consent at assembly, consent at delivery, the no-counts family view, and the three-wall access control. The teacher contribution pipeline is shipped (83bca642): consent-before-candidacy, held-never-auto-clears, the held→picked forbidden rule.

Not yet enabled: the printed Keepsake. The printed keepsake ships turned off in code by default. Every order intent is queued and not sent. No money moves. There is no price, no checkout, and no order form today. We will say so clearly when it is enabled.

Connected to the school publishing platform

Seen makes sure every child is on a page. The platform builds the page. The fund covers the cost.

homeroom.software is the publishing platform: the yearbook, newspaper, newsletter, and literary magazine engine that builds the book Seen makes sure every child is in. yearbook.press is the complete yearbook programme: design, photos, proofing, print, and distribution in one place. yearbook.fund is the giving layer: the campaign and giving platform that sponsors yearbooks for students who cannot afford one — the fund gives them the copy, and Seen makes sure they are in it.

Free for the school · Advisers, staff, and principals · 2026

Book a conversation to see the current state honestly

Seen is in production. The conversation shows the current state honestly: the Coverage gap report, the Letters lifecycle, the Keepsake access model, the teacher contribution pipeline, and exactly what the printed-Keepsake timeline looks like. There is no pricing commitment and no signup. Free for the school. The CTA is a conversation.

To book: email [email protected].

FAQ

Common questions

What is Seen?

Seen is the noticing engine for the adults who serve kids — not a student app. It has three shipped faces. Coverage is a school-wide, cross-publication dashboard that shows an adviser which students have never appeared in any publication this year. Letters is the human-written witness letter, with no AI path by architecture. Keepsake is a family-compiled, family-owned collection of your child’s year, revocable at any time. Seen audits the institution. It never profiles a child.

Is Seen free for the school?

Yes. Seen is free for the school — it enters at no charge. A school does not need to switch a print contract, cancel anything, or buy a book to use it. It works alongside whatever publishing programme the school already runs. There is no signup, no billing, and no pricing commitment. The CTA is a conversation — book one, see the current state honestly, and decide whether it fits your programme.

What does “the algorithm suggests, a human decides” mean?

The Coverage face exposes no method that writes, awards, ranks, notifies, or publishes anything. Every output is a read-only aggregate: the list of students who have never appeared, broken down by grade and homeroom. The report can only suggest where to look. An adviser reads the list and decides to place a student — through the existing place lane in the publishing platform — or not. Seen never places a student, recognises a student, or awards a student automatically. This is structural: the guard test asserts it on the dependency graph, not just in a policy document.

Who can see the Coverage dashboard?

Editorial staff, school administrators, and district administrators only. A parent, a student, or a studio representative gets a 403. This is enforced at the route level by requireCoverageViewer and tested in the readonly-guard test. The report returns names and counts only — never image references or photo URLs.

Does the Coverage report span only the yearbook, or all publications?

All publications the school runs: the yearbook, the newspaper, the news-site, and the literary magazine — in one report. The service unions the yearbook page-student ledger with story-based surfaces (newspaper, news-site, literary magazine) so a student who appeared in the newspaper but never in the yearbook shows up correctly as “appeared somewhere.” A surface with nothing tagged says so plainly — the report shows which surfaces are instrumented and which are not.

Is there really no AI path in the witness letter?

Yes — by architecture, not just by policy. The witness-letter domain module has a guard test that asserts three things on the dependency graph: no export has generation semantics (generate, complete, synthesize, autocompose, llm, gpt, claude, anthropic); every export is synchronous (an async function proves a live inference call could be there; sync-only proves it cannot); and no AI-package identifier appears in any function source. If someone adds an AI path to the module, the guard test fails and the commit is blocked. The letter is written by a human who knows the child. That is not a preference setting — it is a structural fact.

What happens if a merge token in a witness letter is unrecognised?

The entire letter is withheld. renderWitnessMergeBody returns {ok: false, reason: “unknown_token”} and the platform does not emit the letter. It is never auto-filled with blank praise or a placeholder. The adviser is notified that the letter has an unknown token and must correct it before it can go out.

Who can access the Keepsake?

Only a verified guardian of that specific student. Three fail-closed walls protect every request: requireSchool (tenant isolation, schoolId from the path), denyStudentData (a studio rep is hard-denied), and isGuardianOfStudent (awaited, re-resolved fresh on every request — a revoked or transferred relationship goes dark on the next call). The keepsake is never public, never student-facing, and never indexable.

No counts, ranks, or scores — what does the Keepsake actually contain?

The Keepsake is a qualitative collection: the appearances the guardian selected, the witness letter addressed to that student (after the adviser marks it final), and group photos that passed the consent remediation check. The family view type structurally omits every numeric aggregate — there is no count of appearances, no ranking, no score. A guard test enforces this at the type level. The keepsake is the year as a family remembers it, not a performance record.

Is the printed Keepsake available?

Not yet. The digital export is free and works. The printed keepsake is honest-off: it ships turned off in code by default, every order intent is queued and not sent, and no money moves. A per-copy book needs variable-data and per-copy-binding capability; every current printer target fails the default-deny check. We will say so clearly when it is enabled. There is no live checkout, no price, and no order form today.

Does Seen do facial recognition or auto-tagging?

No. The Coverage face reads pre-resolved rows — placements and subjects already tagged by a human or the existing tagging workflow. The Keepsake assembly reads the same resolved rows. Neither module face-matches, auto-identifies, or runs any inference on a student’s photo. Seen finds coverage gaps from the ledger. It does not find children by face.

Does Seen have any student-facing surfaces?

None. There are no student logins, no student views, no student notifications, and no student-facing surface at all. Coverage is for editorial staff and administrators. Letters are written by staff advisers and go to families (via the Keepsake). The Keepsake is for a verified guardian, not the student. The absence of engagement mechanics is deliberate: no streaks, no rankings, no leaderboards. This is the opposite of a growth-hacked student app, and we think that matters.