Letter Software · official school correspondence · early access
Write the official letter once. The merge engine addresses it to every family.
Home letters, mail-merge letters, and official family correspondence — authored from one source, personalized per family off the roster, consent-gated at emit, and routed to print or to delivery.
The office writes an official letter one time. The variable-data mail-merge engine clones it per family — a distinct, addressed copy each — filling {{first_name}}, {{grade}}, and the roster fields you choose, consent-filtered and sanitized fail-closed. Who receives it resolves off the one imported roster through the targeting selector, never a side list kept by hand. Any letter that names a student routes through the consent gate at the moment the detail would be emitted, so correspondence stays private to the family it names — never public, never sold. The authoring and the merge run today; the outbound send is honest early-access, and we name that plainly rather than claim a live send.
Mail-merge engine: one source, personalized per family
This is the official-correspondence authoring desk — distinct from frontoffice.press (the school’s public voice) and from mailing.software (the physical print-and-post pipeline). The plain-language catalog of every module is at schoolsoftware.app; the full platform story is at homeroom.software.
The surfaces, marked plainly
Three built rails, and two legs named as early-access
The mail-merge engine, the roster-scoped targeting, and the consent gate are built and run today. The two outbound legs — the live send and the print-and-post leg — are honest early-access. Each is marked for exactly what it is.
Mail merge
One authored letter, personalized for every family
You write the official letter once, and the variable-data mail-merge engine clones it per recipient — a distinct, addressed copy for each family — filling {{first_name}}, {{grade}}, {{homeroom}}, and the fields you choose from the one imported roster. The recipient set is consent-filtered, and every merged value is sanitized fail-closed, so a token that has no value on file resolves to nothing rather than leaking a placeholder or a stray record. It is the same variable-data flat-paper rail that sets report cards and yearbook pages, pointed at the office’s correspondence. You author the source; the engine sets the copies.
Mail-merge engine: built
Roster-scoped audience
Who the letter is for resolves off the roster, not a side list
Who receives a letter resolves off the one imported roster through the shared targeting selector: the whole school, a role group, a grade level, a bus route, a named custom group, or a single individual. Exactly one selector column matches the chosen kind, so an audience is a precise projection of the roster the office already maintains — never a parallel mailing list kept by hand in a spreadsheet. Single-tenant isolation walls the roster to one school, so a letter scoped to one school is never resolvable against another school’s families.
Roster targeting: built
Consent-gated
Any student-coupled letter body is consent-gated at emit
A letter that discloses a student-coupled detail — a name, a grade, an award tied to a child — routes through the shared consent chokepoint at the emit boundary, the same FERPA posture the grade and report-card surfaces enforce. The check happens the moment the detail would be emitted into a copy, not in a reviewer’s memory and not left in the database: a coupled detail without consent on file is not emitted, and the recipient set is resolved THROUGH consent so an unconsented family is never even addressed. Official correspondence is private to the family it names — never public, and never sold.
Consent gate: built
One source, two legs
One authored source, routed to print or to delivery
The finished, merged letter leaves the desk by one of two legs, and the authoring never changes between them. The print leg hands the print-ready copies to mailing.software for the postal run — addressed, printed, and mailed to a home address. The delivery leg hands the same copies to the comms engine to reach a consented family channel. The authoring and the merge are built and run today; both outbound legs are honest early-access, named plainly below rather than presented as live.
Routing: authoring built, both legs early-access
Live send
The live send is honest-off, named plainly
The actual outbound send — pushing a letter to a family channel or dropping a printed copy in the mail — is honest early-access. The dispatch plan starts provider_not_provisioned with zero counts and the route exposes the send seam as a 503; the engine never fabricates a send or invents a delivery it did not make. What is available today is authoring the letter, cloning it per recipient on the merge engine, scoping the audience off the roster, and clearing every student-coupled disclosure through the consent gate. The send itself is the early-access step, and this page does not claim it is live.
Live send: honest-off (provider_not_provisioned)
How a letter moves
From one authored source to a routed, per-family copy
The flow is short and the authoring never changes. The office writes once; the engine personalizes and scopes; the consent gate clears every student-coupled disclosure at emit; and the finished letter routes to print or to delivery. The outbound send is the one honest-off step, named plainly.
Step 1 · Author once
The office writes the official letter once
A principal, a secretary, or a club adviser composes the correspondence one time in the authoring surface — a home letter, an official family notice, a per-family update. This is authoring an official letter, not posting a public bulletin: the piece is addressed to families, not to the community at large. The one authored source is the single thing you maintain; everything after it is a projection of what you wrote.
Step 2 · Personalize
The merge engine clones it per recipient
The variable-data mail-merge engine clones the letter per subject and fills {{first_name}}, {{grade}}, {{homeroom}}, and any roster field you elected to include. Each family gets its own addressed copy from the one source. Every merged value is sanitized fail-closed — an empty or unknown token resolves to nothing, never a leaked placeholder — and the copies are assembled from the live roster record, not a stale export.
Step 3 · Scope
The audience resolves off the roster
Who the letter reaches is scoped through the targeting selector: all_school, role_group, grade_level, bus_route, custom_group, or individual, with exactly one selector column matching the kind. The audience is a precise projection of the imported roster the office already maintains, single-tenant walled to one school — not a second contact list kept by hand.
Step 4 · Consent-gate
Every student-coupled disclosure clears the gate at emit
If a copy would surface a student-coupled detail, the shared consent chokepoint is checked at the emit boundary, fail-closed. The recipient set is resolved THROUGH consent, so an unconsented family is never addressed, and a coupled detail without consent on file is not emitted into the copy. The check is at emit, message by message — the same FERPA posture the rest of the platform enforces.
Step 5 · Route
The finished letter routes to print or to delivery
The merged, consent-cleared copies leave by one of two legs. The print leg hands print-ready copies to mailing.software for the postal run. The delivery leg hands the same copies to the comms engine for a consented family channel. One authored source, two legs — the authoring and the merge stay identical whichever leg the letter takes.
Step 6 · Honest-off
The live send is named as early-access
The outbound send is honest-off. The dispatch plan starts provider_not_provisioned with zero counts and the route exposes the send seam as a 503; nothing is dispatched and no delivery is fabricated. Authoring, merge, targeting, and the consent gate are built and run today; the send — and the print-and-post leg through mailing.software — is the early-access step, and we say so plainly.
One authored source, two legs
The same letter, routed to print or to delivery
A letter leaves the desk by one of two legs, and the authoring and the merge stay identical whichever it takes. The built work is the authoring and the per-family merge; both outbound legs are honest early-access.
The print leg
A letter meant to arrive on paper — a home letter, an official notice a family keeps — routes to mailing.software for the physical print-and-post run: addressed, printed, and mailed to a home address.
What is built
The authoring and the variable-data merge are built: the print-ready copies are assembled from the one authored source through the same flat-paper rail report cards ride.
What is honest-off
The postal send itself — the print-and-mail vendor handoff — is honest early-access on mailing.software, the same posture mailed report cards carry. No live postal dispatch is wired here.
Print leg: authoring built, postal send early-access
The delivery leg
A letter meant to reach a family channel routes through the mass-notification comms engine: the recipient set is resolved off the roster and through consent, and each consented family is addressed on a channel they have on file.
What is built
The targeting selector and the consent-resolved recipient set are built: an audience is a precise, consent-filtered projection of the roster, never a fabricated recipient.
What is honest-off
The live send is honest-off: the dispatch plan starts provider_not_provisioned with zero counts and the route exposes the seam as a 503. The engine never fabricates a send.
Delivery leg: targeting built, live send honest-off
The print leg cross-links mailing.software for the postal run; the delivery leg rides the mass-notification comms engine. Neither outbound leg is presented as live: the authoring and the merge are built, and the sends are named as the early-access step.
A letter is correspondence — not a publication, not a postal run
Letter Software sits deliberately between two siblings and duplicates neither. It is the authoring desk for official correspondence: a letter written to a family and personalized to that family.
It is not the public voice. Announcements, newsletters, and the school press are a PUBLICATION posted for the community to open, and that lane is frontoffice.press. A letter here is private, per-recipient correspondence — addressed to one family, consent-gated at emit, and never posted to a public surface.
It is not the postal pipeline. Envelopes, address handling, and the print-and-mail vendor handoff are the physical operation, and that lane is mailing.software. Letter Software authors the letter and runs the merge, then hands the finished, print-ready copies to mailing.software for the postal leg. One authors; the other posts.
The point of drawing the lane this tightly is that the one authored source stays canonical. The office maintains a single letter and a single roster projection; the print leg and the delivery leg are two routes off that one source, not two tools with two copies to keep in sync.
FERPA and consent: correspondence gated at the emit boundary
Official correspondence brushes against student-coupled information by its nature — a home letter names a child, a family notice carries a grade. Letter Software treats that boundary as the same FERPA boundary the rest of the platform enforces, checked where the detail would be emitted rather than trusted to a reviewer afterward.
The disclosure check happens at emit. A letter stored in the authoring surface is internal draft content, not a disclosure. The disclosure event is the moment a student-coupled detail would be written into a per-family copy or handed to an outbound leg, and that emission routes through the shared consent chokepoint. The check is fail-closed: a missing, unverified, or withdrawn consent denies the disclosure, and the recipient set is resolved THROUGH consent, so an unconsented family is never even addressed.
The audience is roster-scoped and tenant-isolated. A letter is scoped to families on one school’s imported roster through the targeting selector, and single-tenant isolation at the data layer means a letter for one school is never resolvable against another school’s families. Correspondence stays a single school’s private message to its own families.
Correspondence is never public and never sold. A student-coupled letter is not posted to a public surface and its recipient data is not a product. Letter Software is a for-profit product and makes no charitable or tax-deductible claim about anything on this page. The office reads the imported roster; this surface is SIS-adjacent and does not own the authoritative record.
The outbound legs: named plainly as early-access
The honest-off surfaces on this page are the two outbound legs. The authoring, the merge, the targeting, and the consent gate are built; the sends are the early-access step, and the page never presents a send as available today.
Live send: honest-off
Pushing a letter to a family channel is the outbound send leg. The dispatch plan starts provider_not_provisioned with zero counts and the route exposes the send seam as a 503; the engine never fabricates a send or invents a delivery. What is available today is authoring the letter, cloning it per family, scoping the audience, and clearing the consent gate. Early access — live send
Print-and-post: early-access via mailing.software
A letter that arrives on paper routes to mailing.software for the postal run — addressed, printed, and mailed to a home address. The print-ready generation is built through the variable-data flat-paper rail; the postal send is honest early-access on mailing.software, the same posture mailed report cards carry. Early access — postal send
What is available today
The office can author an official letter, clone it per family on the mail-merge engine, scope the audience off the roster through the targeting selector, and clear every student-coupled disclosure through the consent gate at emit. That is the built surface. The outbound send — delivery or print-and-post — is the early-access leg, and this page says so plainly.
No pricing, no checkout
Money is honest-off across the platform. There is no pricing, no checkout, and nothing to buy or subscribe to on this page. The next step is a conversation. Money honest-off
Common questions
Straight answers on what is built, what is honest-off, and how Letter Software stays distinct from the public-voice and physical-post lanes.
How is this different from the school newsletter or announcements page?
A newsletter or announcement is the school’s PUBLIC voice — a publication posted as an online edition anyone can open, which is frontoffice.press. Letter Software is PRIVATE, per-recipient official correspondence: a letter addressed to one family, personalized from the roster, consent-gated, and never posted publicly. A letter is not a publication; it is correspondence.
How is this different from the physical mailing tool?
mailing.software owns the physical print-and-post pipeline — envelopes, address handling, the postal vendor handoff. Letter Software owns the AUTHORING and the merge: the one authored source and the per-recipient copies. When a letter needs to arrive on paper, Letter Software hands the finished, merged copies to mailing.software for the postal leg. The two do not overlap: one authors, the other posts.
Can Letter Software send a letter to families today?
It can author the letter once, clone it per family on the mail-merge engine, scope the audience off the roster, and clear every student-coupled disclosure through the consent gate. The live send is honest early-access: the dispatch plan starts provider_not_provisioned with zero counts and the send seam is exposed as a 503. The page does not claim a live send — authoring and merge are built; the outbound send is the early-access step.
What does the mail-merge engine actually do?
It is a variable-data engine: it clones the one authored letter per recipient and fills {{first_name}}, {{grade}}, {{homeroom}}, and any roster field you include, producing a distinct addressed copy for each family. The recipient set is consent-filtered and every value is sanitized fail-closed, so an unknown token resolves to nothing rather than leaking a placeholder. It is the same variable-data flat-paper rail that sets report cards and yearbook pages.
How is the audience for a letter decided?
Off the one imported roster, through the targeting selector: all_school, role_group, grade_level, bus_route, custom_group, or individual, with exactly one selector column matching the kind. The audience is a precise projection of the roster the office already maintains — not a second mailing list — and single-tenant isolation means a letter scoped to one school is never resolvable against another school’s families.
What stops a letter from exposing a student's information?
The consent gate at the emit boundary. Any letter that would disclose a student-coupled detail routes through the shared consent chokepoint the moment the detail would be emitted. It is fail-closed: a coupled detail without consent on file is not emitted, and the recipient set is resolved THROUGH consent so an unconsented family is never addressed. The check is at emit, not in a reviewer’s memory and not in the database.
What is the difference between the print leg and the delivery leg?
One authored source, two legs. The print leg routes the print-ready copies to mailing.software for the postal run — addressed, printed, mailed to a home address. The delivery leg routes the same copies through the comms engine to a consented family channel. The authoring and the merge are identical for both; only the outbound leg differs, and both legs are honest early-access.
Is any student-coupled correspondence ever public or sold?
No. Official correspondence is private to the family it names. A student-coupled letter is consent-gated at emit, never posted to a public surface, and never sold. Letter Software is a for-profit product, and it makes no charitable or tax-deductible claim about anything on this page.
Does the office keep a separate contact list?
No. The audience is a projection of the one imported roster, not a hand-kept mailing list. A family that leaves the roster leaves the audience on the next import; a family that joins is scoped the same way. The office authors against the one roster the platform already holds.
Is there pricing or a checkout on this page?
No. Money is honest-off across the platform: there is no pricing, no checkout, and nothing to buy or subscribe to on this page. The next step is a conversation — email [email protected] and we will point you to the right door.
How does this connect to the rest of the platform?
Letter Software shares the roster, the consent substrate, and the variable-data flat-paper rail with the rest of the platform. It cross-links frontoffice.press for the public voice, mailing.software for the print-and-post leg, and the plain-language module catalog at schoolsoftware.app. The full platform story is at homeroom.software.
Related surfaces
Letter Software connects to the rest of the platform through the shared roster, the consent substrate, and the variable-data flat-paper rail. These destinations cover the adjacent surfaces — the public voice, the print-and-post leg, the catalog, and the full platform.
The school’s public voice: announcements, newsletters, and the school press posted as an online edition anyone can open. The distinct sibling — that lane is a public publication; a letter here is private, per-recipient correspondence.
The physical print-and-post pipeline: envelopes, address handling, the postal vendor handoff. Letter Software authors and merges the letter, then hands the finished copies here for the print leg. One authors, the other posts.
The plain-language K–12 module catalog front door, where an administrator scans every built module with honest per-module status. Official correspondence is one line item there; this page is its full home.
The flagship platform brand home: the full product story and the complete picture of the roster, the consent substrate, and the variable-data flat-paper rail Letter Software builds on.
What is built and what is honest early-access
We describe Letter Software as it is. The left column is built and running today. The right column is named plainly as honest early-access. No claim outruns the code, no competitor is named, and there is no pricing or checkout anywhere on this page.
Built and running today
The mail-merge engine. One authored letter, cloned per recipient with {{token}} personalization off the roster, consent-filtered and sanitized fail-closed. The variable-data flat-paper rail that sets report cards and yearbook pages, pointed at correspondence. Built
Roster-scoped targeting. The audience resolves off the one imported roster through the targeting selector (all_school, role_group, grade_level, bus_route, custom_group, individual), single-tenant walled to one school. A projection of the roster, never a hand-kept list. Built
The consent gate at emit. Any student-coupled letter body routes through the shared consent chokepoint at the emit boundary, fail-closed. The recipient set is resolved through consent; a coupled detail without consent on file is not emitted. Correspondence is never public and never sold. Built
Honest-off, named plainly
The live send. The outbound send is honest early-access. The dispatch plan starts provider_not_provisioned with zero counts and the send seam is exposed as a 503. The engine never fabricates a send, and this page does not claim a live send. Honest-off
The print-and-post leg. A letter that arrives on paper routes to mailing.software for the postal run. The print-ready generation is built through the flat-paper rail; the postal send is honest early-access on mailing.software, the same posture mailed report cards carry. Honest-off
Money. There is no pricing, no checkout, and nothing to buy or subscribe to on this page. Money is honest-off across the platform. Letter Software is a for-profit product and makes no charitable or tax-deductible claim. Honest-off
Any student-coupled letter is consent-gated at the emit boundary, fail-closed — correspondence is never public and never sold. Letter Software is a for-profit product and makes no charitable or tax-deductible claim. The live send starts provider_not_provisioned and is not claimed live; the print leg is early-access on mailing.software.