Digital assurance ยท Quarterly service

Making a multi-site education estate governable

A repeatable assurance model for maintenance, recovery, security, access, performance and accountable decisions across a complex school web estate.

  • WordPress and WP-CLI
  • Cloudflare
  • Lighthouse

Context

Anglian Learning operates a substantial group of school and trust websites. The contracted quarterly maintenance service covers 20 websites across two managed servers.

At this scale, software updates alone cannot demonstrate that the estate remains dependable. The organisation needs visible evidence covering recovery, security, functionality, performance, access and outstanding risk.

The challenge

The work needed to become a governable service rather than a collection of technical tasks.

That meant defining the scope, checks, evidence, change boundaries, exception handling and reporting so that another person could understand what was inspected, what changed and which decisions remained open.

My role

I designed the quarterly operating sequence, evidence requirements, rollback boundaries and client reporting. I coordinate maintenance across the estate and retain responsibility for exceptions, remediation decisions and communication about risk.

I also led a privileged-access review across the wider hosted estate without taking ownership decisions away from accountable stakeholders.

The assurance model

Each cycle covers:

  1. Confirming the estate and intended scope.
  2. Verifying backups and recovery arrangements before change.
  3. Reviewing application, certificate and server health.
  4. Applying controlled maintenance with rollback available.
  5. Testing forms and important user journeys.
  6. Reviewing security, access and performance evidence.
  7. Recording exceptions, follow-up work and accountable owners.
  8. Providing a client-readable report rather than an unexplained technical log.

Automation gathers consistent evidence and highlights anomalies. Direct checks and technical judgement remain part of every significant change.

Access governance

The access review covered the wider hosted estate, mapping administrator access and presenting the evidence needed for ownership decisions.

The review established a stronger authentication baseline, preserved essential recovery access and left account-removal decisions with the people accountable for each service rather than applying them automatically.

Outcome

The trust has a repeatable quarterly assurance model covering backups, updates, security, rollback, forms, key journeys, performance and reporting.

The access work made privileged access visible and governable without trading resilience for tidiness or allowing a technical supplier to make organisational ownership decisions unilaterally.

Evidence and limits

Exact account and assignment figures are not published. The case study does not claim every recommended account was removed. Its value is the operating model, evidence and accountable decision process.