Control statement v1.0 · Effective 18 August 2026
Institutional operating posture

Governed learning, explicit authority, reconstructable administration.

This statement describes the Academy controls available for institutional cohort delivery and the limits that remain with Terra Vita, the contracting institution and authorised human reviewers.

Reliance boundary. This control statement describes Terra Vita Academy’s operating design. It is not an ISO certification, independent assurance opinion, accreditation, regulator approval, security guarantee or substitute for an institution’s procurement, privacy, information-security or legal review.
G1

Identity and access

Private routes, training media and participant downloads require a signed, time-limited server session. Participant and administrator permissions are separated.

Server enforced
G2

Assessment separation

Automated scoring and TV-AI provide learning feedback only. They cannot issue a certificate or turn training performance into institutional approval.

Advisory only
G3

Human certificate authority

Authorised administrators review completion evidence and remain accountable for issue, correction, reissue and revocation.

Human decision
G4

Record traceability

Participant, progress, simulation, knowledge-check, feedback, acknowledgement and certificate records are separated and time-stamped in the configured Academy database.

Traceable
G5

Public-safe verification

The verification route exposes only bounded certificate fields. Answers, coaching notes, login events and private progress are not part of the public record.

Data minimised
G6

AI governance

TV-AI is authenticated, clearly labelled, assessment-aware, multilingual and unable to write back to source records.

No writeback
Control matrix

What is controlled, who decides, and what is retained.

Control areaAcademy mechanismAccountable authorityBoundary / evidence
Participant eligibilityNamed participant record, organisation and cohort reference.Terra Vita Academy administrator or institution-designated cohort owner.Registration alone does not create access.
AuthenticationHashed access code verification, server-signed session, expiry and logout.Terra Vita Academy administrator.Browser state is not treated as the security boundary.
Training progressModule and simulation events linked to the participant and cohort.Participant for completion; Academy administrator for record administration.Opening a page is not evidence of competence.
Learning feedbackAutomated feedback, practice routes and optional admin coaching.Participant and authorised reviewer.Feedback is formative and does not create institutional reliance.
TV-AI supportBounded multilingual explanation and Socratic hints.Participant for their work; authorised humans for all decisions.No assessment answers, progress writeback or certificate authority.
CertificateAdmin review, unique number, verification code, status and revocation route.Authorised Terra Vita Academy administrator.Certificate of completion, not professional accreditation or project assurance.
Cohort reportingBounded aggregate or named reporting as agreed with the institution.Contracting institution and Terra Vita.Disclosure scope must be recorded before cohort launch.
Incident responseAccess suspension, credential reset, audit-event review and correction route.Terra Vita Academy administrator; institutional contact where applicable.Material incidents require documented handling under the applicable agreement.
Institutional onboarding

Controls that must be confirmed before a cohort opens.

  • Named institutional owner and Terra Vita cohort administrator.
  • Participant scope, purpose, delivery period and support route.
  • Applicable terms, data-controller/processor roles and reporting scope.
  • Retention criteria and any institution-specific deletion requirement.
  • Language and accessibility needs.
  • Certificate wording and whether individual names may appear in institutional reports.
  • Escalation route for access, privacy, security and content issues.

Release gate

  1. Access and database configuration checked.
  2. Private-route and administrator-role tests passed.
  3. Data-use notice version confirmed.
  4. TV-AI provider and boundaries checked, if enabled.
  5. Certificate policy and public verification tested.
  6. Named human administrator accepts launch responsibility.

Current release posture

Release v64 introduces server-enforced Academy sessions, administrative route enforcement, protected media and downloads, a bounded multilingual TV-AI guide, explicit AI-use rules, strengthened security headers, accessibility controls and versioned institutional policy pages.

Deployment condition. An external cohort should open only after the live environment’s session secret, Academy database functions, email route, TV-AI provider configuration and certificate verification route have passed the administrator launch check.