AI Tools & Solutions

Who Controls What an AI Tutor Can Access in Your LMS?

September 10, 2026
7 min
Written by
LinkedIn
Lecture hall viewed from above and behind, showing rows of students seated at desks with notebooks, laptops, and water bottles, facing a presenter standing at a podium near a projector screen at the front of the room.

When an institution adds a LearnWise AI tutor to its learning environment, one question matters more than any feature: who decides what the tutor can see, and how is instructor work protected? For faculty, the concern is concrete. Course materials may be their intellectual property, and connecting them to any third-party system raises fair questions about access, consent, and control.

This guide explains how access works with LearnWise's AI Student Tutor. What it can reach, who sets that scope, what happens to institutional data, and where the institution's own governance decisions begin. Two commitments hold throughout: content connected to LearnWise is never used to train AI models, and the institution, not LearnWise, decides what the tutor can access and how it is used. 

Who decides what course materials an AI tutor can access?

The institution and its authorized instructors choose which courses and content the LearnWise AI Student Tutor can use, scoped by course, content source, content type and user role. The tutor does not receive blanket access to the learning management system by default, only chosen information.

When an administrator connects courses in their LMS, they choose which content types the assistant may draw from, such as pages, files, quizzes, assignments, and announcements, rather than pointing it at everything in the course. A separate file setting controls whether the assistant uses all course files or only files reachable through published modules and pages, so hidden or student-inaccessible files are skipped. During indexing, LearnWise adds only the connected courses and configured content types to the tutor’s knowledge base. It does not add the wider LMS, LMS gradebook records, student submissions, or materials from unconnected courses to that knowledge base. This walled-garden approach is the same principle described in the AI in the LMS guide.

When a student asks a question, the tutor draws only from what that specific student is enrolled in and permitted to see, mirroring their existing course access in the LMS. A student enrolled in one course and one module of that course, for example, is only ever shown material from that course and that module; content from other courses, unpublished material, content gated behind release conditions the student has not met, and instructor-only resources are never surfaced to them. Administrators also control where the assistant appears, and can limit it to specific courses using an allow or block list. 

How does LearnWise protect instructors' intellectual property?

LearnWise draws only on the courses and content types an institution connects, scoped at the course and content-type level rather than per individual document, and that content is not used to train AI models. There is no default access, and the assistant does not reach beyond the scope the institution sets. 

The intellectual property question has two parts. The first is technical: what the software can and cannot access, which is governed by the scoping controls above. The second is contractual and institutional: whether a given institution has the authority to authorize a particular processing arrangement, given its own IP policies and faculty agreements. 

The institution is responsible for ensuring that it has the necessary rights, licences, consents and authority to make those materials available, including materials created by instructors, students or third parties. LearnWise does not acquire ownership of those materials and does not process them beyond the institution’s documented instructions and the rights granted under the applicable agreement. LearnWise’s Trust Center provides supporting information and general policies, but it does not replace the institution-specific terms and conditions. 

Can instructors control which materials are used in their own courses?

Within a clear division of roles. The courses and content types connected to the tutor are scoped at the administrator level, so an instructor cannot individually add or remove specific sources ingested from the connected LMS course. Excluding a course or content type so the assistant is not active in it, is an administrator function and exclusive to the institution using the assistant.

Where the institution enables teacher customization, instructors get control over their own course experience without changing those underlying institutional controls. They can add their own supporting files to a course, in formats including PDF, Word, plain text, and Markdown, and remove any file they add, with administrators able to review, download, relink, or remove those files at any time. They can also shape how the tutor works at the course level: adding course-specific shortcut buttons, setting a welcome message, adjusting the tutor's nickname, and adding instructor information such as office hours or contact details. This includes setting the tone and pedagogical approach of the tutor's responses, such as a warmer, more encouraging tone or a Socratic style that guides students to an answer rather than stating it outright. Institution-set defaults and administrator controls remain in place throughout, so customization gives instructors local ownership while governance stays with the institution.

Is institutional data used to train AI models, and where is it stored?

Content connected to LearnWise is not used to train, fine-tune, or improve AI models, whether LearnWise's own or those of the underlying providers, and it is not shared across institutions. This is the concern most institutions raise first, so we ensure to answer it directly: connecting course content lets the tutor look it up to answer a student's question, and it is never used to train, fine-tune, or improve any model, LearnWise's or a provider's. 

That is the key difference from generic chatbots like ChatGPT: LearnWise operates on authenticated, institution-approved course data, such as connected course content and lecture materials, so students can ask questions and generate study aids grounded in their actual course. Those materials are used to deliver the tutor experience, not to train a general-purpose AI model.

LearnWise uses established enterprise AI providers to generate responses, and connected course content is processed by those providers only under LearnWise's approved subprocessor and data-processing terms to deliver the service, not to train models. How LearnWise coordinates multiple models while keeping answers grounded in institutional sources is described in how LearnWise uses LLMs safely. Institutional data is logically segregated by institution and assistant, access-controlled, and encrypted in transit and at rest. It is stored in the institution's primary region, with options across the UK, EU (Ireland), United States, Canada, and Australia, and kept within that region by default.

On data retention: during an active engagement, connected content and conversation data are kept for the duration of the agreement as needed to provide the service. After an engagement ends, institutional data is retained for a limited period of up to 90 days, after which it is returned or deleted according to the institution's instruction, with a deletion certificate available on request. The Trust Center is the authoritative reference for storage, residency, retention, segregation, and subprocessor commitments.

How should institutions roll out AI tutoring responsibly?

Responsible rollout is institution-led. The institution defines the scope, decides which courses are included or excluded, and involves faculty in those decisions rather than having them made on faculty's behalf. This is a governance exercise, not only a technical one.

Faculty involvement is a safeguard, not a formality, and works best as consultation before deployment. The controls exist to support that: scope, source connection, role-based access, and course inclusion are all configurable and reversible, and courses can be added or excluded through an administrator-managed allow or block list. This is also where AI tutoring aligns with an institution's wider AI position. Our guide to AI governance in higher education sets out how to govern AI inside the LMS, from role-based access to audit and human oversight, and the AI Student Tutor product page shows how the assistant is configured for students in practice.

Does an AI tutor replace instructors?

No. An AI tutor supports learning by helping students work through the course material they already have, and it does not replace instructors. Instructors and administrators retain control over what is connected and how the assistant behaves.

The purpose of an AI tutor is to extend the support an institution already offers, giving students a way to ask questions, get explanations, and prepare using their course context at any hour. Much of that demand is routine and self-directed. Across LearnWise usage, study practice is the most common use of the AI tutor, roughly 30% of conversations, where students generate quizzes and practice questions to revise, and around 52% of conversations happen outside standard campus hours. Handling that routine, off-hours demand frees instructors to spend their time on the deeper, more meaningful support humans can provide.That support is grounded in materials the institution chooses to connect and operates within the controls the institution sets. LearnWise is designed to amplify the work of instructors, not to substitute for it, and the instructor's role, along with the institution's authority over its own content, remains central.

Implementing AI-powered tutoring solutions

For institutions weighing an AI tutor, the commitments are consistent. Access is controlled and scoped by the institution, not granted automatically. Content is not used to train AI models and is not shared across institutions. Rollout is an institutional governance decision, made with faculty rather than on their behalf. And the assistant supports instructors rather than replacing them. These commitments are backed by independent certification: LearnWise is certified to ISO/IEC 27001:2022, Cyber Essentials (CE), Cyber Essentials Plus (CE+), and TX-RAMP Level 2, and has completed SOC 2 Type I and Type II attestations. These certifications and assurances are maintained through applicable annual surveillance audits, recurring independent assessments, and renewal cycles. LearnWise also undergoes annual penetration testing and biannual accessibility assessments. In addition, LearnWise complies with applicable EU and UK GDPR requirements, Canada's PIPEDA, and supports institutions' FERPA compliance.

For the full detail on data residency, retention, segregation, subprocessors, and compliance certifications, the Trust Center is the authoritative reference, and the best place for an institution to verify these commitments independently. If you would also like to see how the controls work in practice for your institution, you can book a demo.

Featured use case
Man in blue shirt speaking and gesturing indoors with wooden ceiling beams and brick wall background.
AI driving cost efficiencies and better outcomes
Create an AI assistant
to support your students
Empowering your students with immediate access to AI assistance at any hour.
Book a demo