Roadmap
This is where First Six is heading. It is organised by horizon rather than by date ("in progress", "next", and "exploring"), because a direction is more useful than a calendar we would only have to walk back. Items move up the list as they get closer, and shipped work moves off it and into the changelog.
This is a direction, not a contract. Nothing here is a dated commitment, and the order can change as pilots tell us what matters most. Where a security or compliance item below affects a procurement decision, we're happy to write it into an agreement as a milestone. See HECVAT and vendor security reviews.
In progress
Work that is actively underway.
- SAML federation: the production sign-in path is OIDC, live with Microsoft Entra. A SAML proof-of-concept exists; converging a real SAML-federated institution onto the same identity-linking path is the work in flight. Raise it early if SAML is a hard requirement. See the OIDC flow.
- Data Processing Agreement: done. A signable template has existed since 13 July 2026, so institutions sign a ready document rather than drafting one from scratch. It is reviewed and approved in-house, not by external counsel.
- Production / non-production separation: done, August 2026. A separate non-production project was stood up in July 2026 and schema changes land on both; preview and development builds moved onto it and the rule is now enforced in code, so a deployment that is not production fails to build against the production database. The residual we keep naming is that both projects sit in one cloud organisation. Set out in our vendor security responses.
- Content-Security-Policy enforcement: a nonce-based CSP runs in report-only today; moving it to enforcing after the violation review.
Next
Scoped and expected to start once the in-progress work lands.
- SOC 2 readiness, then attestation: the technical controls a SOC 2 looks for are largely in place; the work ahead is the formal readiness program and an independent audit.
- Independent penetration test: a third-party test we're happy to make a contractual condition of a pilot.
- Independent accessibility audit: the VPAT is published (VPAT 2.5, covering WCAG 2.1 AA, Section 508 and EN 301 549), but it is our own evaluation. A third-party audit to verify it, and remediation of the criteria it rates Does Not Support, are the next step. See our accessibility commitment.
- Programmatic bulk export: signed outbound webhooks have shipped (help-request events). See the changelog; a documented bulk export API for a data warehouse is still planned. Today's data-out options are webhooks and on-demand CSV export.
- Reach: content-engagement analytics. See which content students actually open, and how engagement trends week to week, per audience. Previously shipped, temporarily removed; returning in a future release.
Exploring
Directions we think are right but haven't fully scoped. Less certain, and more likely to change shape.
- SMS crisis alerts: an optional text-message channel for crisis paging, on top of the email and Slack or Teams alerts, for responders who want a buzz on their phone. Crisis alerts today reach your team by email always, plus an optional Slack or Teams webhook and an optional crisis help-desk queue; a dedicated SMS channel is a candidate to add if institutions ask for it.
- ISO 27001: a natural companion to SOC 2 once that program is mature.
- Deeper SIS automation: reducing the manual steps in keeping rosters in sync. See SIS sync.
- Semantic search across this knowledge base: finding the right article by meaning, not just keyword.
What shapes this list
Two things move items up. The first is safety and trust: anything that protects student data or makes an institution's review faster tends to jump the queue. The second is what pilots ask for: real usage beats our guesses about priority, so the list bends toward what customers actually hit.
What you won't find here are features that overstate what the product does: individual-student prediction, causal claims about retention, or anything that positions First Six as a replacement for professional support. Those aren't "later", they're deliberate non-goals.
Common questions
Do these items have dates?
No, and on purpose. The horizons (in progress, next, exploring) reflect how close something is, not a promised quarter. For a security or compliance item that affects your decision, we can commit to it as a milestone in an agreement.
How do I request something that isn't here?
Tell us through your usual First Six contact, or the feedback link in the product. Requests that show up across multiple institutions are the ones most likely to move up.
Where do I see what's already shipped?
In the changelog, newest first. When something on this page ships, it moves off the roadmap and earns a dated changelog entry.
Related
The fastest answer is usually one question away.