Roadmap and Known Limitations
What we have, and what we do not have yet
Every product has limits. These are ours, found by reviewing our own code, so your evaluation team does not have to discover them the hard way. Roadmap items carry no delivery dates unless a contract says otherwise.
Last reviewed: September 2026
Product status
Available now
- AtlasOA: outcomes library, curriculum mapping, assessment results, closing-the-loop records and narratives, accreditation evidence packages, trends, early intervention, competency frameworks, annual planning, course evaluations, and the self-directed 30-day evaluation.
- Atlas K-12: the seven-pillar whole-child model, tiering from district thresholds, intervention plans and progress monitoring, Care Teams, Smart Groups, SEL surveys, the strategy library and technique catalog, Compass AI, and Microsoft Entra single sign-on.
- Full release history: changelog.
In development
- Confirming SIS and LMS connectors against live production systems (see Integrations).
- Code-signed installers, pending a code-signing certificate.
Planned
- AtlasOA: Workday Student integration.
- Atlas K-12: in-app notifications, Care Team meeting scheduling with invitations, attendance counseling forms, one-click PDF student progress reports, welcome emails for new users, LMS integrations, screener import presets, a public REST API, and a family report.
More detail is on the roadmap page and in the roadmap section of the changelog.
Known limitations
Both products
- Windows only; Linux and macOS servers are not supported.
- Self-hosted only; no hosted (SaaS) option and no shared multi-institution installation.
- One server with a SQLite database; no built-in high availability or replication.
- HTTPS requires a reverse proxy such as IIS; the applications serve HTTP themselves.
- The database, uploads, and backups are not encrypted by the application; use disk encryption.
- No multi-factor authentication for local accounts.
- Sign-in rate limiting is per IP address and resets when the application restarts. Behind a reverse proxy it must be configured to see real client addresses.
- Installers are not code-signed yet.
- No single "export everything" button, and no in-app tool to delete or anonymize one student's records.
- Staff browsers load web fonts from Google (and, in Atlas K-12, a charting library from jsDelivr).
- Not yet evaluated for accessibility; no VPAT. See Accessibility.
- No third-party penetration test or formal attestation yet. See Independent validation.
- No published supported-versions policy yet.
AtlasOA
- No single sign-on (SAML, OIDC, or LDAP).
- No per-program or per-department scoping: users with read permission see all programs.
- Some administration screens and attachment actions check that a user is signed in rather than the specific permission. Until this is corrected, give accounts only to trusted staff.
- Formula-injection protection covers competency framework and evidence-package data; other exports do not have it yet.
- Canvas and Moodle API tokens are not yet encrypted in the local connection settings file.
- Password minimum length is enforced only when users change their own password.
- In the installed build, the audit log file and offsite-backup settings sit in the application folder, so uninstalling removes them; back them up. Offsite copies to SFTP and S3 need additional components.
- LMS and SIS connectors are in beta: none has yet run against a live campus system.
- No bulk download of all attachments.
Atlas K-12
- Teachers see all students at their school, not only their own classes.
- Microsoft Entra is the only single sign-on option, for one tenant; Google Workspace sign-in is not available.
- No self-service password reset.
- Deactivating a user blocks their next sign-in; an open session can continue for up to 8 hours.
- Backups are started manually; there is no schedule, rotation, or restore screen.
- No screen to browse or export the full audit log; the Security Health page shows summaries and chain status. No automatic audit-log retention setting.
- SIS API connectors are in beta; grade sync through them is being confirmed. OneRoster does not carry attendance or behavior.
- The SIS connection test shows administrators the raw error text returned by the SIS.
- Compass does not mask names typed into questions, and keeps conversation history in the browser until sign-out.
- The content security policy still permits inline scripts.
- In air-gapped installations, charts may not display because the charting library loads from the internet.
If a limitation matters to your decision, ask us whether it is planned. We will tell you plainly.
Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.