Sharing lecture notes without exposing student identities

I designed a privacy-safe way for Disability Support Services teams to distribute peer notes without exposing the students involved, while keeping the workflow manageable for the admins running it.

Type
Feature
Project
Genio Notes, then Glean
Role
UX Designer, leading problem framing, scenarios, roles and permissions, prototyping, UX writing and UI through delivery
Area
Disability Support Services note sharing, accessibility, admin workflows, privacy and permissions
Status
Launched January 2023 and still in active use
Glean admin screen for creating a shared collection with fields for collection name, note-takers, recipients and admin notes.

Shared Collections creation flow inside Glean Admin, showing how admins set up note-takers, recipients and context for the collection.

01 · Starting point

The sharing feature already existed. It just was not solving the real workflow.

We were not starting from a blank page. A way to share an individual note already existed, but usage was low. At the same time, Disability Support Services teams were still doing the important work manually.

In one March 2022 conversation, an admin described receiving every event from a peer note-taker herself, then forwarding it to the student who needed it one at a time so the people on either side never had to know who the other person was.

That gave us two useful signals at once: the existing sharing pattern was not being adopted, and the workaround replacing it carried a real operational cost.

The problem was not simply sharing notes. It was sharing them without exposing people or creating another fragile hand-off.

02 · Choosing the model

The research did not give us a unanimous answer.

We tested three directions with three institutions: keep the workflow inside the product, use anonymous identities, or export notes into another system the institution already ran.

Two of the three favoured keeping the workflow inside the product because it preserved oversight and kept the notes where people were already working. The consistent warning was admin effort. Setting up and maintaining the sharing relationship could itself become another job for the support team.

I did not treat that concern as evidence that the native direction was wrong. Admins were already spending time receiving and redistributing notes manually, while exporting would move the workflow back into another system and recreate some of that duplication.

So we pressed ahead with the native model, but with a clearer constraint: the product had to give institutions the control they wanted without making the setup feel heavier than the workaround it was replacing.

01Native sharing
02Anonymous identities
03Export elsewhere

Research did not remove the trade-off. It told us which trade-off we needed to manage.

03 · Designing the trade-off

Control without exposing the people behind the notes.

The design moved away from a bigger share button and towards an admin-managed collection with three clear roles: admins manage, note-takers contribute and recipients access the notes.

Anonymity was part of the model rather than a setting added later. Recipients saw the notes, not the person who contributed them, while admins retained enough visibility to manage the service and assure quality.

We shipped the workflow inside the product while keeping note-takers and recipients anonymous to each other.

We also chose copy rather than live sync. When a recipient copied an event into their account, it became a stable study artefact they could rely on even if the original later changed.

Those decisions gave institutions the oversight that made the native direction valuable, while keeping the student-facing experience deliberately simple.

Decision 01

Minimal roles

Admin, note-taker and recipient each had a clear job instead of a broad permissions matrix.

Decision 02

Anonymous by default

The support relationship stayed hidden between peers while remaining manageable for the institution.

Decision 03

Copy, not sync

Recipients kept a stable version of the notes rather than revising from something that could change underneath them.

04 · Testing the details

Specific feedback became specific changes.

Once an early version existed, usability testing gave us much more precise feedback than the initial discovery work.

One admin assumed “Edit shared collection” would let her edit the events inside it. The action only renamed the collection, so we changed the label to “Rename shared collection”. It was a small copy change, but it removed an incorrect expectation at the point of use.

That is the clearest iteration loop in the project: observe the expectation, identify the mismatch, then change the interface so the action says exactly what it does.

Other testing led to an admin notes field so similar collections could be distinguished more easily, and a faster way to pair one note-taker with several recipients rather than building every relationship separately.

Not every finding required a fix. The contributor and collaborator terminology was understood without explanation, so we left it alone. Testing helped us avoid unnecessary redesign as well as identify what needed changing.

Knowing what not to change was as useful as finding what needed fixing.

05 · What lasted

A small feature with a trust model underneath it.

2023launched
786organisations in recent usage
2,183recent collection opens

Shared Collections launched in January 2023 and remains in active use. The strongest signal for me is not a launch spike, but that the underlying model has continued to support institutions years later.

The case study also changed how I think about research evidence. The useful outcome was not that every participant agreed. It was that the disagreement made the constraint visible early enough to design around it.

Privacy shaped the product model, admin effort shaped the constraint, and usability testing shaped the details. Some findings became changes, while clear terminology was deliberately left alone. Both are evidence that the research was being used rather than simply collected.

The real design work was not the screen. It was deciding which trade-offs the product had to carry well.