Tenure

The operating system for organizational memory

People move on.The know-how stays.

Tenure is the system of record for any organization where people rotate faster than knowledge transfers: clubs, university offices, teams, and growing companies. It keeps finance, events, approvals, members, and memory in one governed place, and Tenure AI turns that record into instant answers, so each new leader is productive in days, not a semester.

Runs alongside the tools you already use. No rip-and-replace. Founding Fall 2026 pilot with Simon's Office of Student Engagement.

Tenure
+ New

Finance

auto-touring ↺

Treasury balance

$12,400

▲ $1,300 · 11.7% this month

$18,000 budget

Budget by category

Events 38%Operations 24%Marketing 16%Reserve 22%
Membership dues, 28 paid+$840Sep 14
Aramark, fall sponsorship+$4,000Oct 2
Rochester Print, banners−$240Oct 9
Gala venue deposit−$1,500Oct 18

Founding Fall 2026 pilot

Startup WednesdaySimon Business School
  • Every org OSE stewards
  • Hard + soft conflict detection
  • 2-gate approval chain, 7 request types
  • Immutable audit trail
The cost of turnover

When a leader leaves, the org pays for it twice.

A year of relationships, vendor deals, budgets, and playbooks walks out the door, and the next person spends a semester relearning what the organization already knew.

Without Tenure

The handoff today
  • A cold handoff through a shared Drive folder
  • Sponsor and vendor relationships go quiet
  • The same mistakes repeat every single year
  • Weeks of ramp before anyone is useful

With Tenure

The seat remembers
  • One living system of record for the org
  • The seat keeps its own institutional memory
  • An AI that answers straight from history
  • The next leader is productive in days
Why Tenure is different

The person is new. The seat remembers everything.

Every other tool models people and rosters that wipe clean each year. Tenure models a durable seat, a position that keeps its money, contacts, playbooks, and decisions no matter who is sitting in it this term.

  • Knowledge attaches to the position, not the student who held it
  • Occupants rotate through the seat; the record never resets
  • That growing record is what Tenure AI draws on to bring the next leader up to speed

VP Finance & Operations

durable seat · SCC-VP-FINA-OPER

Occupant · term 2026–27

the person rotates ↻
MLMarcus Leeactive
PNPriya Nairshadow
MCMaya Chenalumni

Institutional memory on this seat

12

records, carried across every handoff

+ VendorPrestige Catering, flat $3,800
Ask this seat anything

Who’s our banquet caterer, and what did we overpay last year?

Prestige Catering. The ’25 gala ran $1,240 over, Marcus renegotiated it to a flat $3,800.3 sources ↗

How it works

The role remembers, so the person doesn’t have to.

Tenure isn’t a binder someone hands over on their way out. The work itself becomes the record, so every transition starts from everything that came before, not a blank page.

  • 01

    Run it in Tenure

    Finances, events, members, and decisions get logged as the work happens, no separate wiki anyone has to remember to update.

  • 02

    It stays with the seat

    Knowledge belongs to the role, not the person who held it, so nothing walks out the door at term’s end.

  • 03

    The next leader inherits it

    They open a handoff packet assembled from the record itself, current the day they arrive, then ask Tenure AI about anything in it.

The handoff

The handoff document nobody has to write.

Every seat, side by side: who holds it now, who held it last term and how to reach them, how many knowledge cards are attached, and who is shadowing in. It isn’t a document someone remembered to write on their way out. It is assembled from the record, so it is current the day you open it.

Handoff packet

Student Culture Council · every seat, as of today

assembled from the record
  • President

    SCC-PRES

    Holds it now

    Dana Osei

    Held it last term

    Marcus Lee ’26

    m.lee@u.rochester.edu

    Cards

    22

    Shadowing inShadowAriel Fonseca
  • VP Finance & Operations

    SCC-VP-FINA-OPER

    Holds it now

    Marcus Lee

    Held it last term

    Maya Chen ’25

    maya.chen@alum.rochester.edu

    Cards

    34

    Shadowing inShadowPriya Nair
  • VP Events & Partnerships

    SCC-VP-EVEN-PART

    Holds it now

    Sana Ali

    Held it last term

    Ines Duarte ’25

    i.duarte@alum.rochester.edu

    Cards

    19

    Shadowing innot yet named
  • VP Sponsorship

    SCC-VP-SPON

    Holds it nowVacant
    Held it last term

    Tomas Reyes ’26

    t.reyes@u.rochester.edu

    Cards

    27

    Shadowing inShadowJordan Kim
Awaiting approval

3 requests

two sitting in the office gate

Due to the office

2 deliverables

next one closes in 6 days

Where the budget stands

$12,400

of $18,000 committed this term

No departing officer writes this. Tenure assembles it from the seats, the approvals, the deliverables, and the ledger already on file.

Shadow access

They read the seat before they sit in it.

There is no first day where somebody opens an empty account. Access attaches to the seat, so a handoff is a change of status, not a transfer of files, passwords, and folders somebody has to remember to send.

What the incoming officer sees: everything the seat can see, read-only, from the day they are named to the day their term starts.

  1. ShadowBefore the term begins

    The incoming officer is added to the seat with read-only access to everything it knows: past decisions, vendor terms, and the reasons behind them.

  2. ActiveDay one

    The same access becomes write access. Nothing is copied over and nothing is rebuilt, the seat simply changes hands.

  3. AlumniAfter the term

    The outgoing officer keeps their record and loses the keys. A seat that carries history is retired, never deleted, so the record stays where the work happened.

Continuity, measured

We don’t measure engagement. We measure whether the knowledge survived.

What the seat model is built to deliver, Fall 2026 pilot targets.

0-day

seat onboarding

the incoming officer gets read-only access to the seat's record before their term begins

0

knowledge lost at graduation

everything stays attached to the seat, not the person

0-gate

approval chain, 7 request types

every decision appends a permanent step naming the seat that made it

0%

of actions logged

immutable, RBAC-scoped, nothing silently editable

The platform

One governed system for everything the org runs on.

Finance, scheduling, approvals, members, documents, messaging, and memory: the dozen tools an organization juggles across spreadsheets and logins, unified into one record that every transition inherits.

Remember

Tenure AI

Ask in your own words across everything the seat can see, plus the seat’s own private memory. Every answer links the records, files, and decisions it came from. No model is trained on your data.

How do we run elections?

Nominations open week 10, two-week window, ranked-choice ballot in the Members module.

Bylaws §4 · 2 records ↗
Grounded in your records · sources shown
Govern

Approvals & oversight

Multi-step approval chains, routed by seat. Every decision snapshots the exact policy in force, so you can always prove the rules, not just who said yes.

eventbudgetvendorcommsdocumentrosterexception
Run

Finance

Budgets, dues, reimbursements, and vendors in one ledger. Request, approve, and reconcile in place, with the full history kept by seat.

$12,400of $18,000
Run

Conflict-aware calendar

Plan events, vendors, and run-of-show. Tenure catches hard and soft scheduling conflicts before they become a double-booked room.

Hard conflict, Schlegel 207, 5:00 to 6:30p

Remember

Institutional memory

The living record, decisions, context, and know-how that survives every turnover instead of leaving in someone’s head.

ContactPlaybookVendorLessonCredentialDeadline
Run

Members & durable seats

Roster, roles, and contacts, organized around positions that persist. Access follows the seat and revokes itself at graduation.

ACTIVESHADOWALUMNI
Remember

Documents

Contracts, decks, and spreadsheets open in Tenure: PDF, Word, Excel, and PowerPoint with speaker notes. Text files and spreadsheets can be edited in place, versioned, and Tenure warns you if someone else saved first.

versionedopens in-appedit in place
Govern

Immutable audit trail

Every allow and every deny, append-only. Denials are logged too, so you can prove nobody did something. Rows are only ever created, never updated or deleted.

budget.approved · SCC-VP-FINA-OPER · allow

Remember

Messages

Role-aware conversations with sensitivity levels and delivery across in-app, email, and push, threaded to the work they’re about.

RBACsensitivityin-app · email · push
Govern

Cross-org collaboration

A shared feed where teams co-host and partner. Every cross-org request is gated and audited by whoever oversees them.

feedco-hostapproved & audited
Govern

Reports & search

Roll spending, participation, and continuity into board-ready reports, and search the entire record in one box, scoped to what you can see.

board-readyRBAC-scopedsources linked
Tenure at work

Not a pitch deck. The system, actually running.

Finance

Every dollar, tracked and approved in place.

Budgets, dues, and reimbursements live in one ledger. Officers request, leadership approves, and the whole history stays with the role, so next year's treasurer sees exactly what things cost and who signed off.

Finance · fall

live

$12,400 / $18,000

Print order, D. Reyes$240PendingApproved
Gala venue deposit$1,500PendingApproved
The handoff

Records cross the term with their history intact.

When leadership rotates, the work doesn't reset. Deals, contacts, and playbooks move to the incoming board with the context that made them matter, who built them, what they cost, and why.

Term handoff

2024–25 → 2025–26

Outgoing

Incoming

LeadWegmans · ’24
DealAramark renewal

$4,000 · Maya ’24

Tenure AI

They read the seat before they sit in it.

Ask Tenure in your own words (how a deal was closed, what the last board decided, why a decision was made) and get an answer grounded in the seat’s own record, with every source linked. The incoming officer gets read-only access to that record before their term begins, so the first week isn’t spent reconstructing the last one.

  • Every answer links back to the record it came from
  • No more “ask the person who left”
  • If the model is unavailable, you still get the ranked, permission-scoped sources, and Tenure tells you which happened
  • The seat's record grows richer every term
Ask Tenure
Treasurer seat

What's our sponsorship pipeline?

From last term’s sponsorship cards: Aramark renewal sent, M&T Bank a warm intro from Maya ’24 awaiting reply, Rochester Print at a standing 15% rate.

3 sources

How do we run elections?

Nominations open week 10, two-week window, ranked-choice ballot in the Members module. Last cycle’s timeline and the bylaws clause are attached.

Bylaws §4 · 2 records
Ask about this seat’s history…
Trust & governance

Built for whoever has to sign off.

A dean, an operations lead, a finance office, a student-engagement director, anyone accountable for an organization gets real oversight, on the record. Approvals, audit, and access control are built in, not bolted on.

Audit log
Immutable · append-only
ActorActionResult
SCC-VP-FINA-OPERbudget.approvedallow
MEMBERbudget.deletedeny
OSE_DIRECTORapproval.overrideallow
SCC-VP-MARK-COMMmessage.broadcast_sentallow
OSE_ADVISORcontent.overridedeny
SCC-VP-EVEN-PARTvendor.createdallow

Live audit log, every allow and every deny, append-only.

Oversight without micromanagement

Multi-step approval chains routed by role. Every decision snapshots the exact policy in force, so you can always prove the rules, not just who said yes.

event · budget · vendor · comms · document · roster

Access follows the seat

Access attaches to the seat, not the person. Incoming officers get read-only access before their term starts; outgoing ones keep the record and lose the keys. No orphaned access.

SHADOW → ACTIVE → ALUMNI

Every action, on the record

An append-only audit trail captures every allow and every deny. The denials are what let you prove nobody did something. Rows are only ever created, never updated or deleted.

allow / deny · create-only · 35 write sites

Your data. Your eyes only.

Multi-tenant isolation enforced at the query layer, not by convention. The tenant filter is attached to the database client itself, so no query can decline it, and every table in the schema must be classified before it can ship.

tenant-isolated · enforced in production · verified in CI

Institutional data, kept inside your walls.

  • You own your records. They stay with the seat when a person leaves: access is revoked, history is not.
  • Isolated per organization. Every query carries the tenant context, or it fails.
  • Tenure AI answers only from your own record. It never trains a shared model.

On the AI:Tenure AI reads only records you already have permission to see, and shows its sources. Answers are generated by Anthropic’s API from those sources. Your record is never used to train any model, by us or by them.

YOUR ORGANIZATION · TENANT BOUNDARYteams · clubs · officesapproved+ audited
  • Encrypted at rest (database, documents, images)
  • Multi-tenant isolation by design
  • SOC 2 roadmap, in progress
  • Every action append-only & auditable
For the office

The office gets its own system, not a login to everyone else’s.

The pilot runs on both sides of the record at once: every organization the office stewards, and the office’s own administrators. One console across all of them, what is pending, what is vacant, and what got denied.

Administration console

Office of Student Engagement · every organization it stewards

signed in as Director

Overrides

institution-wide

Spring Gala vendor contract

$4,200 · Student Culture Council · SCC-VP-EVEN-PART

6 days in gate 1
Force approveForce rejectboth gates bypassed, both outcomes logged

approval.force_approved · Director, Office of Student Engagement · allow

Three staff levels

A director inherits everything staff can do, and staff inherit everything an advisor can do. So an advisor sees advising and a director sees everything, without anybody maintaining a permissions spreadsheet.

AdvisorStaffDirector

Sixteen named powers

Publish or cancel an event, archive or restore a document or a memory card, adjust a budget, read the audit log. The console builds its own navigation from those powers, so nobody is shown a tab that would only turn them away.

16 powerscapability-derived nav

Overrides, on the record

Force-approve and force-reject work institution-wide and bypass both gates. Then they land in the audit log exactly like every other action, naming the seat that used them and when.

force approveforce rejectaudited
Succession

The office hands off too.

The outgoing director keeps their authority until the named successor accepts. Then the grant and the step-down happen together, in one move.

  • No coverage gap between one director and the next
  • No shared password, and no account handed down
  • No week where nobody in the office can approve anything
  1. 01

    The director names a successor

    Nothing moves yet. The outgoing director keeps every power they had a minute ago.

  2. 02

    The successor accepts

    Until they accept, the transfer does not exist. Nobody is half in, and nobody is holding a login that belongs to someone else.

  3. 03

    One move, both sides

    The grant and the step-down commit together, so the office is never without somebody who can approve.

Who it’s for

One model. Every kind of organization.

The people rotate. The seat stays. Wherever turnover outpaces knowledge transfer, the same durable-seat model keeps the operations and the memory with the role, not the person who happens to hold it this term.

Student organization members gathered around a laptop in a lecture hallVP Finance & Operations · SCC-VP-FINA-OPER

University organizations

Leadership turns over every spring

Run the club and hand it off clean, finances, events, members, and a record the next board inherits on day one. No scattered drives, no lost passwords, no starting from zero.

Administrators seated at a formal governing-body table with microphonesOffice of Student Engagement · Director

University administrations

Oversees dozens of orgs at once

Govern every organization you steward from one seat, approvals, spending, and compliance that persist by role, without approving every bake sale. The knowledge you fund stops walking out the door.

Two small-business owners packing and labelling orders in their studioHead of Operations · OPS-HEAD-OPER

SMEs & growing teams

Employees leave, roles remain

When someone resigns, their vendors, playbooks, and hard-won context shouldn't leave with them. The same seat model applies outside a university: knowledge attaches to the role, and whoever takes it next reads the seat's record before their first day in it.

A board reviewing plans and charts together, seen from aboveBoard Chair · BRD-CHAI

Nonprofits, chapters & boards

Annual board & volunteer rotation

Volunteer boards reset every year and relearn the same lessons. The same engine already configures a structurally different organization, programs, committees, sites, and funder relations in place of clubs and boards, so donor context and deadlines can persist across every term.

Committees, agencies, chapters, guilds, sports clubs, if the calendar changes the people but not the work, Tenure is the seat that remembers.

Fits your stack

Bring what you already have. Keep the calendar you already open.

Upload the budget spreadsheet and Tenure reads your columns however you named them. Drop in the decks, contracts, and PDFs and they open in-app. Subscribe your Outlook, Google, or Apple Calendar with one signed link, no password shared.

Excel
Open in Tenure

Excel, Word, PowerPoint, PDF

Contracts, decks, and spreadsheets open in the app, PowerPoint with its speaker notes. Spreadsheets and text files can be edited in place and versioned, and Tenure tells you if someone else saved first.

xlsx · docx · pptx · pdf

OutlookGoogle Calendar
Subscribe, one link

Outlook, Google, Apple Calendar

Subscribe to the Tenure calendar from the one you already open. No account connection and no password shared: the link is signed to you, so it carries only what your seat is allowed to see. One-way today, Tenure fills your calendar and does not read it back.

signed feed · one-way today

Excel
Imported, columns matched

Your existing budget spreadsheet

Upload the budget you already keep. Tenure works out which column is which, whatever you named them, drops your subtotal rows so nothing double-counts, and shows you what it read before anything is saved. Or start from our template, generated by the same code that reads it.

columns auto-matched · preview before save

FAQ

Does Tenure replace our Google Drive, Slack, or Notion?

No. Tenure doesn't connect to them, it's where the record itself lives. Bring your spreadsheets, decks, and documents in, subscribe your calendar to Tenure's, and the files and decisions that define how the organization runs stop living in someone's personal account and start belonging to the role.

Is Tenure only for universities?

No. It's built for any organization where people rotate faster than knowledge transfers, student clubs, university offices, companies, nonprofits, and volunteer boards. The seat model is identical everywhere: knowledge stays with the role, not the person who holds it this term.

Who owns the data?

The organization does. Access passes cleanly to the next occupant at every transition, and nothing leaves with an individual when they graduate, resign, or roll off the board.

How fast is onboarding, really?

Days instead of a semester. Because the memory stays with the seat, Tenure AI answers from the role's own record, budgets, vendors, past events, and the reasons behind decisions. It doesn't train a model on your data; it surfaces and explains what's already in your record.

Is sensitive data handled responsibly?

Yes. Tenure runs least-access by default, isolates each organization's data at the query layer, and logs every action to an immutable audit trail. The organization owns its records, not Tenure, not any individual. Documents are encrypted at rest and only ever served through short-lived signed links, never a raw file URL.

What does it cost?

We're setting pilot pricing with Simon's Office of Student Engagement directly, at the level of the whole portfolio it stewards rather than per club, so it fits a real budget. Contact sales and we'll walk you through it.

Still deciding whether Tenure fits your organization? .

Run the org. Hand it off. Lose nothing.

See Tenure on your organization's real handoff. A short walkthrough: we'll show you exactly what carries forward.

or email us