Returning students
Exempt from the draw. Their seats are reserved and taken off available capacity before the pool is built.
Preferences, caps, reserved seats, weights and score ordering live in a versioned rule set, and the classification table behind it is authored in the admin console rather than deployed: edit a draft, publish it, and that revision becomes immutable. A rule set pins the exact revision a draw will seal. The tiers below follow the New York charter school example; the order of preferences is always school policy.
Eight steps, in the same order, every time. The engine consumes a frozen projection of the applicants and the rule set — it never re-reads a live application mid-draw.
A family applying to four schools in your district used to carry four portal links and read four separate results. One door now opens all of it — a district address, a one-time email code, and every application that family holds anywhere in the district on a single list. Each school still runs its own lottery on its own capacity and answers for it alone; what changed is the application steps and the tracking around them.
Draw programmes one after another and you eventually seat a child at the programme that happened to clear first, over one who ranked above them. A match clears every participating programme at the same moment, from one sealed input and one derived key. It covers the programmes of a single school: a match that spanned schools would decide two institutions’ capacity from one seed, which neither could answer for on its own.
“Was the list edited?”, “was the draw computed correctly?” and “did anyone choose the key?” are three different questions — Campus checks and reports each one separately, years after the season ends and on paper when a board or an authorizer asks.
Staff and families never share a screen, a login or an endpoint.
See a complete lottery run — freeze, draw, publish and verify — on your own capacities and priority rules.