13 Districts Approved Closures. Nobody Merged the Filter Policies.
Thirteen districts approved school closures or consolidations in the last year, affecting over 100 schools. When two schools merge, two filtering policies merge — and that merge fails toward less restriction, not more. A configuration guide for K-12 IT.

On September 30, K-12 Dive reported that Los Angeles Unified is opening the 2026-27 year weighing closures and consolidations, with enrollment projected under 400,000 students — down from more than 700,000 in 2002-03. Albuquerque Public Schools approved a districtwide facility-planning process on September 16 after dropping from 84,000 students to under 64,000 since 2018.
They are not outliers. K-12 Dive's closure tracker lists thirteen district-approved closure or consolidation plans in roughly the last year alone.
Every one of those plans has an IT consequence that nobody puts in the board presentation:
When two schools become one, two filtering policies become one. That merge does not happen automatically, and when it goes wrong it fails in the direction of less restriction, not more.
This is a configuration guide for the IT director who just found out their building count is changing.
The scale of what is actually happening
These are board-approved plans, not proposals:
| District | Approved | Schools closed / consolidated | Stated savings |
|---|---|---|---|
| Miami-Dade County Public Schools | June 17, 2026 | 9 | $10M |
| Pittsburgh Public Schools | May 27, 2026 | 12 | ~$8M by 2028 |
| School District of Philadelphia | April 30, 2026 | 17 | Not stated |
| San Jose Unified | March 26, 2026 | 5 | $1.475M/yr |
| Fort Bend ISD | March 9, 2026 | 7 | $5–7M/yr |
| Houston ISD | Feb. 26, 2026 | 12 | $14.6–20M |
| Judson ISD | Feb. 9, 2026 | 4 | $7M |
| Broward County Public Schools | Jan. 21, 2026 | 6 | $8.95M/yr |
| Corpus Christi ISD | Jan. 12, 2026 | 7 | $11M |
| Kyrene School District | Dec. 16, 2025 | 6 | $5.8M/yr |
| Cleveland Metropolitan School District | Dec. 9, 2025 | 29 | $30M/yr |
| Atlanta Public Schools | Dec. 3, 2025 | 16 | $300–350M by 2040 |
| Austin ISD | Nov. 20, 2025 | 10 | $21.5M |
Source: K-12 Dive school closure tracker, as of October 2026.
That is well over 100 school communities being folded into other school communities. Each one arrives with its own device fleet, its own organizational unit, its own exception list, and its own set of local decisions that were never written down.
Why a policy merge fails toward less restriction
Here is the mechanic that catches people.
Most filtering stacks resolve conflicts by priority, and most of them resolve ties by "last write wins" or by some ordering nobody on your team has read. When you consolidate Elementary A into Elementary B, you typically do one of three things:
- Move the devices into B's organizational unit
- Merge A's policy into B's policy
- Create a new combined policy and point everything at it
Options 2 and 3 are where districts get hurt, because merging two allow/block sets is not a union — it is a conflict resolution. School A blocked example-game-site.com by name. School B never did, because that site was never a problem on their campus. Merge the two exception lists and you have one entry saying BLOCK and one entry saying nothing. Fine.
Now flip it. School B had an explicit teacher-requested ALLOW for a streaming domain, scoped to their media program. School A blocked it. After the merge, that ALLOW is an entry in the combined policy. The BLOCK was a category default, not an explicit rule — so it has lower precedence than an explicit allow.
The allow wins. The merged school is now less restricted than either school was before the merge, and nothing in the UI tells you that happened.
We wrote about this precedence problem in detail in Two Policies Disagree. Which One Wins?. Consolidation is the event that turns that theoretical question into a live one across your whole district in a single weekend.
The five things that break, in the order they break
1. Orphaned organizational units
The closed school's OU still exists. Its policies still exist. Nothing is assigned to it, so nothing shows a problem on any dashboard.
Then in March, someone re-images a cart of Chromebooks and they enroll into the old OU — because the enrollment token on the device was never rotated. Those devices are now live, in a student's hands, under a policy nobody has reviewed since the building closed.
Check: list every OU with zero assigned devices and a policy still attached. Delete the policy or delete the OU. Do not leave an armed, unmonitored policy in the tree.
2. Exception lists that nobody owns
Every school accumulates one-off unblocks. A teacher asked for a site in 2023, it got added, that teacher has retired, the site is still allowed.
When we audited 1,300 unblock requests across live deployments, the filter was wrong 16% of the time — meaning roughly one in six exceptions existed because the categorization was bad, not because the site was genuinely needed. Consolidation is a free opportunity to clear those out, because the person who asked for most of them is no longer in that building.
Check: export both schools' exception lists before you merge. Any entry older than 18 months with no owner on record gets removed, not carried forward. Carrying it forward is how an exception becomes permanent.
3. Grade-band drift
This is the dangerous one, and consolidation causes it structurally.
Several of these plans don't merge like-for-like — Miami-Dade's consolidation explicitly produces "a new K-8 school, two academies for grades 6-12, and one new K-12 school." That means elementary students and high school students are now on the same campus, often on the same network, sometimes in the same OU.
A policy written for 11th graders applied to 4th graders is a CIPA problem, a parent-complaint problem, and a safety problem. A policy written for 4th graders applied to 11th graders means your AP Biology class can't research anything and your teachers lose faith in the filter within a week.
Check: after a K-8 or K-12 reconfiguration, the policy assignment must follow grade band, not building. If your stack can only scope by OU or by network, you need the OU structure to encode grade band before the students arrive, not after.
4. Safety alerting with no recipient
Every wellness and self-harm alert routes to a person. In most districts that person is a named counselor or administrator at a specific building.
Close that building and the alert rule is still active, still firing, and routing to a mailbox that is either closed or belonging to someone who no longer has responsibility for those students. The alerts don't stop. They just stop being read.
This is the failure we consider the most serious on this list, because it is completely silent. Your dashboard shows alerts being generated. Delivery shows success. Nobody is on the other end.
Check: before the effective date, pull every alert routing rule tied to a closing building and re-point it to a named person at the receiving school. Then send a test alert and confirm a human acknowledges it. Delivery status is not evidence of receipt.
5. Device inventory drift at exactly the wrong moment
Consolidations move hardware. Carts get redistributed, some devices get retired, some get held back as spares, and some sit in a closet for four months.
A device that is enrolled, unmonitored, and physically unaccounted for is the single most common way a student ends up on an unfiltered device. And the window is wide: a closure approved in spring takes effect in fall, so the hardware sits in limbo across an entire summer.
Check: snapshot your enrolled device list on the last day of the old configuration and reconcile it against the first week of the new one. Anything enrolled but not seen in 30 days gets its enrollment revoked, not "flagged for review."
A sequence that works
If your district has an approved plan with an effective date, this is the order that avoids the failure modes above:
- Eight weeks out — export both schools' full policy state: categories, explicit rules, exception lists, alert routing, OU structure. Store it outside the filtering console. You will need the before-state to prove what changed.
- Six weeks out — decide grade-band policy assignment for the new configuration. Build the target OU tree. Do not assign anything yet.
- Four weeks out — reconcile the exception lists. Everything carried forward needs a named owner and a reason. Everything else is dropped.
- Two weeks out — re-point every safety alert rule and test it with a real alert that a real human acknowledges.
- Effective date — move devices into the target OUs. Confirm policy application on a sample device per grade band, by actually attempting a blocked site, not by reading the console.
- Week one — reconcile device inventory. Revoke enrollment on anything unaccounted for.
- Week four — re-export policy state and diff it against step 1. Anything that changed and isn't on your list is drift. Find out why.
The honest scope
A web filter does not make a consolidation go well. The hard parts of closing a school are community trust, transportation, staffing, and the emotional weight of it. None of that is a technology problem.
But the filtering and monitoring layer is one of the few pieces of a consolidation that can be fully verified before the effective date — and one of the few that fails silently if it isn't. There is no parent phone call when an alert routes to a closed mailbox. There is no complaint when a 4th grader inherits a high-school policy until something specific goes wrong.
If your district is on that list, or expects to be, the work above is roughly two days of IT time spread across two months. That is a cheap insurance policy against the one category of consolidation failure that nobody sees coming.
Running a consolidation and want a second set of eyes on the policy merge? KyberGate's policy precedence is explainable per-rule — you can see which rule won and why, before the students arrive. Talk to us about your district's plan.
Ready to protect your students?
Deploy KyberGate in under 30 minutes. No hardware required.
Request a Demo