# 3. Password & Security Management

User Type: **Affiliate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 3. Password & Security Management

### 3.1 Change Password
**What it does:** Lets the Affiliate change their account password. The Affiliate enters their current password and a new password, and the platform validates the new password's strength and updates it. All active sessions except the current one are signed out on change. This lets the Affiliate keep their account secure.

**Sub-features:**
- Enter the current password
- Enter a new password
- New password strength validation
- Password updated on success
- Other active sessions signed out on change
- Change confirmation
- Change available on web and mobile
- Change event logging (initiated, completed)
- Audit logging of the change password

**Affiliate User Journey:**
1. Affiliate opens the password settings.
2. Affiliate enters their current password.
3. Affiliate enters a new password.
4. The new password strength is validated.
5. The password is updated.
6. Other active sessions are signed out.
7. Affiliate opens Profile → "Activity" and confirms the change events are recorded.

**Rules & Edge Cases:**
- The current password is required.
- The new password strength is validated.
- Other active sessions are signed out on change.
- Change events (initiated, completed) are logged with the account and the timestamp.
- The change password is audit-logged with the account and the timestamp.

### 3.2 Forgot Password
**What it does:** Lets the Affiliate reset their password if they have forgotten it. The Affiliate enters their registered email, receives a reset link, and sets a new password. The reset link is single-use and expires. This provides a recovery path for locked-out Affiliates.

**Sub-features:**
- Enter the registered email to start a reset
- Reset link sent to the email
- Set a new password via the link
- Reset link is single-use
- Reset link expires
- Resend reset link with a cooldown
- Reset available on web and mobile
- Reset event logging (requested, completed)
- Audit logging of the forgot password

**Affiliate User Journey:**
1. Affiliate opens the forgot password screen.
2. Affiliate enters their registered email.
3. A reset link is sent to the email.
4. Affiliate opens the link and sets a new password.
5. The reset link is single-use and expires.
6. Affiliate can resend the reset link with a cooldown.
7. Affiliate opens Profile → "Activity" and confirms the reset events are recorded.

**Rules & Edge Cases:**
- The reset is started with the registered email.
- The reset link is single-use and expires.
- A resend has a cooldown.
- Reset events (requested, completed) are logged with the account and the timestamp.
- The forgot password is audit-logged with the account and the timestamp.

### 3.3 Two-Factor Authentication (2FA)
**What it does:** Lets the Affiliate enable two-factor authentication (2FA) for an extra layer of security. When enabled, the Affiliate must enter a one-time code (from an authenticator app or SMS) in addition to their password at login. The Affiliate can enable, disable, and reconfigure 2FA. This protects the account from unauthorized access.

**Sub-features:**
- Enable two-factor authentication
- One-time code at login (authenticator or SMS)
- Backup codes for recovery
- Disable two-factor authentication
- Reconfigure the 2FA method
- 2FA status shown
- 2FA available on web and mobile
- 2FA event logging (enabled, disabled, code verified)
- Audit logging of the two-factor authentication

**Affiliate User Journey:**
1. Affiliate opens the security settings.
2. Affiliate enables two-factor authentication.
3. Affiliate scans the authenticator setup.
4. Backup codes are generated.
5. At the next login, a one-time code is required.
6. Affiliate can disable or reconfigure 2FA.
7. Affiliate opens Profile → "Activity" and confirms the 2FA events are recorded.

**Rules & Edge Cases:**
- The 2FA requires a one-time code at login.
- Backup codes are provided for recovery.
- The 2FA can be disabled or reconfigured.
- 2FA events (enabled, disabled, code verified) are logged with the account and the timestamp.
- The two-factor authentication is audit-logged with the account and the timestamp.
