# 3.4 Role Assignment

User Type: **Corporate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 3.4 Role Assignment

### 3.4.1 Corporate Roles
**What it does:** Defines the built-in roles available in a Corporate account: Corporate Admin, Department Manager, HR Manager, and Employee, each with a fixed permission set.

**Sub-features:**
- Corporate Admin role
- Department Manager role
- HR Manager role
- Employee role
- Role permission summary view
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the corporate roles

**Corporate User Journey:**
1. The admin opens Settings → Roles.
2. The built-in roles and their permissions are listed.
3. The admin reviews the permission summary for each role.
4. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- Built-in roles cannot be edited; only custom roles can.
- The Corporate Admin role is the only role that can manage billing.
- Events (viewed) are logged with the account and the timestamp.
- The corporate roles are audit-logged with the account and the timestamp.

### 3.4.2 Assign & Change Roles
**What it does:** Lets the Corporate Admin assign a role to any user and change it later. Role changes take effect on the user's next session.

**Sub-features:**
- Assign a role to a user
- Change a user's role
- Revoke elevated roles
- Role change takes effect on next session
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the role assignment

**Corporate User Journey:**
1. The admin opens a user's profile.
2. The admin assigns the Department Manager role.
3. The user's permissions update on their next session.
4. The admin later changes the role back to Employee.
5. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- Only the Corporate Admin can assign or change roles.
- At least one Corporate Admin must always remain.
- Role changes are effective from the user's next session.
- Events (viewed) are logged with the account and the timestamp.
- The role assignment is audit-logged with the account and the timestamp.

### 3.4.3 Permission Matrix
**What it does:** Shows a full matrix of permissions by role, so the admin can verify exactly what each role can do before assigning it.

**Sub-features:**
- Permission-by-role matrix
- Search permissions by name
- Export the matrix to CSV
- Highlight a role's permissions
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the permission matrix

**Corporate User Journey:**
1. The admin opens Settings → Roles → Permission Matrix.
2. The matrix lists every permission against every role.
3. The admin searches for a permission by name.
4. The admin highlights a role's permissions.
5. The admin exports the matrix to CSV.
6. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- The matrix is read-only.
- Events (viewed) are logged with the account and the timestamp.
- The permission matrix is audit-logged with the account and the timestamp.
