# 3.4 Role Assignment — Test Cases

User Type: **Corporate**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: role_assignment.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.4.1 | Corporate Admin role | TC-COR-3-04-001 |
| 3.4.1 | Department Manager role | TC-COR-3-04-002 |
| 3.4.1 | HR Manager role | TC-COR-3-04-003 |
| 3.4.1 | Employee role | TC-COR-3-04-004 |
| 3.4.1 | Role permission summary view | TC-COR-3-04-005 |
| 3.4.1 | Available on web and mobile | TC-COR-3-04-006 |
| 3.4.1 | Event logging (viewed) | TC-COR-3-04-007 |
| 3.4.1 | Audit logging of the corporate roles | TC-COR-3-04-008 |
| 3.4.1 | Rule: Built-in roles cannot be edited; only custom roles can. | TC-COR-3-04-009 |
| 3.4.1 | Rule: The Corporate Admin role is the only role that can manage billing. | TC-COR-3-04-010 |
| 3.4.1 | Rule: Events (viewed) are logged with the account and the timestamp. | TC-COR-3-04-011 |
| 3.4.1 | Rule: The corporate roles are audit-logged with the account and the timestamp. | TC-COR-3-04-012 |
| 3.4.2 | Assign a role to a user | TC-COR-3-04-013 |
| 3.4.2 | Change a user's role | TC-COR-3-04-014 |
| 3.4.2 | Revoke elevated roles | TC-COR-3-04-015 |
| 3.4.2 | Role change takes effect on next session | TC-COR-3-04-016 |
| 3.4.2 | Available on web and mobile | TC-COR-3-04-017 |
| 3.4.2 | Event logging (viewed) | TC-COR-3-04-018 |
| 3.4.2 | Audit logging of the role assignment | TC-COR-3-04-019 |
| 3.4.2 | Rule: Only the Corporate Admin can assign or change roles. | TC-COR-3-04-020 |
| 3.4.2 | Rule: At least one Corporate Admin must always remain. | TC-COR-3-04-021 |
| 3.4.2 | Rule: Role changes are effective from the user's next session. | TC-COR-3-04-022 |
| 3.4.2 | Rule: Events (viewed) are logged with the account and the timestamp. | TC-COR-3-04-023 |
| 3.4.2 | Rule: The role assignment is audit-logged with the account and the timestamp. | TC-COR-3-04-024 |
| 3.4.3 | Permission-by-role matrix | TC-COR-3-04-025 |
| 3.4.3 | Search permissions by name | TC-COR-3-04-026 |
| 3.4.3 | Export the matrix to CSV | TC-COR-3-04-027 |
| 3.4.3 | Highlight a role's permissions | TC-COR-3-04-028 |
| 3.4.3 | Available on web and mobile | TC-COR-3-04-029 |
| 3.4.3 | Event logging (viewed) | TC-COR-3-04-030 |
| 3.4.3 | Audit logging of the permission matrix | TC-COR-3-04-031 |
| 3.4.3 | Rule: The matrix is read-only. | TC-COR-3-04-032 |
| 3.4.3 | Rule: Events (viewed) are logged with the account and the timestamp. | TC-COR-3-04-033 |
| 3.4.3 | Rule: The permission matrix is audit-logged with the account and the timestamp. | TC-COR-3-04-034 |


## 3.4.1 Corporate Roles

### TC-COR-3-04-001 — Corporate Admin role

**Type:** Positive

**Covers:** 3.4.1 → Corporate Admin role; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Corporate Admin role.

2. Observe the result and verify the full behavior: Corporate Admin role.

**Expected Result:** Corporate Admin role — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-002 — Department Manager role

**Type:** Positive

**Covers:** 3.4.1 → Department Manager role; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Department Manager role.

2. Observe the result and verify the full behavior: Department Manager role.

**Expected Result:** Department Manager role — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-003 — HR Manager role

**Type:** Positive

**Covers:** 3.4.1 → HR Manager role; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: HR Manager role.

2. Observe the result and verify the full behavior: HR Manager role.

**Expected Result:** HR Manager role — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-004 — Employee role

**Type:** Positive

**Covers:** 3.4.1 → Employee role; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Employee role.

2. Observe the result and verify the full behavior: Employee role.

**Expected Result:** Employee role — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-005 — Role permission summary view

**Type:** Positive

**Covers:** 3.4.1 → Role permission summary view; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Role permission summary view.

2. Observe the result and verify the full behavior: Role permission summary view.

**Expected Result:** Role permission summary view — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-006 — Available on web and mobile

**Type:** Positive

**Covers:** 3.4.1 → Available on web and mobile; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Available on web and mobile.

2. Observe the result and verify the full behavior: Available on web and mobile.

**Expected Result:** Available on web and mobile — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-007 — Event logging (viewed)

**Type:** Positive

**Covers:** 3.4.1 → Event logging (viewed); Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Event logging (viewed).

2. Observe the result and verify the full behavior: Event logging (viewed).

**Expected Result:** Event logging (viewed) — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-008 — Audit logging of the corporate roles

**Type:** Positive

**Covers:** 3.4.1 → Audit logging of the corporate roles; Rule: Built-in roles cannot be edited; only custom roles can.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Audit logging of the corporate roles.

2. Observe the result and verify the full behavior: Audit logging of the corporate roles.

**Expected Result:** Audit logging of the corporate roles — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-009 — Rule: Built-in roles cannot be edited; only custom roles can.

**Type:** Positive

**Covers:** 3.4.1 → Built-in roles cannot be edited; only custom roles can.; Rule: Built-in roles cannot be edited; only custom roles can..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Built-in roles cannot be edited; only custom roles can..

2. Observe the result and verify the full behavior: Built-in roles cannot be edited; only custom roles can..

**Expected Result:** Built-in roles cannot be edited; only custom roles can. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-010 — Rule: The Corporate Admin role is the only role that can manage billing.

**Type:** Positive

**Covers:** 3.4.1 → The Corporate Admin role is the only role that can manage billing.; Rule: The Corporate Admin role is the only role that can manage billing..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: The Corporate Admin role is the only role that can manage billing..

2. Observe the result and verify the full behavior: The Corporate Admin role is the only role that can manage billing..

**Expected Result:** The Corporate Admin role is the only role that can manage billing. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-011 — Rule: Events (viewed) are logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.1 → Events (viewed) are logged with the account and the timestamp.; Rule: Events (viewed) are logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Events (viewed) are logged with the account and the timestamp..

2. Observe the result and verify the full behavior: Events (viewed) are logged with the account and the timestamp..

**Expected Result:** Events (viewed) are logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-012 — Rule: The corporate roles are audit-logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.1 → The corporate roles are audit-logged with the account and the timestamp.; Rule: The corporate roles are audit-logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: The corporate roles are audit-logged with the account and the timestamp..

2. Observe the result and verify the full behavior: The corporate roles are audit-logged with the account and the timestamp..

**Expected Result:** The corporate roles are audit-logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High


## 3.4.2 Assign & Change Roles

### TC-COR-3-04-013 — Assign a role to a user

**Type:** Positive

**Covers:** 3.4.2 → Assign a role to a user; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Assign a role to a user.

2. Observe the result and verify the full behavior: Assign a role to a user.

**Expected Result:** Assign a role to a user — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-014 — Change a user's role

**Type:** Positive

**Covers:** 3.4.2 → Change a user's role; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Change a user's role.

2. Observe the result and verify the full behavior: Change a user's role.

**Expected Result:** Change a user's role — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-015 — Revoke elevated roles

**Type:** Positive

**Covers:** 3.4.2 → Revoke elevated roles; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Revoke elevated roles.

2. Observe the result and verify the full behavior: Revoke elevated roles.

**Expected Result:** Revoke elevated roles — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-016 — Role change takes effect on next session

**Type:** Positive

**Covers:** 3.4.2 → Role change takes effect on next session; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Role change takes effect on next session.

2. Observe the result and verify the full behavior: Role change takes effect on next session.

**Expected Result:** Role change takes effect on next session — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-017 — Available on web and mobile

**Type:** Positive

**Covers:** 3.4.2 → Available on web and mobile; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Available on web and mobile.

2. Observe the result and verify the full behavior: Available on web and mobile.

**Expected Result:** Available on web and mobile — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-018 — Event logging (viewed)

**Type:** Positive

**Covers:** 3.4.2 → Event logging (viewed); Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Event logging (viewed).

2. Observe the result and verify the full behavior: Event logging (viewed).

**Expected Result:** Event logging (viewed) — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-019 — Audit logging of the role assignment

**Type:** Positive

**Covers:** 3.4.2 → Audit logging of the role assignment; Rule: Only the Corporate Admin can assign or change roles.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Audit logging of the role assignment.

2. Observe the result and verify the full behavior: Audit logging of the role assignment.

**Expected Result:** Audit logging of the role assignment — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-020 — Rule: Only the Corporate Admin can assign or change roles.

**Type:** Positive

**Covers:** 3.4.2 → Only the Corporate Admin can assign or change roles.; Rule: Only the Corporate Admin can assign or change roles..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Only the Corporate Admin can assign or change roles..

2. Observe the result and verify the full behavior: Only the Corporate Admin can assign or change roles..

**Expected Result:** Only the Corporate Admin can assign or change roles. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-021 — Rule: At least one Corporate Admin must always remain.

**Type:** Positive

**Covers:** 3.4.2 → At least one Corporate Admin must always remain.; Rule: At least one Corporate Admin must always remain..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: At least one Corporate Admin must always remain..

2. Observe the result and verify the full behavior: At least one Corporate Admin must always remain..

**Expected Result:** At least one Corporate Admin must always remain. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-022 — Rule: Role changes are effective from the user's next session.

**Type:** Positive

**Covers:** 3.4.2 → Role changes are effective from the user's next session.; Rule: Role changes are effective from the user's next session..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Role changes are effective from the user's next session..

2. Observe the result and verify the full behavior: Role changes are effective from the user's next session..

**Expected Result:** Role changes are effective from the user's next session. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-023 — Rule: Events (viewed) are logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.2 → Events (viewed) are logged with the account and the timestamp.; Rule: Events (viewed) are logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Events (viewed) are logged with the account and the timestamp..

2. Observe the result and verify the full behavior: Events (viewed) are logged with the account and the timestamp..

**Expected Result:** Events (viewed) are logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-024 — Rule: The role assignment is audit-logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.2 → The role assignment is audit-logged with the account and the timestamp.; Rule: The role assignment is audit-logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: The role assignment is audit-logged with the account and the timestamp..

2. Observe the result and verify the full behavior: The role assignment is audit-logged with the account and the timestamp..

**Expected Result:** The role assignment is audit-logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High


## 3.4.3 Permission Matrix

### TC-COR-3-04-025 — Permission-by-role matrix

**Type:** Positive

**Covers:** 3.4.3 → Permission-by-role matrix; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Permission-by-role matrix.

2. Observe the result and verify the full behavior: Permission-by-role matrix.

**Expected Result:** Permission-by-role matrix — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-026 — Search permissions by name

**Type:** Positive

**Covers:** 3.4.3 → Search permissions by name; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Search permissions by name.

2. Observe the result and verify the full behavior: Search permissions by name.

**Expected Result:** Search permissions by name — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-027 — Export the matrix to CSV

**Type:** Positive

**Covers:** 3.4.3 → Export the matrix to CSV; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Export the matrix to CSV.

2. Observe the result and verify the full behavior: Export the matrix to CSV.

**Expected Result:** Export the matrix to CSV — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-028 — Highlight a role's permissions

**Type:** Positive

**Covers:** 3.4.3 → Highlight a role's permissions; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Highlight a role's permissions.

2. Observe the result and verify the full behavior: Highlight a role's permissions.

**Expected Result:** Highlight a role's permissions — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-029 — Available on web and mobile

**Type:** Positive

**Covers:** 3.4.3 → Available on web and mobile; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Available on web and mobile.

2. Observe the result and verify the full behavior: Available on web and mobile.

**Expected Result:** Available on web and mobile — delivered exactly as documented.

**Priority:** Critical

### TC-COR-3-04-030 — Event logging (viewed)

**Type:** Positive

**Covers:** 3.4.3 → Event logging (viewed); Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Event logging (viewed).

2. Observe the result and verify the full behavior: Event logging (viewed).

**Expected Result:** Event logging (viewed) — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-031 — Audit logging of the permission matrix

**Type:** Positive

**Covers:** 3.4.3 → Audit logging of the permission matrix; Rule: The matrix is read-only.

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Audit logging of the permission matrix.

2. Observe the result and verify the full behavior: Audit logging of the permission matrix.

**Expected Result:** Audit logging of the permission matrix — delivered exactly as documented.

**Priority:** Medium

### TC-COR-3-04-032 — Rule: The matrix is read-only.

**Type:** Positive

**Covers:** 3.4.3 → The matrix is read-only.; Rule: The matrix is read-only..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: The matrix is read-only..

2. Observe the result and verify the full behavior: The matrix is read-only..

**Expected Result:** The matrix is read-only. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-033 — Rule: Events (viewed) are logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.3 → Events (viewed) are logged with the account and the timestamp.; Rule: Events (viewed) are logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: Events (viewed) are logged with the account and the timestamp..

2. Observe the result and verify the full behavior: Events (viewed) are logged with the account and the timestamp..

**Expected Result:** Events (viewed) are logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High

### TC-COR-3-04-034 — Rule: The permission matrix is audit-logged with the account and the timestamp.

**Type:** Positive

**Covers:** 3.4.3 → The permission matrix is audit-logged with the account and the timestamp.; Rule: The permission matrix is audit-logged with the account and the timestamp..

**Preconditions:** A Corporate account is active and the Corporate user is in the state required for this behavior.

**Steps:**

1. As a Corporate user, set up the precondition and perform: The permission matrix is audit-logged with the account and the timestamp..

2. Observe the result and verify the full behavior: The permission matrix is audit-logged with the account and the timestamp..

**Expected Result:** The permission matrix is audit-logged with the account and the timestamp. — delivered exactly as documented.

**Priority:** High
