# 7.3 Data Export & API Access

User Type: **Corporate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 7.3 Data Export & API Access

### 7.3.1 Bulk Data Export
**What it does:** Lets the admin export the organization's data — employees, completions, compliance, billing — as CSV or JSON files for external analysis.

**Sub-features:**
- Export employees, completions, compliance, billing
- CSV and JSON formats
- Date-range scoping
- Download link with expiry
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the bulk data export

**Corporate User Journey:**
1. The admin opens Integrations → Data Export.
2. The admin selects the datasets and a date range.
3. The export is generated.
4. The admin downloads the file via the expiring link.
5. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- Download links expire after 24 hours.
- Exports are limited to 100,000 rows; larger requests are split.
- Events (viewed) are logged with the account and the timestamp.
- The bulk data export is audit-logged with the account and the timestamp.

### 7.3.2 API Access
**What it does:** Provides a REST API with scoped API keys so the organization can read and write platform data from its own systems.

**Sub-features:**
- REST API with documented endpoints
- Scoped API keys (read / write)
- Rate limiting
- API key rotation
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the API access

**Corporate User Journey:**
1. The admin opens Integrations → API.
2. The admin creates a read-scoped API key.
3. The organization's system calls the API.
4. Rate limits are enforced.
5. The admin rotates the key.
6. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- API keys are scoped; a read key cannot write.
- The rate limit is 600 requests/minute per key.
- Rotating a key invalidates the old key immediately.
- Events (viewed) are logged with the account and the timestamp.
- The API access is audit-logged with the account and the timestamp.

### 7.3.3 Webhooks
**What it does:** Lets the organization receive real-time event notifications (employee enrolled, course completed, compliance breached) via webhook endpoints.

**Sub-features:**
- Register webhook endpoints
- Event types: enrolled, completed, compliance
- Signed payloads (HMAC)
- Delivery retries and logs
- Available on web and mobile
- Event logging (viewed)
- Audit logging of the webhooks

**Corporate User Journey:**
1. The admin opens Integrations → Webhooks.
2. The admin registers an endpoint and selects event types.
3. When an event occurs, a signed payload is delivered.
4. Failed deliveries are retried.
5. The delivery log shows status per event.
6. The admin opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- Payloads are signed with HMAC-SHA256; unsigned deliveries are rejected by the receiver.
- Retries follow exponential backoff for up to 24 hours.
- Events (viewed) are logged with the account and the timestamp.
- The webhooks are audit-logged with the account and the timestamp.
