# MDA Identity, Responsibility & Access Model

Status: **DRAFT for approval** — target state: approved **MDA Identity, Responsibility & Access Model**
Source: *Mi Digital Academy - Education CRM Features Document* (all user-type doc trees under `Documents/`)
Scope: human & access structure only. **No application code, no database tables** (no `users`, `roles`, `permissions` tables are defined here).

Legend:
- ✅ = permitted · ❌ = explicitly not permitted · ◐ = partial / scoped · — = not applicable or not documented
- **OPEN DECISION (OD-n)** = the requirements do not specify this; a policy decision is required before implementation. Nothing is invented. All OD items are listed in Section 7.

---

## 1. Actor Map

### 1.1 Platform operators (MDA staff)

| # | Actor | What they represent in the business |
|---|---|---|
| A1 | **Super Administrator** | The platform owner/operator. Fixed, full-access role. Manages everything: users, roles, content, billing, system, security. "cannot be created, edited, or deleted… a fixed, full-access role". |
| A2 | **Billing Administrator** (predefined sub-admin) | Platform finance staff. "manages plans, pricing, discounts, payments, refunds, and billing reports; no access to content or curriculum". |
| A3 | **Teacher / Content Creator** (predefined sub-admin) | Content author. "creates and manages assigned courses and content; no access to billing, pricing, or platform-wide settings". May or may not be linked to a school/institute (two onboarding paths). |
| A4 | **Content Reviewer** (predefined sub-admin) | Quality gate for content. "reviews and approves/rejects content submissions; read access to content, no creation or billing access". Scoped by subject/type/expertise. |
| A5 | **Student Support Administrator** (predefined sub-admin) | Platform support staff. "manages student accounts, support tickets, and student data within scope; no access to billing configuration or content approval". |
| A6 | **Support agents** | Ticket handlers assigned by Super Admin. Docs also name a preset template "Support Agent" — whether this is the same as A5 is **OD-15**. |
| A7 | **Custom sub-admin roles** | Super-Admin-defined roles starting empty (deny-by-default). Examples named in docs: "Course Operations", "Refunds Processor", "Content Lead", "Finance Approver". |
| A8 | **Dedicated account manager** | Platform-side named contact for Training Institutes (onboarding, check-ins, staff training; routing point for 500+ enterprise license purchases). |
| A9 | **Dedicated affiliate manager** | Platform-side named contact for Affiliates (strategy, questions, account issues). |
| A10 | **Platform billing team** | Resolves institute billing disputes; processes affiliate payout requests and commission disputes. |
| A11 | **On-duty admin** | Recipient of critical security alerts (SMS). Rotation mechanism **OD-72**. |

### 1.2 Individual consumers

| # | Actor | What they represent in the business |
|---|---|---|
| A12 | **Student** | The learner. Owns an account, learns, takes assessments, manages own subscription (self-service buyer). Can be a **minor (under 18)** — registration captures an optional parent email for consent. |
| A13 | **Parent** | Guardian account. Links to one or more children, monitors, controls, pays for children's subscriptions, communicates with teachers. |
| A14 | **Guardian (on a child's account)** | A role that can act on behalf of a child's account (accept link requests, consent to monitoring). How a guardian is attached to a child's account is **OD-6**. |
| A15 | **Affiliate** | External promoter. Referral links/QR, commissions (Tier 1 + Tier 2), payment requests. Enrollment is reviewed and approved by the platform before referral tools unlock. |
| A16 | **Sub-affiliate** | An Affiliate recruited via another Affiliate's recruitment link; forms the recruiter's Tier 2 downline. |
| A17 | **Referred customer** | End customer who signed up/purchased via an Affiliate's link, QR, or discount code. Source of the Affiliate's commissions. |
| A18 | **Tertiary (Individuals)** | Named in the Super Admin user-management scope ("…Teachers, Tertiary (Individuals)"). No dedicated doc tree exists. Scope **OD-49**. |
| A19 | **Group owner** | A Student who owns a study group (manages membership, announcements, group sessions). A sub-role of A12, not a separate account type. |
| A20 | **Peers / classmates** | Other Students in study groups, forums, leaderboards. |

### 1.3 Organizational tenants

| # | Actor | What they represent in the business |
|---|---|---|
| A21 | **Training Institute** | Organization (school/training body) that buys bulk student licenses and manages its own students. Requires Institute Verification before full features activate. |
| A22 | **Institute Admin (Primary)** | "The primary account holder of a Training Institute… the only role that cannot be delegated or duplicated; single primary role per institute." Full institute-portal access. |
| A23 | **Institute Academic Coordinator** | Institute sub-admin: student management, learning paths, batch assessments, read-only analytics, batch reports/announcements. No billing/licenses/integrations/branding. |
| A24 | **Institute Billing Manager** | Institute sub-admin: license usage, purchases, invoices, discount eligibility, renewals/upgrades. No student management/analytics/content/integrations. |
| A25 | **Institute Student Support** | Institute sub-admin: student queries, account requests, access issues, engagement monitoring, progress reports. No billing/license management/analytics/content creation. |
| A26 | **Corporate (tenant)** | Company buying seat-based learning for employees. One account per verified domain. |
| A27 | **Corporate Admin** | Built-in corporate role. "the only role that can manage billing"; only role that can assign/change roles. "At least one Corporate Admin must always remain." |
| A28 | **Department Manager** | Built-in corporate role. "Managers see only their own department's data." Receives 14-day overdue escalations. |
| A29 | **HR Manager** | Built-in corporate role. Recipient of scheduled HR reports. Scope **OD-33**. |
| A30 | **Employee** | Built-in corporate role. The learner inside a Corporate account; needs a seat to be active. |
| A31 | **CSR (tenant)** | Funding company running CSR education programs. Team roles: **admin, finance, program manager**. |
| A32 | **CSR team members** | Invited members of a CSR account with role-based access to "funding, billing, and reporting". Per-role split **OD-35**. |
| A33 | **Funded beneficiaries** | "funded students and institutes" — students/institutes funded by a CSR via programs/cohorts. |
| A34 | **Organization (tenant)** | "NGO, government body, educational board". Admin roles: **super admin, program admin, finance admin, compliance admin**; user roles: **learner, mentor, program coordinator**. |
| A35 | **Organization admins** | Multi-admin setup; primary admin set up at registration with verification. Role→domain mapping **OD-36**. |
| A36 | **Organization users** | learner / mentor / program coordinator. Per-role feature access **OD-37**. |
| A37 | **Sponsor (tenant)** | Brand sponsoring courses/content and scholarships. Team roles: **admin, marketing, finance**. |
| A38 | **Sponsor team members** | Role-based access to "sponsorship, billing, and reporting". Per-role split **OD-38**. |
| A39 | **Sponsored students / scholarship recipients** | Students in sponsored courses or funded via sponsor scholarships; visible to sponsors only "with privacy masking". |

### 1.4 External systems / non-human actors

| # | Actor | What they represent |
|---|---|---|
| A40 | **LMS / SIS / HRIS / third-party integrations** | External systems connected via SSO, sync, API keys, webhooks (institutes, corporate, organizations). |
| A41 | **IdP (SAML 2.0 / OIDC)** | Identity providers for Corporate and Organization SSO. "Platform staff (Super Admin and internal roles) never authenticate via an organization's SSO." |

---

## 2. Responsibility Matrix

| Actor | Allowed to do (responsibilities) | Responsible for |
|---|---|---|
| **Super Administrator** (A1) | Define/edit/archive/delete roles; configure the permission catalog per role; create/edit/activate/suspend/delete **all** account types; manage account links; manage license seats; manage curriculum, courses, content, assessments, resource library; configure content approval workflow; manage plans, pricing, discounts; configure affiliate program (tiers, rates, payout approval, approve/reject/terminate affiliates); payment gateway, refunds, invoicing; revenue/tax/reconciliation; all reporting & exports; marketing campaigns; integrations & public API keys; backups & DR; system settings; security config (IP, geo, password policy, 2FA mandates, lockouts, sessions); support operations (assign tickets, SLA, escalation); data protection & compliance (consent, deletion, portability, child safety, policies) | Platform integrity, access enforcement, content quality gate, financial correctness, regulatory compliance, security |
| **Billing Administrator** (A2) | Manage plans, pricing, discounts, payments, refunds, billing reports | Financial configuration and transaction processing. **Not** responsible for content/curriculum |
| **Teacher / Content Creator** (A3) | Create/edit/delete content **in assigned courses only** (videos, podcasts, exams, resources, flashcards, mind maps); handle student queries in assigned subjects; run live sessions; content enters approval workflow where policy requires | Content quality for assigned courses. **Not** responsible for billing, pricing, platform settings, content approval, other teachers' content |
| **Content Reviewer** (A4) | Review/approve/reject/flag content within their subject/type filter; route defective content back to creator | Content quality gate for their subset. **Not** responsible for creation, billing, or overall queue state (Super Admin only) |
| **Student Support Administrator** (A5) | Manage student accounts, support tickets, student data **within scope** | Student account health and support. **Not** responsible for billing configuration or content approval |
| **Support agents** (A6) | Handle assigned tickets (open/pending/resolved; priorities low→urgent; escalation levels 1/2/3) | Ticket resolution within SLA |
| **Student** (A12) | Learn (browse/enroll/watch/complete); take assessments; manage own profile, goals, target exams, study plans; manage **own** subscription & payments; create community content (moderated); request data portability / account deletion; submit purchase & restricted-content requests to parent | Own learning, own account, own subscription (where not parent-managed) |
| **Parent** (A13) | Link/verify/unlink children; monitor & analyze children; set parental controls; approve/modify AI study plans; purchase & manage **children's** subscriptions; approve child purchase requests (spending limits); message teachers, raise concerns, schedule meetings; share insights with teachers; define rewards | Children's learning oversight, children's subscriptions, consent management for minors |
| **Affiliate** (A15) | Promote via referral link/QR/tracked links; create discount codes **if permitted by program tier**; view own commissions; submit payment requests (min payout threshold); manage own payment methods; raise commission disputes; recruit sub-affiliates; run marketing automation; complete Affiliate Academy | Own referral performance, own payout hygiene. **Not** responsible for referred customers' accounts |
| **Training Institute** (A21) | Purchase bulk licenses; allocate/transfer/release seats; bulk & individual student registration; assign courses/paths/assessments; batch announcements; analytics & exports; LMS/SIS integrations; custom learning paths & proprietary content; white-label/branding | Its students' access and learning outcomes; license entitlement compliance |
| **Institute Admin (Primary)** (A22) | Everything in the institute portal: sub-admin management, licensing, seats, registration, assignment, analytics, billing history, integrations, branding, unrestricted exports | Institute account, sub-admin governance, commercial relationship |
| **Institute Academic Coordinator** (A23) | Assign courses, create learning paths, schedule batch assessments, read-only analytics, batch reports, batch announcements, custom assessments | Day-to-day student learning. **Not** billing, license purchase, integrations, branding |
| **Institute Billing Manager** (A24) | View license usage (read-only), purchase additional licenses, invoices, discount eligibility, renewals/upgrades | Commercial relationship. **Not** student management, analytics, content, integrations |
| **Institute Student Support** (A25) | Student queries, account requests (limited fields: name, email, grade, batch), access issues, engagement monitoring, individual progress reports (shareable by secure link) | Student front-line support. **Not** billing, license management, analytics admin, content creation |
| **Corporate Admin** (A27) | Register & verify domain; bulk/manual employee enrollment; seat assign/revoke/transfer/renew; departments & nested teams; role assignment (only role); mandatory training with deadlines & escalation; learning paths; certification registry; all analytics/HR reports; **billing (only role)**; cost centers & budgets; SSO, HRIS/LMS connectors, API keys, webhooks | Corporate account, employee access, compliance, billing |
| **Department Manager** (A28) | View own-department progress/compliance; receive weekly/monthly reports with acknowledgment; receive 14-day overdue escalations | Own department's learning & compliance |
| **HR Manager** (A29) | Receive scheduled HR reports (monthly learning, cost-per-employee) | HR reporting consumption. Scope **OD-33** |
| **Employee** (A30) | Complete assigned/recommended/mandatory courses; pass assessments; renew own certifications | Own learning obligations |
| **CSR admin** (A31/A32) | Register & verify; manage team members & roles; create & fund programs (**CSR admin approval**); budget allocation across categories/tranches; disbursement tracking; milestones; beneficiary outcomes, ROI, custom impact reports; funding invoices & reconciliation | Funded programs, budget integrity, impact reporting |
| **CSR finance / program manager** (A32) | Role-based access to "funding, billing, and reporting" | Per-role split **OD-35** |
| **Organization admins** (A35) | Manage programs, cohorts, curriculum; bulk enrollment; seats; departments/groups; roles; mandatory training & certification compliance; audit reports & data export; bulk license billing & **government invoicing** (approval workflow); government LMS sync, SSO, API access | Organization account, programs, compliance, billing |
| **Organization users** (A36) | learner: complete training; mentor / program coordinator: support programs | Per-role scope **OD-37** |
| **Sponsor admin** (A37/A38) | Register & brand-verify; manage team; sponsor courses/content (tier, duration, placement); fund scholarships; branding placement & renewal; visibility metrics, students reached, outcomes, ROI, impact story; sponsorship invoices & payment schedules | Sponsorship delivery, branding compliance |
| **Sponsor marketing / finance** (A38) | Role-based access to "sponsorship, billing, and reporting" | Per-role split **OD-38** |

---

## 3. Permission Matrix

Actions: **V**iew · **C**reate · **E**dit · **D**elete · **A**pprove · **M**anage · **X**ecute (perform) · **Xp**ort

### 3.1 Platform operators

| Object | Super Admin | Billing Admin | Teacher/Content Creator | Content Reviewer | Student Support Admin |
|---|---|---|---|---|---|
| Roles & permissions | C E M (catalog read-only) | — | — | — | — |
| Users (all types) | C E D M (unscoped directory) | — | — | — | ◐ student data within scope |
| Account links (parent↔child, student↔institute, corporate→employees) | C E D M | — | — | — | — |
| License seats | M | — | — | — | — |
| Curriculum (boards/grades/subjects) | C E D M | — | — | — | — |
| Courses | C E D M | — | ◐ assigned courses only (C E D) | — | — |
| Content (video/podcast/resources/flashcards/mind maps) | C E D M A | — | ◐ assigned courses only (C E D) | V A (approve/reject/flag, subject/type filter) | — |
| Assessments | C E D M X | — | ◐ assigned courses only | — | — |
| Membership plans / pricing / discounts | C E D M | C E M (plans, pricing, discounts) | ❌ | ❌ | ❌ |
| Affiliate program (tiers, rates, permissions) | M A (approve/reject applications; activate/suspend/terminate) | — | — | — | — |
| Payments / refunds / invoicing | M X | M X (payments, refunds, billing reports) | ❌ | ❌ | ❌ |
| Revenue / tax / reconciliation | M Xp | ◐ billing reports | ❌ | ❌ | ❌ |
| Reports & exports (platform) | C Xp | ◐ billing reports | ❌ | ❌ | — |
| Marketing & communication | C E M X | — | — | — | — |
| Integrations / public API keys | C E D M | — | — | — | — |
| Backups / DR / data export | M X Xp | — | — | — | — |
| System settings / security config | M | — | — | — | — |
| Support tickets | M (assign, route, escalate) | — | — | — | M (within scope) |
| Audit / denial logs | V Xp (never E/D) | — | — | — | — |

### 3.2 Individual consumers

| Object | Student | Parent | Affiliate |
|---|---|---|---|
| Own profile / account / 2FA / sessions | V E M (D via deletion request w/ cooling-off) | V E M (D via deletion request) | V E M (deactivate own) |
| Own subscription & payments | V M X (subscribe, upgrade, cancel, auto-renewal; pay) | — | — |
| Child's subscription & payments | — | V C E M X (purchase, add/remove subjects, renewals, payment methods) | — |
| Courses (catalog) | V (sample preview limited) X (enroll/drop, gated by subscription) | — | — |
| Own learning (watch, notes, bookmarks, downloads) | V C E D M X | — | — |
| Assessments | V (own results) X (take) | — | — |
| Child monitoring / performance / reports | — | V M (generate) Xp (download) | — |
| Parental controls (screen time, content, sessions, AI plan approval) | — | V C E A M | — |
| Child purchase requests | C (submit) | A (approve/deny; spending limits) | — |
| Child restricted-content requests | C (submit) | A (approve/deny, time-boxed) | — |
| Shared goals / rewards / tokens | C (propose; child must agree) V | C E M V | — |
| Teacher communication | — (escalate doubts only) | V C M (messages, concerns, meetings) | — |
| Reports → teacher | — | M (explicit per-item share) | — |
| Referral link / QR / tracked links | — | — | V C D (regenerate) |
| Discount codes | X (apply at checkout) | — | C **if permitted by program tier** (OD-20) |
| Own commissions / statements | — | — | V Xp (statements) |
| Payment requests / payment methods | — | — | C (min payout threshold, OD-19) V C E D |
| Commission disputes | — | — | C |
| Referred customers (own) | — | — | V (activity feed; PII scope OD-21) |
| Downline sub-affiliates | — | — | V C (recruit) |
| Marketing automation (sequences, posts) | — | — | V C E D M |
| Study groups / forums / community | V C E D M X (owner: membership, announcements) | — | — (private affiliate community: V C) |
| Data portability / own data | V Xp | V Xp | — |

### 3.3 Organizational tenants

| Object | Institute Admin | Inst. Academic Coord. | Inst. Billing Mgr | Inst. Student Support | Corporate Admin | Dept Manager | Employee |
|---|---|---|---|---|---|---|---|
| Sub-admins / team roles | C E D M (deactivate) | ❌ | ❌ | ❌ | M (assign/change roles — only role) | ❌ | ❌ |
| Students / employees (accounts) | C E D M (bulk + individual) | ◐ assign courses/paths | ❌ | ◐ limited fields (name, email, grade, batch) | C E M (bulk + manual) | V (own dept) | V (self) |
| Seats / licenses | M (purchase, allocate, transfer, release) | ❌ | V (read-only) C (purchase) | ❌ | M (assign, revoke, transfer, renew) | ❌ | V (own seat) |
| Departments / groups / cohorts | ◐ groups/cohorts | — | — | — | C E D M (create, merge, archive, nested teams) | V (own dept) | — |
| Courses (platform catalog) | ❌ (cannot create platform-level) | V (assign to groups) | ❌ | ❌ | ❌ | ❌ | V (assigned) |
| Learning paths | C E M | C E M (institute paths) | ❌ | ❌ | C E M (build/assign, mandatory) | ❌ | X (complete) |
| Assessments | M (batch) | C M (custom, batch; results read-only) | ❌ | ❌ | M (mandatory, deadlines, escalation) | ❌ | X (take) |
| Analytics / reports | V M Xp (unrestricted export — only role) | V (read-only) M (batch reports) Xp | V (billing export only) | V (individual progress reports) Xp (PDF, secure link) | V M Xp (all, schedule) | V (own dept only) | V (self) |
| Billing / invoices | V M (history, renewals, disputes) | ❌ | V C M (purchases, invoices, renewals/upgrades) | ❌ | V M (**only role that can manage billing**) | ❌ | ❌ |
| Cost centers / budgets | — | — | — | — | C E M (define, allocate, budgets, alerts) | ❌ | ❌ |
| Integrations (LMS/SIS/HRIS/API/webhooks) | C E M | ❌ | ❌ | ❌ | C E M | ❌ | ❌ |
| Branding / white-label | C E M (publish, rollback) | ❌ | ❌ | ❌ | — | — | — |
| Announcements / alerts | M | M (batch-wide) | — | M (rate-limited) | M (reminders, digests) | — | — |

| Object | CSR admin | CSR finance / prog. mgr | Org admin(s) | Org users | Sponsor admin | Sponsor mktg / finance |
|---|---|---|---|---|---|---|
| Team members & roles | C E D M | ❌ | C E D M (admin roles) | ❌ | C E D M | ❌ |
| Programs / learning paths | C E M (create & fund; **admin approval**) | ◐ per role (OD-35) | C E M (programs, curriculum, cohorts) | X (complete) | C E M (sponsor courses/content, scholarships) | ◐ per role (OD-38) |
| Budgets / funding | C E M (allocation, tranches, reallocation) | ◐ per role (OD-35) | C E M (budget allocation, cost centers) | ❌ | V (spend summary) | ◐ per role (OD-38) |
| Beneficiaries / sponsored students | V (privacy masking) M (progress, certificates re-issue request, feedback) | ◐ | — | — | V (privacy masking; aggregates) | ◐ |
| Invoices / billing | V M (funding invoices, reconciliation, statements) | ◐ per role (OD-35) | V M (bulk license billing, **government invoicing** w/ approval workflow) | ❌ | V M (sponsorship invoices, payment schedules, renewal) | ◐ per role (OD-38) |
| Impact / visibility / compliance reports | V M Xp (PDF/Excel, share link) | ◐ | V M Xp (audit reports, data export, scheduled) | ❌ | V M Xp (visibility, ROI, impact story, share link) | ◐ |
| Integrations / SSO / API | — | — | C E M (government LMS, data sync, SSO, API keys) | ❌ | — | — |

---

## 4. Information Visibility Matrix

### 4.1 Data-scope model (from Role & Permission Management)

- Scope types: **"all records, own records (assigned to the user), team/institute records, custom record-set rules"**.
- Per-role scope per data category: courses, students, tickets, invoices.
- Multi-role: effective access = **union** of held roles' permissions; multi-role scope default = **union of visible records** (configurable — OD-64).
- Record-level scope enforced on **reads, writes, searches, and exports**; "no partial disclosure"; ID-guessing denied + logged.

### 4.2 Per-actor visibility

| Actor | Can see | Whose | Must NOT see |
|---|---|---|---|
| Super Administrator | Everything (unscoped directory; overall review-queue state; any institute's sub-admin list & audit trail) | All | — (but audit logs are immutable even to them) |
| Billing Administrator | Plans, pricing, discounts, payments, refunds, billing reports | Platform financial data | Content, curriculum |
| Teacher/Content Creator | Assigned courses & their students; their courses' analytics (read-only) | Own assigned records only | "unassigned courses are invisible"; "Other teachers' content — No cross-teacher access"; billing; system settings |
| Content Reviewer | Content in their subject/type filter | Their subset | Other reviewers' subsets; overall queue state (Super Admin only); creation & billing data |
| Student Support Admin | Student accounts, tickets, student data within scope | Scoped students | Billing configuration; content approval |
| Student | Own profile, courses, progress, results, payments (read-only), subscription, gamification, community moderation status | Self | Other students' individual performance (peer comparison/benchmarking "anonymous; no individual peer is identified"); other users' payment data |
| Parent | Linked children only: real-time activity, progress/time, scores, deadlines, subscription & billing, AI plans, control activity log | Linked children only | "a parent never sees unrelated accounts"; child data limited until relationship verified |
| Affiliate | Own referral data, own referred customers (activity feed), own commissions, own downline, own campaigns | Self + own referrals | Other affiliates' private data (implied by ownership scoping — OD-22); platform financials |
| Institute (all roles) | Own institute only: students, licenses, analytics, invoices, integrations | Own institute | "cross-institute access is denied at the API layer"; other institutes' records (hard boundary, not configurable); platform-level data |
| Institute Academic Coordinator | Read-only analytics; batch reports | Own institute | Billing, license purchase, integrations, branding; "cannot edit individual student scores" |
| Institute Billing Manager | License usage (read-only), invoices, billing history | Own institute | Student management, analytics, content, integrations |
| Institute Student Support | Student queries, engagement (read-only), individual progress | Own institute's students | Billing, license management, analytics admin, content creation |
| Corporate Admin | Full tenant: all employees, departments, seats, billing, reports | Own corporate tenant | Other tenants (implied — OD-31) |
| Department Manager | "Managers see only their own department's data" | Own department | Other departments' data |
| Employee | Own learning queue, own profile; corporate profile read-only | Self | Admin data; other employees' data (not stated — OD-31) |
| CSR | Own funded programs, funded students & institutes, disbursements, invoices, impact data; per-student detail "**with privacy masking**" | Own CSR tenant | Unmasked individual student PII; other tenants |
| Organization | Own users, programs, cohorts, compliance, billing, audit data | Own organization | Other tenants (not stated — OD-31) |
| Sponsor | Own sponsored items, placements, invoices, sponsored-student **aggregates**; "Scholarship recipient list (with privacy masking)" | Own sponsor tenant | Unmasked individual student PII; other tenants |

### 4.3 Hard isolation boundaries (explicit in docs)

1. **Cross-institute isolation**: "one institute's records are not reachable by another institute's users" — hard boundary, not configurable.
2. **Cross-teacher isolation**: "No cross-teacher access" to content.
3. **Parent scope**: "a parent never sees unrelated accounts".
4. **Institute↔student**: "an institute never sees unlinked or other-institute students".
5. **SSO tenant boundary**: "an identity from one organization's provider can never authenticate into another organization's users or into platform staff roles".
6. **Audit logs**: append-only; "no role, including Super Admin, can edit or delete entries".
7. **Privileged data access** (admin viewing a user's personal data or a minor's record) is **audit-logged**.
8. **Right-to-access responses**: "Redaction of other individuals' personal data".
9. **Data portability**: "only user's own data; aggregate data excluded".
10. **Exports respect scope**: "Exports are scoped to the institute's own data only"; export actions are audit-logged.

---

## 5. Relationship Map

| Relationship | Cardinality | Rules (from docs) |
|---|---|---|
| **Parent → Child(ren)** | 1 : many | "one parent to many children; a child to the appropriate guardian(s)". Link requires **guardian identity verification** + child acceptance; carries parental-consent state. "A maximum linked children limit is enforced" (value — OD-8). Unlink requires reason + new-guardian verification. Anomaly detection on duplicate links. |
| **Child → Guardian(s)** | many : appropriate | "a child to the appropriate guardian(s)". Guardian-on-child role can accept links & consent (OD-6). |
| **Student → Institute** | 1 : 1 (primary) | "One student to one primary institute". Link can carry a license seat (allocated at link time; cap enforced). Re-link is a move: old seat released, new allocated; blocked if no seats. Student's own account/progress survive institute changes. Anomaly detection: student linked to two institutes. |
| **Institute → Student** | 1 : many | Institute creates students (bulk/individual), assigns licenses ("A student can hold only one active license at a time"), groups/cohorts ("A student can belong to multiple groups"), controls status, assigns courses/paths/assessments, communicates, issues certificates, exports. |
| **Institute → Sub-admins** | 1 : many | "Only the Institute Admin can manage sub-admins; sub-admins cannot create or edit other sub-admins." Multiple sub-admins per role allowed. "The Institute Admin role itself cannot be delegated or duplicated." "The last admin cannot be deactivated." Deactivation immediate; audit retained. Super Admin can assign roles during onboarding. |
| **Teacher → Course(s)** | many : many (assignment) | "A teacher's data scope is always their assigned courses; unassigned courses are invisible." Assignment by Super Admin (Path A) or institute (Path B). |
| **Teacher → Student(s)** | via assigned courses | Teacher sees students in assigned courses only; handles queries in assigned subjects. |
| **Child → Teacher** | "the child's teacher" | Implied assignment exists; how it is created is **OD-7**. |
| **Parent → Teacher** | via child | Direct messaging, concerns, meetings, insight sharing (explicit per-item). |
| **Corporate → Employee** | 1 : many | "One seat per employee at a time"; "Each employee has exactly one primary department"; "An employee can belong to multiple teams but one primary department"; "A team belongs to exactly one department". |
| **Corporate → Department → Team** | hierarchy | Merging "keeps all learning and compliance records on the employees". |
| **Corporate multi-admin** | ≥1 | "The first admin is the only user with full admin rights until more are added"; "At least one Corporate Admin must always remain." |
| **CSR → Funded programs → Beneficiaries** | 1 : many : many | Beneficiaries are "funded students and institutes" with "Program, cohort, and status per beneficiary". CSR funds new or existing platform programs. |
| **CSR → Team members** | 1 : many | "Invite via email with acceptance link"; roles admin/finance/program manager; "Deactivate team member access". |
| **Organization → Programs → Cohorts → Users** | hierarchy | "Create cohorts within a program; Enroll users into cohorts"; departments → groups → users; seats allocated "to departments and groups". |
| **Organization multi-admin** | ≥1 (stated min — OD-44) | "Primary admin setup with verification; Additional admin invitations with roles". |
| **Sponsor → Sponsored courses/content** | 1 : many | Tier (bronze/silver/gold/platinum), duration, placement; "Placement removal on expiry". |
| **Sponsor → Scholarships → Recipients** | 1 : many : many | Recipients visible "with privacy masking". |
| **Sponsor → Team members** | 1 : many | Email invite; roles admin/marketing/finance. |
| **Affiliate → Referred customers** | 1 : many | Attribution via unique referral link / QR / tracked links / discount code. |
| **Affiliate → Sub-affiliates** | 1 : many (Tier 2) | "Recruits added to the Tier 2 downline" via recruitment link. Tiers are exactly Tier 1 (direct) + Tier 2 (sub-affiliates). Depth beyond 2 — OD-17. |
| **Platform → all tenants** | operator | Platform verifies CSR/Sponsor/Organization/Institute accounts; raises invoices; issues completion certificates; enforces RBAC; can revoke parent↔child links. |
| **Corporate → Employees (linking)** | named in master list | "Account linking (parent→children, student→institute, corporate→employees)" — detailed rules **OD-50**. |

---

## 6. Access Rules

Rules that combine **role + relationship + ownership + assignment**.

### 6.1 Core RBAC (platform-wide)

1. **Deny-by-default**: "anything not explicitly permitted is denied"; a missing permission mapping results in denial, never a silent allow.
2. **Per-request, server-side** enforcement on web **and** service/API surfaces — "the same permission governs web and service surfaces, so there is no UI bypass".
3. **Single check** covers feature + action + data scope.
4. **Super Administrator exemption**: full access, not subject to the check.
5. **Effective access = union of all held roles**; multi-role scope default = union of visible records.
6. **Prompt propagation**: permission changes take effect on the next request (no re-login); in-progress request completes, new actions denied.
7. **Reachability never implies permission**: direct URLs, bookmarks, shared links all checked; "no partial disclosure"; ID-guessing denied + logged.
8. **Denial logging**: user, role(s), target, request type, timestamp, IP, device; append-only; pattern/probing detection raises review items (does not auto-block).
9. **Optional "request access"** path routes to Super Admin (whether enabled — OD-65).
10. **Separation of duties**: "no single predefined role combines content approval with billing, or billing configuration with refund approval"; SoD conflicts on combined roles are **flagged for review, not blocked** (full rule catalog — OD-70).

### 6.2 Authentication-gated access

11. **Pre-auth check order**: account status → lockout → IP allow/deny → location policy → credentials → 2FA.
12. **Status gates**: suspended/deactivated accounts cannot log in (generic error, no enumeration); unverified email → limited access, auto-deactivated after policy period (e.g., 7 days).
13. **Lockout**: configurable threshold (e.g., 5) / duration (e.g., 15 min); per-account and per-IP independent counters; OTP failures counted separately; admin unlock requires identity verification + recorded reason (second approver — OD-73).
14. **2FA**: **mandatory** for Super Admin, Billing Administrator, and all staff roles; **optional** for students/parents; mandatory-role users cannot self-disable; trusted-device skip is role-gated; "A social login can never be the only authentication method for a privileged role".
15. **IP control**: "Deny lists take precedence over allow lists"; scope global or per role; optional expiry; hits logged.
16. **Location/geo**: per-role location policies (e.g., admin roles restricted to operating country); geo-restrictions platform-level + content-level licensing, enforced server-side; stricter/union applies.
17. **Password policy**: breached-password blocklist (hard block); no reuse of last N (e.g., 10); "Role-scoped overrides always apply the stricter of the platform default and the role override".
18. **Sessions**: role overrides apply stricter values; privileged roles always have a concurrency cap at least as strict as platform default; remember-me "disabled for all admin roles" (example config); overflow behavior (block vs end-oldest) — OD-66.
19. **SSO**: organization-scoped; role mapping (e.g., "institute staff → Teacher role, admin contact → Institute Administrator, students → Student role"); JIT provisioning; de-provisioning suspends (not deletes); "Platform staff (Super Admin and internal roles) never authenticate via an organization's SSO"; unmapped group → denied or default-restricted, "never a silent grant of access"; provider outage fails closed unless org opted into password fallback.
20. **Social login**: linking requires existing password verification; duplicate email → link/merge review.

### 6.3 Age / consent-gated access

21. **Minimum age**: "self-registration allowed from age 13; features marked '18+' (e.g., payment methods management) restricted to adults"; "Where local law sets a higher minimum age than the platform default, the stricter threshold applies" (configured values — OD-61).
22. **Minor consent**: "a minor's account cannot be fully active without guardian consent"; "a minor cannot independently add a payment method"; pending consent beyond policy window (e.g., 14 days) → deactivation, reversible.
23. **Age-appropriate content filtering**: age groups by grade/age band, content age ratings, enforced age gate.

### 6.4 Status-gated access (account lifecycle)

24. **Statuses**: Active, Suspended, Deactivated, Pending verification.
25. **Suspend**: temporary, reversible, data retained, sessions ended, billing paused per policy; appeal path exists.
26. **Deactivate**: permanent, triggers privacy data-handling; retention-window restore path.
27. **Delete preconditions**: deactivated + retention window elapsed + no legal hold + no open financial obligations + no active subscription + no allocated seat + no open tickets; anonymized audit/financial references remain.
28. **Subscription lapse**: institute sub-admins lose access; Path A teacher deactivated; offline downloads expire.
29. **User notified of every status change.**

### 6.5 Assignment / relationship-gated access

30. **Teacher**: access strictly to **assigned courses** ("unassigned courses are invisible"); Path A (independent, Super Admin assigns) vs Path B (mapped through school/institute; deactivated when institute removes them).
31. **Content Reviewer**: access strictly to **subject/type filter** subset; assignment "by the subject, the type, and the expertise".
32. **Student course access** = enrollment + membership/seat validity + role/permission + content availability + account status.
33. **Bulk course assignment**: per-student eligibility check (membership active, seat valid, age/consent where required).
34. **Parent access** = linked + verified relationship + child consent + authenticated session; scope defined by consent; withdrawal reduces access.
35. **Parental approval for purchases**: child submits request; parent approves/denies; **monthly spending limit** — within limit auto-approved, above requires approval.
36. **Parental controls** apply to child's platform usage only; "**Core learning content always available**"; age-filter override requires a reason; AI study plans "applied to the child after approval".
37. **Subscription gating**: enrollment, live-session join, offline downloads all "gated by the Student's subscription"; sample content limited (e.g., first 2 minutes).
38. **Free trial**: 7-day full access, no credit card; one trial per account; extension policy-governed.
39. **Institute seats**: "A student can hold only one active license at a time"; transfer only to active student in same institute; removal frees seat (history retained); suspended = paused not revoked; lapsed license revokes access; registration beyond seat count is queued + Billing Manager notified; utilization alerts at 80%/95%; expiry alerts at 60/30/7 days.
40. **Institute sub-admin governance**: "Role restrictions cannot be overridden… only the Institute Admin or Super Administrator can change the role"; "The restriction set is enforced at the API layer, not only the UI"; denied attempts logged; "no single sub-admin role combines billing with student management, or analytics with license purchasing".
41. **Corporate**: "Only the Corporate Admin can assign or change roles"; "At least one Corporate Admin must always remain"; role changes effective from next session; "The Corporate Admin role is the only role that can manage billing"; enrollment requires a seat ("it never auto-expands the plan"); work email must match verified domain; domain verification gates SSO + bulk enrollment; mandatory-training escalation 7/3/1 days → employee, 14 days → department manager, 30 days → Corporate Admin (configurable, floor 1 day); "the HRIS is source of truth" (manual roster edits overridden by sync); offboarding deactivates access, revokes seat, preserves records.
42. **CSR**: "Only verified accounts can fund programs"; "Funding approval workflow (CSR admin approval)"; "Allocation limits and approval for changes" (approver — OD-35).
43. **Organization**: "Invoice approval workflow" + statutory compliance fields + PO reference (government invoicing); SAML/OIDC JIT provisioning; role-based access enforcement for all admin/user roles; "Deactivate admin access"; "Admin activity log".
44. **Sponsor**: "Only verified sponsors get branding placement"; "Placement approval workflow"; "Placement removal on expiry".
45. **Affiliate**: referral tools "unlocked on approval" of enrollment; discount code creation "permitted by the program tier" (OD-20); payment request "requires the minimum payout threshold" (value — OD-19); milestone tiers (Bronze/Silver/Gold/Platinum) grant increasing rates (values — OD-18).
46. **Support**: ticket assignment to agents; account-request queue ownership (Super Admin or delegated to sub-admins with the permission); SLA escalation owner → Super Admin.

### 6.6 Change-control rules

47. **Role/permission changes**: mandatory change preview (affected users + capabilities gained/lost); immediate propagation.
48. **Bulk operations**: mandatory preview + reason + per-account result report; size guardrails; legal holds respected per item.
49. **Sensitive-field edits** (email, phone, DOB) route through verification/correction flows; DOB via age-correction flow with evidence.
50. **Provisional credentials** force first-login password change; admin-created accounts carry "created by [admin]" provenance; admin creation does not bypass verification policy.
51. **Password reset** invalidates ALL sessions; support-assisted path after identity verification.
52. **Admin session termination / forced logout**: reason required, user notified, audit-logged.
53. **2FA channel change/revoke** requires passing current 2FA; "channel secrets and backup codes are never exposed in any admin view".
54. **Invoices are immutable** once issued; corrections via credit notes (corporate & institute).
55. **API keys**: "shown only once at creation"; revocation immediate; scope-limited; read key cannot write (corporate: 600 req/min per key); webhooks HMAC-SHA256 signed; secrets shown once; rotation invalidates previous.
56. **Shared links** (reports, invoices, progress) are "controlled and expirable"; saved-report share links "controlled to institute admins".
57. **Every export is audit-logged** with actor, dataset, timestamp; large exports asynchronous.
58. **Audit trails** are pervasive and append-only; license audit trail "immutable and append-only".

---

## 7. Security / Privacy Questions (OPEN DECISIONS)

Items the requirements leave open. **A policy decision is required before implementation.** Grouped by theme; each is referenced as OD-n throughout this document.

### 7.1 Minors, consent & family
- **OD-1** — Is parent consent mandatory for under-18s before *full* access, or only before certain features? (Registration proceeds with blank parent email; "the platform's child-safety policy governs follow-up" — policy undefined.)
- **OD-2** — How does a minor's own consent to monitoring interact with parent consent at registration? Is consent required for all monitored data or only some?
- **OD-3** — Default **scope of parent access**: does the parent see the child's forum posts, AI-companion chats/mood tracking, notes — or only learning/performance data?
- **OD-4** — **Dual control of one subscription**: both student (self-service) and parent (purchase/cancel/renewal) can manage the same child subscription; no precedence/conflict rule. Is the student's self-service billing disabled when a parent is linked?
- **OD-5** — Can a minor hold a payment method / complete a payment without the parental-approval flow? (Students can pay directly; minors need consent + spending limits.)
- **OD-6** — How is a **guardian attached to a child's account** ("a guardian on the child's account" can accept links & consent)?
- **OD-7** — How is the **child→teacher assignment** created (institute? school? manual)?
- **OD-8** — **Maximum linked children limit** value.
- **OD-9** — **Relationship verification method** for parent↔child ("matching school/institute records where available, or a verification step") — what step, and what if no records exist?
- **OD-10** — Effect of **parent account deletion** on child links, parental controls, child subscriptions; and of **child account deletion** on the parent's dashboard/consent records.
- **OD-11** — Visibility of **AI-companion mood/emotional data** to parent and teacher.
- **OD-12** — **Leaderboard identity**: leaderboards list "top performers" (identifiable) while peer comparison is explicitly anonymous; are names visible to all? Can parental controls hide a child from leaderboards?

### 7.2 Teachers, content & support
- **OD-13** — Is **"instructor"** (professional courses, live sessions) the same account type as **"teacher"** (parent communication, doubt escalation)?
- **OD-14** — **Teacher visibility of student data**: docs only show teachers receiving escalated doubts, parent-shared insights, and live-session attendance. Can teachers view student dashboards/scores/activity directly?
- **OD-15** — Is **"Support Agent"** (preset template) the same role as **"Student Support Administrator"** (predefined role)?
- **OD-16** — Naming inconsistency: SSO maps "admin contact → **Institute Administrator**" while RBAC calls it "**Institute Admin**" — canonical name?

### 7.3 Affiliates & commissions
- **OD-17** — **Multi-tier depth**: docs define exactly Tier 1 + Tier 2. Is depth capped at 2? Do Tier 3+ earn anything?
- **OD-18** — **Commission tier rates & thresholds** (per-tier rates, milestone criteria) — values unspecified.
- **OD-19** — **Minimum payout threshold** value for affiliate payment requests.
- **OD-20** — **Which program tiers permit discount code creation**.
- **OD-21** — **Affiliate visibility of referred-customer PII** (name/email vs. pseudonymous).
- **OD-22** — **Leaderboard privacy**: does the affiliate leaderboard expose other affiliates' identities or only names/ranks?
- **OD-23** — **Affiliate email outreach**: consent/opt-out handling for auto-responder sequences and scheduled promotions; can affiliates export lead contact lists?
- **OD-24** — **Pending commission handling on affiliate account deactivation** (paid out or forfeited?).
- **OD-25** — **Affiliate enrollment review**: who reviews (which platform role) and by what criteria?

### 7.4 Tenants, PII & data sharing
- **OD-26** — **Student PII in bulk CSV import** (institutes): which fields allowed (DOB, phone, address)? Retention/deletion of uploaded files?
- **OD-27** — **Student data export entitlements** for institutes: "only the data the Institute is entitled to" — entitlement definition (which fields) undefined.
- **OD-28** — **Integration data scope** (LMS/SIS/HRIS): field-level scope, direction, and whether student PII leaves the platform.
- **OD-29** — **API key scope values** and **webhook event catalog** (and whether events include student PII) — not enumerated.
- **OD-30** — **Benchmark data**: anonymization method, minimum cohort size, opt-out from contributing; how benchmark cohorts are formed and whether they include non-consenting users.
- **OD-31** — **Cross-tenant isolation** is implied by per-tenant scoping but **never stated explicitly** as a platform rule.
- **OD-32** — **Corporate permission matrix contents**: the "Permission-by-role matrix" feature is described but never enumerated (only two rules stated: admin-only billing, admin-only role management).
- **OD-33** — **HR Manager scope**: all employees or a subset? View-only or can enroll/edit?
- **OD-34** — **Corporate custom roles**: "only custom roles can [be edited]" implies creation, but no spec exists.
- **OD-35** — **CSR role split** (admin/finance/program manager over funding/billing/reporting) not itemized; **budget reallocation approver** and limits undefined.
- **OD-36** — **Organization admin role mapping** (super/program/finance/compliance → programs/users/billing/compliance) implied but never stated; whether super admin is required for role assignment unstated.
- **OD-37** — **Organization user role scopes** (learner/mentor/program coordinator) not itemized.
- **OD-38** — **Sponsor role split** (admin/marketing/finance) not itemized.
- **OD-39** — **CSR/Sponsor beneficiary masking spec**: what exactly is masked (name? contact? scores?)? Can sponsors/CSR ever see identifiable data (e.g., scholarship administration)?
- **OD-40** — **External report sharing** (CSR impact reports, Sponsor impact story via link): link expiry, access control, personal-data content.
- **OD-41** — **Government data** (Organization): data residency, retention, access restrictions for government-body accounts.
- **OD-42** — **SSO coverage**: SSO specified for Corporate and Organization only; CSR and Sponsor have none — intentional?
- **OD-43** — **Mandatory 2FA** option documented only for Corporate admins; CSR/Org/Sponsor admins have 2FA available but no mandatory option stated.
- **OD-44** — **Multi-admin minimums**: "at least one Corporate Admin" is stated; no equivalent last-admin rule for Organization, CSR, or Sponsor.
- **OD-45** — **Organization seat rule**: no stated rule that enrollment requires an available seat (Corporate has one explicitly).
- **OD-46** — **Data export scope per role** (finance admin vs compliance admin) unspecified.
- **OD-47** — **Account suspension**: "suspended" status exists for CSR/Sponsor/Organization, but who can suspend (platform only?) and what it blocks is unspecified.
- **OD-48** — **Certificate re-issue (CSR)**: who approves/fulfills the request (platform?)?
- **OD-49** — **Tertiary (Individuals)** account type: named in Super Admin scope but no doc tree defines its roles/permissions.
- **OD-50** — **Corporate→employee linking rules** (named in master list) not specified in detail.
- **OD-51** — **Institute verification criteria**: who performs it (manual vs automated) and what evidence is required.
- **OD-52** — **Sub-admin batch ownership**: how a coordinator's batch scope is assigned (by Admin? auto?).
- **OD-53** — **White-label scope per institute**: what an institute can/cannot rebrand.
- **OD-54** — **Trial for parent-purchased accounts**: free trial documented only for Student self-service flow.
- **OD-55** — **Consent form acknowledgments**: which consents are legally required (e.g., minor data processing) and who issues them.
- **OD-56** — **Offline content DRM**: device-level protection (sideloading, screen capture) not addressed.

### 7.5 Platform policy & retention
- **OD-57** — **Retention periods** for audit logs, denial logs, consent history, version history, chat transcripts — all "per policy" with no concrete durations.
- **OD-58** — **Consent withdrawal handling**: "account paused/closed per policy" — pause vs close undecided.
- **OD-59** — **Non-consenting users**: "restrict non-essential processing or deactivate" — choice not made.
- **OD-60** — **Velocity/location auto-block** default (configurable, default not set).
- **OD-61** — **Minimum age configured values** (13/18 are examples; jurisdiction-dependent).
- **OD-62** — **`data_protection_compliance/` docs are placeholder-level**: DRM mechanism, background-check standard/scope, anonymization method (pseudonymization vs aggregation), audit frequency — all undefined.
- **OD-63** — **`customer_support_management/` docs are placeholder-level**: SLA target values, escalation level definitions, chatbot scope — undefined.
- **OD-64** — **Multi-role scope resolution** alternatives (default is union; "per policy" implies configurability).
- **OD-65** — **Legal hold**: referenced (deletion precondition, bulk ops) but definition, authority, and mechanism unspecified.
- **OD-66** — **Concurrent-session overflow behavior**: "block or end-oldest" — choice not made.
- **OD-67** — **Password rotation**: "rotation notices for high-risk roles" — enforced or notice-only?
- **OD-68** — **Deletion propagation to backups**: depends on an undefined backup-retention policy.
- **OD-69** — **Financial record retention**: "retained for tax purposes and will be anonymized" — duration and method unspecified.
- **OD-70** — **SoD conflict rule catalog**: examples given ("create + approve, configure + execute") but full rule set undefined; accepted-conflict review-by dates have no default.
- **OD-71** — **Access review cadence**: "quarterly" stated as support; whether mandatory and for which roles unspecified.
- **OD-72** — **Critical-alert routing**: "SMS to on-duty admin" — on-duty rotation/assignment mechanism unspecified.
- **OD-73** — **Admin unlock of lockouts**: whether a second approver is required.
- **OD-74** — **Public API key scoping granularity** vs the internal RBAC catalog relationship.
- **OD-75** — **Geo-restriction enforcement on existing sessions**: "optional" — default not set.

---

## 8. Approval

| | |
|---|---|
| Deliverable | MDA Identity, Responsibility & Access Model |
| Status | **DRAFT — pending approval** |
| Open decisions | 75 (OD-1 … OD-75) — must be resolved or explicitly deferred before implementation |
| Excluded by scope | Application code, database table design (`users`, `roles`, `permissions`, etc.) |

**Approval:** ____________________  Date: ____________
