# 7. Access & API — Test Cases

User Type: **Organization**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: access_api.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 7.1 | SSO setup (SAML/OIDC) | TC-ORG-7-01-001 |
| 7.1 | Identity provider configuration | TC-ORG-7-01-002 |
| 7.1 | Just-in-time user provisioning | TC-ORG-7-01-003 |
| 7.1 | SSO login flow | TC-ORG-7-01-004 |
| 7.1 | SSO status and troubleshooting | TC-ORG-7-01-005 |
| 7.1 | Single Sign-On (SSO) available on web and mobile | TC-ORG-7-01-006 |
| 7.1 | single sign-on (sso) event logging (viewed) | TC-ORG-7-01-007 |
| 7.1 | Audit logging of single sign-on (sso) | TC-ORG-7-01-008 |
| 7.1 | Rule: SSO setup (SAML/OIDC). | TC-ORG-7-01-009 |
| 7.1 | Rule: Identity provider configuration. | TC-ORG-7-01-010 |
| 7.1 | Rule: Just-in-time user provisioning. | TC-ORG-7-01-011 |
| 7.1 | Rule: SSO login flow. | TC-ORG-7-01-012 |
| 7.1 | Rule: SSO status and troubleshooting. | TC-ORG-7-01-013 |
| 7.2 | API key generation and management | TC-ORG-7-02-014 |
| 7.2 | Rate limit information | TC-ORG-7-02-015 |
| 7.2 | Documented endpoints (users, programs, progress) | TC-ORG-7-02-016 |
| 7.2 | API usage monitoring | TC-ORG-7-02-017 |
| 7.2 | API key revocation | TC-ORG-7-02-018 |
| 7.2 | API Access available on web and mobile | TC-ORG-7-02-019 |
| 7.2 | api access event logging (viewed) | TC-ORG-7-02-020 |
| 7.2 | Audit logging of api access | TC-ORG-7-02-021 |
| 7.2 | Rule: API key generation and management. | TC-ORG-7-02-022 |
| 7.2 | Rule: Rate limit information. | TC-ORG-7-02-023 |
| 7.2 | Rule: Documented endpoints (users, programs, progress). | TC-ORG-7-02-024 |
| 7.2 | Rule: API usage monitoring. | TC-ORG-7-02-025 |
| 7.2 | Rule: API key revocation. | TC-ORG-7-02-026 |

## 7.1 Single Sign-On (SSO)

### TC-ORG-7-01-001 — SSO setup (SAML/OIDC)
**Type:** Positive
**Covers:** 7.1 → SSO setup (SAML/OIDC); Rule: SSO setup (SAML/OIDC).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: SSO setup (SAML/OIDC).
2. Observe the result and verify the full behavior: SSO setup (SAML/OIDC).
**Expected Result:** SSO setup (SAML/OIDC) — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-7-01-002 — Identity provider configuration
**Type:** Positive
**Covers:** 7.1 → Identity provider configuration; Rule: Identity provider configuration.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Identity provider configuration.
2. Observe the result and verify the full behavior: Identity provider configuration.
**Expected Result:** Identity provider configuration — delivered exactly as documented.
**Priority:** High

### TC-ORG-7-01-003 — Just-in-time user provisioning
**Type:** Positive
**Covers:** 7.1 → Just-in-time user provisioning; Rule: Just-in-time user provisioning.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Just-in-time user provisioning.
2. Observe the result and verify the full behavior: Just-in-time user provisioning.
**Expected Result:** Just-in-time user provisioning — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-004 — SSO login flow
**Type:** Positive
**Covers:** 7.1 → SSO login flow; Rule: SSO login flow.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: SSO login flow.
2. Observe the result and verify the full behavior: SSO login flow.
**Expected Result:** SSO login flow — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-005 — SSO status and troubleshooting
**Type:** Positive
**Covers:** 7.1 → SSO status and troubleshooting; Rule: SSO status and troubleshooting.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: SSO status and troubleshooting.
2. Observe the result and verify the full behavior: SSO status and troubleshooting.
**Expected Result:** SSO status and troubleshooting — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-006 — Single Sign-On (SSO) available on web and mobile
**Type:** Positive
**Covers:** 7.1 → Single Sign-On (SSO) available on web and mobile; Rule: SSO setup (SAML/OIDC).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Single Sign-On (SSO) available on web and mobile.
2. Observe the result and verify the full behavior: Single Sign-On (SSO) available on web and mobile.
**Expected Result:** Single Sign-On (SSO) available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-007 — single sign-on (sso) event logging (viewed)
**Type:** Positive
**Covers:** 7.1 → single sign-on (sso) event logging (viewed); Rule: Identity provider configuration.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: single sign-on (sso) event logging (viewed).
2. Observe the result and verify the full behavior: single sign-on (sso) event logging (viewed).
**Expected Result:** single sign-on (sso) event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-008 — Audit logging of single sign-on (sso)
**Type:** Positive
**Covers:** 7.1 → Audit logging of single sign-on (sso); Rule: Just-in-time user provisioning.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Audit logging of single sign-on (sso).
2. Observe the result and verify the full behavior: Audit logging of single sign-on (sso).
**Expected Result:** Audit logging of single sign-on (sso) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-009 — Rule: SSO setup (SAML/OIDC).
**Type:** Positive
**Covers:** 7.1 → Rule: SSO setup (SAML/OIDC).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: SSO setup (SAML/OIDC).
2. Observe the result and verify the full behavior: SSO setup (SAML/OIDC).
**Expected Result:** SSO setup (SAML/OIDC). — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-7-01-010 — Rule: Identity provider configuration.
**Type:** Positive
**Covers:** 7.1 → Rule: Identity provider configuration.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Identity provider configuration.
2. Observe the result and verify the full behavior: Identity provider configuration.
**Expected Result:** Identity provider configuration. — delivered exactly as documented.
**Priority:** High

### TC-ORG-7-01-011 — Rule: Just-in-time user provisioning.
**Type:** Positive
**Covers:** 7.1 → Rule: Just-in-time user provisioning.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Just-in-time user provisioning.
2. Observe the result and verify the full behavior: Just-in-time user provisioning.
**Expected Result:** Just-in-time user provisioning. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-012 — Rule: SSO login flow.
**Type:** Positive
**Covers:** 7.1 → Rule: SSO login flow.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: SSO login flow.
2. Observe the result and verify the full behavior: SSO login flow.
**Expected Result:** SSO login flow. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-01-013 — Rule: SSO status and troubleshooting.
**Type:** Positive
**Covers:** 7.1 → Rule: SSO status and troubleshooting.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: SSO status and troubleshooting.
2. Observe the result and verify the full behavior: SSO status and troubleshooting.
**Expected Result:** SSO status and troubleshooting. — delivered exactly as documented.
**Priority:** Medium

## 7.2 API Access

### TC-ORG-7-02-014 — API key generation and management
**Type:** Positive
**Covers:** 7.2 → API key generation and management; Rule: API key generation and management.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: API key generation and management.
2. Observe the result and verify the full behavior: API key generation and management.
**Expected Result:** API key generation and management — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-7-02-015 — Rate limit information
**Type:** Positive
**Covers:** 7.2 → Rate limit information; Rule: Rate limit information.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Rate limit information.
2. Observe the result and verify the full behavior: Rate limit information.
**Expected Result:** Rate limit information — delivered exactly as documented.
**Priority:** High

### TC-ORG-7-02-016 — Documented endpoints (users, programs, progress)
**Type:** Positive
**Covers:** 7.2 → Documented endpoints (users, programs, progress); Rule: Documented endpoints (users, programs, progress).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Documented endpoints (users, programs, progress).
2. Observe the result and verify the full behavior: Documented endpoints (users, programs, progress).
**Expected Result:** Documented endpoints (users, programs, progress) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-017 — API usage monitoring
**Type:** Positive
**Covers:** 7.2 → API usage monitoring; Rule: API usage monitoring.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: API usage monitoring.
2. Observe the result and verify the full behavior: API usage monitoring.
**Expected Result:** API usage monitoring — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-018 — API key revocation
**Type:** Positive
**Covers:** 7.2 → API key revocation; Rule: API key revocation.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: API key revocation.
2. Observe the result and verify the full behavior: API key revocation.
**Expected Result:** API key revocation — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-019 — API Access available on web and mobile
**Type:** Positive
**Covers:** 7.2 → API Access available on web and mobile; Rule: API key generation and management.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: API Access available on web and mobile.
2. Observe the result and verify the full behavior: API Access available on web and mobile.
**Expected Result:** API Access available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-020 — api access event logging (viewed)
**Type:** Positive
**Covers:** 7.2 → api access event logging (viewed); Rule: Rate limit information.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: api access event logging (viewed).
2. Observe the result and verify the full behavior: api access event logging (viewed).
**Expected Result:** api access event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-021 — Audit logging of api access
**Type:** Positive
**Covers:** 7.2 → Audit logging of api access; Rule: Documented endpoints (users, programs, progress).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Audit logging of api access.
2. Observe the result and verify the full behavior: Audit logging of api access.
**Expected Result:** Audit logging of api access — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-022 — Rule: API key generation and management.
**Type:** Positive
**Covers:** 7.2 → Rule: API key generation and management.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: API key generation and management.
2. Observe the result and verify the full behavior: API key generation and management.
**Expected Result:** API key generation and management. — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-7-02-023 — Rule: Rate limit information.
**Type:** Positive
**Covers:** 7.2 → Rule: Rate limit information.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Rate limit information.
2. Observe the result and verify the full behavior: Rate limit information.
**Expected Result:** Rate limit information. — delivered exactly as documented.
**Priority:** High

### TC-ORG-7-02-024 — Rule: Documented endpoints (users, programs, progress).
**Type:** Positive
**Covers:** 7.2 → Rule: Documented endpoints (users, programs, progress).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Documented endpoints (users, programs, progress).
2. Observe the result and verify the full behavior: Documented endpoints (users, programs, progress).
**Expected Result:** Documented endpoints (users, programs, progress). — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-025 — Rule: API usage monitoring.
**Type:** Positive
**Covers:** 7.2 → Rule: API usage monitoring.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: API usage monitoring.
2. Observe the result and verify the full behavior: API usage monitoring.
**Expected Result:** API usage monitoring. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-7-02-026 — Rule: API key revocation.
**Type:** Positive
**Covers:** 7.2 → Rule: API key revocation.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: API key revocation.
2. Observe the result and verify the full behavior: API key revocation.
**Expected Result:** API key revocation. — delivered exactly as documented.
**Priority:** Medium
