# 3. Content Protection — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: content_protection.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature,
  expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.1 Digital Rights Management (DRM) | DRM: the DRM (the DRM, the content, the license, the date) | TC-SA-22-03-001 |
| 3.1 Digital Rights Management (DRM) | Content: the content (the content, the type, the date) | TC-SA-22-03-002 |
| 3.1 Digital Rights Management (DRM) | License: the license (the license of the content, the user, the date) | TC-SA-22-03-003 |
| 3.1 Digital Rights Management (DRM) | DRM status: the status (the protected, the unprotected) | TC-SA-22-03-004 |
| 3.1 Digital Rights Management (DRM) | DRM count: the count (the count of the content by status) | TC-SA-22-03-005 |
| 3.1 Digital Rights Management (DRM) | DRM view: the view (the DRMs, the content, the licenses, the dates) | TC-SA-22-03-006 |
| 3.1 Digital Rights Management (DRM) | DRM export: the export (the DRMs, the format, the content) | TC-SA-22-03-007 |
| 3.1 Digital Rights Management (DRM) | Audit logging of the DRM configuration | TC-SA-22-03-008 |
| 3.1 Digital Rights Management (DRM) | Rule: the DRM is the protection (the DRM, the content, the license, the date); the DRM is the shield | TC-SA-22-03-001 |
| 3.1 Digital Rights Management (DRM) | Rule: the content is the subject (the content, the type, the date); the content is the asset | TC-SA-22-03-002 |
| 3.1 Digital Rights Management (DRM) | Rule: the license is the permission (the license of the content, the user, the date); the license is the right | TC-SA-22-03-003 |
| 3.1 Digital Rights Management (DRM) | Rule: the DRM status is the state (the protected, the unprotected); the status is the control | TC-SA-22-03-004 |
| 3.1 Digital Rights Management (DRM) | Rule: the content is protected (the DRMs, the content, the licenses, the dates); the protection is managed | TC-SA-22-03-006 |
| 3.1 Digital Rights Management (DRM) | Rule: DRM configuration is audit-logged with the DRM, content, and timestamp | TC-SA-22-03-008 |
| 3.2 Prevent Unauthorized Video Downloads | Prevention: the prevention (the prevention, the video, the user, the date) | TC-SA-22-03-009 |
| 3.2 Prevent Unauthorized Video Downloads | Video: the video (the video, the title, the date) | TC-SA-22-03-010 |
| 3.2 Prevent Unauthorized Video Downloads | User: the user (the user, the name, the prevention) | TC-SA-22-03-011 |
| 3.2 Prevent Unauthorized Video Downloads | Download attempt: the attempt (the attempt, the user, the date) | TC-SA-22-03-012 |
| 3.2 Prevent Unauthorized Video Downloads | Prevention status: the status (the blocked, the allowed) | TC-SA-22-03-013 |
| 3.2 Prevent Unauthorized Video Downloads | Prevention count: the count (the count of the attempts) | TC-SA-22-03-014 |
| 3.2 Prevent Unauthorized Video Downloads | Prevention view: the view (the preventions, the videos, the users, the dates) | TC-SA-22-03-015 |
| 3.2 Prevent Unauthorized Video Downloads | Audit logging of the download prevention | TC-SA-22-03-016 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: the prevention is the block (the prevention, the video, the user, the date); the prevention is the stop | TC-SA-22-03-009 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: the video is the content (the video, the title, the date); the video is the asset | TC-SA-22-03-010 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: the user is the actor (the user, the name, the prevention); the user is the downloader | TC-SA-22-03-011 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: the prevention status is the state (the blocked, the allowed); the status is the control | TC-SA-22-03-013 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: the downloads are prevented (the preventions, the videos, the users, the dates); the block is managed | TC-SA-22-03-015 |
| 3.2 Prevent Unauthorized Video Downloads | Rule: download prevention is audit-logged with the prevention, video, and timestamp | TC-SA-22-03-016 |
| 3.3 Watermarking for Piracy Prevention | Watermark: the watermark (the watermark, the content, the user, the date) | TC-SA-22-03-017 |
| 3.3 Watermarking for Piracy Prevention | Content: the content (the content, the type, the date) | TC-SA-22-03-018 |
| 3.3 Watermarking for Piracy Prevention | User: the user (the user, the name, the watermark) | TC-SA-22-03-019 |
| 3.3 Watermarking for Piracy Prevention | Watermark type: the type (the type of the watermark, e.g., the visible, the invisible) | TC-SA-22-03-020 |
| 3.3 Watermarking for Piracy Prevention | Watermark status: the status (the applied, the not-applied) | TC-SA-22-03-021 |
| 3.3 Watermarking for Piracy Prevention | Watermark count: the count (the count of the watermarks) | TC-SA-22-03-022 |
| 3.3 Watermarking for Piracy Prevention | Watermark view: the view (the watermarks, the content, the users, the dates) | TC-SA-22-03-023 |
| 3.3 Watermarking for Piracy Prevention | Audit logging of the content watermarking | TC-SA-22-03-024 |
| 3.3 Watermarking for Piracy Prevention | Rule: the watermark is the trace (the watermark, the content, the user, the date); the watermark is the mark | TC-SA-22-03-017 |
| 3.3 Watermarking for Piracy Prevention | Rule: the content is the subject (the content, the type, the date); the content is the asset | TC-SA-22-03-018 |
| 3.3 Watermarking for Piracy Prevention | Rule: the user is the viewer (the user, the name, the watermark); the user is the actor | TC-SA-22-03-019 |
| 3.3 Watermarking for Piracy Prevention | Rule: the watermark type is the mode (the type of the watermark, e.g., the visible, the invisible); the type is the style | TC-SA-22-03-020 |
| 3.3 Watermarking for Piracy Prevention | Rule: the content is watermarked (the watermarks, the content, the users, the dates); the trace is managed | TC-SA-22-03-023 |
| 3.3 Watermarking for Piracy Prevention | Rule: content watermarking is audit-logged with the watermark, content, and timestamp | TC-SA-22-03-024 |
| 3.4 Screen Recording Detection | Detection: the detection (the detection, the user, the session, the date) | TC-SA-22-03-025 |
| 3.4 Screen Recording Detection | User: the user (the user, the name, the detection) | TC-SA-22-03-026 |
| 3.4 Screen Recording Detection | Session: the session (the session, the user, the date) | TC-SA-22-03-027 |
| 3.4 Screen Recording Detection | Detection status: the status (the detected, the not-detected) | TC-SA-22-03-028 |
| 3.4 Screen Recording Detection | Detection count: the count (the count of the detections) | TC-SA-22-03-029 |
| 3.4 Screen Recording Detection | Detection view: the view (the detections, the users, the sessions, the dates) | TC-SA-22-03-030 |
| 3.4 Screen Recording Detection | Detection export: the export (the detections, the format, the user) | TC-SA-22-03-031 |
| 3.4 Screen Recording Detection | Audit logging of the screen recording detection | TC-SA-22-03-032 |
| 3.4 Screen Recording Detection | Rule: the detection is the alert (the detection, the user, the session, the date); the detection is the signal | TC-SA-22-03-025 |
| 3.4 Screen Recording Detection | Rule: the user is the actor (the user, the name, the detection); the user is the recorder | TC-SA-22-03-026 |
| 3.4 Screen Recording Detection | Rule: the session is the context (the session, the user, the date); the session is the moment | TC-SA-22-03-027 |
| 3.4 Screen Recording Detection | Rule: the detection status is the state (the detected, the not-detected); the status is the control | TC-SA-22-03-028 |
| 3.4 Screen Recording Detection | Rule: the recording is detected (the detections, the users, the sessions, the dates); the alert is managed | TC-SA-22-03-030 |
| 3.4 Screen Recording Detection | Rule: screen recording detection is audit-logged with the detection, user, and timestamp | TC-SA-22-03-032 |
| 3.5 Geo-restrictions | Restriction: the restriction (the restriction, the content, the region, the date) | TC-SA-22-03-033 |
| 3.5 Geo-restrictions | Content: the content (the content, the type, the date) | TC-SA-22-03-034 |
| 3.5 Geo-restrictions | Region: the region (the region of the restriction, the country, the date) | TC-SA-22-03-035 |
| 3.5 Geo-restrictions | Restriction status: the status (the restricted, the unrestricted) | TC-SA-22-03-036 |
| 3.5 Geo-restrictions | Restriction count: the count (the count of the restrictions) | TC-SA-22-03-037 |
| 3.5 Geo-restrictions | Restriction view: the view (the restrictions, the content, the regions, the dates) | TC-SA-22-03-038 |
| 3.5 Geo-restrictions | Restriction export: the export (the restrictions, the format, the region) | TC-SA-22-03-039 |
| 3.5 Geo-restrictions | Audit logging of the geo-restriction configuration | TC-SA-22-03-040 |
| 3.5 Geo-restrictions | Rule: the restriction is the limit (the restriction, the content, the region, the date); the restriction is the boundary | TC-SA-22-03-033 |
| 3.5 Geo-restrictions | Rule: the content is the subject (the content, the type, the date); the content is the asset | TC-SA-22-03-034 |
| 3.5 Geo-restrictions | Rule: the region is the location (the region of the restriction, the country, the date); the region is the place | TC-SA-22-03-035 |
| 3.5 Geo-restrictions | Rule: the restriction status is the state (the restricted, the unrestricted); the status is the control | TC-SA-22-03-036 |
| 3.5 Geo-restrictions | Rule: the content is restricted (the restrictions, the content, the regions, the dates); the limit is managed | TC-SA-22-03-038 |
| 3.5 Geo-restrictions | Rule: geo-restriction configuration is audit-logged with the restriction, region, and timestamp | TC-SA-22-03-040 |
| 3.6 Secure Video Streaming (DRM) | Streaming: the streaming (the streaming, the video, the user, the date) | TC-SA-22-03-041 |
| 3.6 Secure Video Streaming (DRM) | Video: the video (the video, the title, the date) | TC-SA-22-03-042 |
| 3.6 Secure Video Streaming (DRM) | User: the user (the user, the name, the streaming) | TC-SA-22-03-043 |
| 3.6 Secure Video Streaming (DRM) | DRM: the DRM (the DRM of the streaming, the license, the date) | TC-SA-22-03-044 |
| 3.6 Secure Video Streaming (DRM) | Streaming status: the status (the secure, the insecure) | TC-SA-22-03-045 |
| 3.6 Secure Video Streaming (DRM) | Streaming count: the count (the count of the streamings) | TC-SA-22-03-046 |
| 3.6 Secure Video Streaming (DRM) | Streaming view: the view (the streamings, the videos, the users, the dates) | TC-SA-22-03-047 |
| 3.6 Secure Video Streaming (DRM) | Audit logging of the secure video streaming | TC-SA-22-03-048 |
| 3.6 Secure Video Streaming (DRM) | Rule: the streaming is the delivery (the streaming, the video, the user, the date); the streaming is the playback | TC-SA-22-03-041 |
| 3.6 Secure Video Streaming (DRM) | Rule: the video is the content (the video, the title, the date); the video is the asset | TC-SA-22-03-042 |
| 3.6 Secure Video Streaming (DRM) | Rule: the user is the viewer (the user, the name, the streaming); the user is the actor | TC-SA-22-03-043 |
| 3.6 Secure Video Streaming (DRM) | Rule: the streaming status is the state (the secure, the insecure); the status is the control | TC-SA-22-03-045 |
| 3.6 Secure Video Streaming (DRM) | Rule: the videos are streamed securely (the streamings, the videos, the users, the dates); the delivery is managed | TC-SA-22-03-047 |
| 3.6 Secure Video Streaming (DRM) | Rule: secure video streaming is audit-logged with the streaming, video, and timestamp | TC-SA-22-03-048 |

## 3.1 Digital Rights Management (DRM)

### TC-SA-22-03-001 — DRM: the DRM (the DRM, the content, the license, the date); the DRM is the shield
**Type:** Positive
**Covers:** 3.1 → DRM: the DRM (the DRM, the content, the license, the date); Rule: the DRM is the protection (the DRM, the content, the license, the date); the DRM is the shield
**Preconditions:** Super Admin is logged in; platform content exists.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Digital Rights Management (DRM).
2. Apply the DRM: the DRM (the DRM, the content, the license, the date) — verify the DRM is the protection.
3. Verify the DRM shows the content, the license, and the date.
4. Verify the DRM-protected content can only be played by licensed users.
**Expected Result:** The DRM is applied — the DRM, the content, the license, and the date are the shield.
**Priority:** Critical

### TC-SA-22-03-002 — Content: the content (the content, the type, the date); the content is the asset
**Type:** Positive
**Covers:** 3.1 → Content: the content (the content, the type, the date); Rule: the content is the subject (the content, the type, the date); the content is the asset
**Preconditions:** Multiple content types exist on the platform.
**Steps:**
1. Select the content: the content (the content, the type, the date) — verify the content is the subject.
2. Verify the content shows the type and the date.
3. Verify DRM can be applied to each content type.
**Expected Result:** The content is selected — the content, the type, and the date are the asset.
**Priority:** High

### TC-SA-22-03-003 — License: the license (the license of the content, the user, the date); the license is the right
**Type:** Positive
**Covers:** 3.1 → License: the license (the license of the content, the user, the date); Rule: the license is the permission (the license of the content, the user, the date); the license is the right
**Preconditions:** DRM is applied to content; users with and without licenses exist.
**Steps:**
1. Issue the license: the license (the license of the content, the user, the date) — verify the license is the permission.
2. Verify the license shows the user and the date.
3. Verify a licensed user can play the content and an unlicensed user cannot.
**Expected Result:** The license is issued — the license of the content, the user, and the date are the right.
**Priority:** High

### TC-SA-22-03-004 — DRM status: the status (the protected, the unprotected); the status is the control
**Type:** Edge
**Covers:** 3.1 → DRM status: the status (the protected, the unprotected); Rule: the DRM status is the state (the protected, the unprotected); the status is the control
**Preconditions:** DRM-protected content exists; newly uploaded premium content that has not yet been DRM-protected (unprotected edge) is also prepared.
**Steps:**
1. View the DRM status: the status (the protected, the unprotected) — verify the DRM status is the state.
2. Verify existing premium content shows protected.
3. Check the new unprotected premium content — verify it is flagged as unprotected with an alert (premium content is never silently exposed); the system either applies DRM automatically or raises a visible warning.
**Expected Result:** The DRM status is shown — the protected and the unprotected are the control; no premium content is ever silently left unprotected.
**Priority:** High

### TC-SA-22-03-005 — DRM count: the count (the count of the content by status); the count is the measure
**Type:** Positive
**Covers:** 3.1 → DRM count: the count (the count of the content by status)
**Preconditions:** Content with protected and unprotected statuses exists.
**Steps:**
1. View the DRM count: the count (the count of the content by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of content items in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The DRM count is shown — the count of the content by status is the measure.
**Priority:** High

### TC-SA-22-03-006 — DRM view: the view (the DRMs, the content, the licenses, the dates); the protection is managed
**Type:** Positive
**Covers:** 3.1 → DRM view: the view (the DRMs, the content, the licenses, the dates); Rule: the content is protected (the DRMs, the content, the licenses, the dates); the protection is managed
**Preconditions:** Multiple DRM-protected content items exist.
**Steps:**
1. View the DRMs: the view (the DRMs, the content, the licenses, the dates) — verify the content is protected.
2. Verify each entry shows the content, the license, and the date.
3. Verify the protection is managed (view, license, revoke).
**Expected Result:** The DRMs are viewed — the DRMs, the content, the licenses, and the dates are visible; the protection is managed.
**Priority:** High

### TC-SA-22-03-007 — DRM export: the export (the DRMs, the format, the content); the export is the record
**Type:** Edge
**Covers:** 3.1 → DRM export: the export (the DRMs, the format, the content)
**Preconditions:** DRM-protected content exists for multiple content types; a type with no DRM-protected content (zero-row export edge) is also prepared.
**Steps:**
1. Export the DRMs: the export (the DRMs, the format, the content) — verify the export is the record.
2. Verify the export contains all DRM records for the selected content in the selected format.
3. Export the empty content type — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The DRMs are exported — the DRMs, the format, and the content are the record; empty-type exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-03-008 — DRM configuration is audit-logged with the DRM, content, and timestamp
**Type:** Positive
**Covers:** 3.1 → Audit logging of the DRM configuration; Rule: DRM configuration is audit-logged with the DRM, content, and timestamp
**Preconditions:** Super Admin has configured DRM.
**Steps:**
1. Open the audit trail and filter by "DRM".
2. Verify entries show the DRM, the content, and the timestamp.
**Expected Result:** The DRM configuration is audit-logged with the DRM, content, and timestamp.
**Priority:** Critical

## 3.2 Prevent Unauthorized Video Downloads

### TC-SA-22-03-009 — Prevention: the prevention (the prevention, the video, the user, the date); the prevention is the stop
**Type:** Positive
**Covers:** 3.2 → Prevention: the prevention (the prevention, the video, the user, the date); Rule: the prevention is the block (the prevention, the video, the user, the date); the prevention is the stop
**Preconditions:** Super Admin is logged in; platform videos exist.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Prevent Unauthorized Video Downloads.
2. Enable the prevention: the prevention (the prevention, the video, the user, the date) — verify the prevention is the block.
3. Verify the prevention shows the video, the user, and the date.
4. Attempt to download a protected video — verify the download is blocked.
**Expected Result:** The prevention is enabled — the prevention, the video, the user, and the date are the stop.
**Priority:** Critical

### TC-SA-22-03-010 — Video: the video (the video, the title, the date); the video is the asset
**Type:** Positive
**Covers:** 3.2 → Video: the video (the video, the title, the date); Rule: the video is the content (the video, the title, the date); the video is the asset
**Preconditions:** Multiple videos exist on the platform.
**Steps:**
1. Select the video: the video (the video, the title, the date) — verify the video is the content.
2. Verify the video shows the title and the date.
3. Verify download prevention can be applied per video.
**Expected Result:** The video is selected — the video, the title, and the date are the asset.
**Priority:** High

### TC-SA-22-03-011 — User: the user (the user, the name, the prevention); the user is the downloader
**Type:** Positive
**Covers:** 3.2 → User: the user (the user, the name, the prevention); Rule: the user is the actor (the user, the name, the prevention); the user is the downloader
**Preconditions:** Multiple users have attempted downloads.
**Steps:**
1. Select the user: the user (the user, the name, the prevention) — verify the user is the actor.
2. Verify the user shows the name and the prevention.
3. Verify each blocked attempt is attributed to the correct user.
**Expected Result:** The user is selected — the user, the name, and the prevention are the downloader.
**Priority:** High

### TC-SA-22-03-012 — Download attempt: the attempt (the attempt, the user, the date); the attempt is the event
**Type:** Positive
**Covers:** 3.2 → Download attempt: the attempt (the attempt, the user, the date)
**Preconditions:** A user has attempted to download a protected video.
**Steps:**
1. View the download attempt: the attempt (the attempt, the user, the date) — verify the attempt is the event.
2. Verify the attempt shows the user and the date.
3. Verify the attempt is recorded even when the download is blocked.
**Expected Result:** The download attempt is shown — the attempt, the user, and the date are the event.
**Priority:** High

### TC-SA-22-03-013 — Prevention status: the status (the blocked, the allowed); the status is the control
**Type:** Edge
**Covers:** 3.2 → Prevention status: the status (the blocked, the allowed); Rule: the prevention status is the state (the blocked, the allowed); the status is the control
**Preconditions:** Blocked and allowed download attempts exist; a user with a legitimate offline-viewing license attempting a download (licensed-download edge) is also prepared.
**Steps:**
1. View the prevention status: the status (the blocked, the allowed) — verify the prevention status is the state.
2. Verify an unauthorized attempt shows blocked.
3. Check the licensed user's attempt — verify it shows allowed (licensed offline viewing works); the block never breaks legitimate licensed access.
**Expected Result:** The prevention status is shown — the blocked and the allowed are the control; licensed users keep working, unauthorized users are blocked.
**Priority:** High

### TC-SA-22-03-014 — Prevention count: the count (the count of the attempts); the count is the measure
**Type:** Positive
**Covers:** 3.2 → Prevention count: the count (the count of the attempts)
**Preconditions:** Multiple download attempts exist.
**Steps:**
1. View the prevention count: the count (the count of the attempts) — verify the count is the measure.
2. Verify the count matches the actual number of attempts.
3. Trigger a new attempt — verify the count increments.
**Expected Result:** The prevention count is shown — the count of the attempts is the measure.
**Priority:** High

### TC-SA-22-03-015 — Prevention view: the view (the preventions, the videos, the users, the dates); the block is managed
**Type:** Positive
**Covers:** 3.2 → Prevention view: the view (the preventions, the videos, the users, the dates); Rule: the downloads are prevented (the preventions, the videos, the users, the dates); the block is managed
**Preconditions:** Multiple download attempts exist.
**Steps:**
1. View the preventions: the view (the preventions, the videos, the users, the dates) — verify the downloads are prevented.
2. Verify each entry shows the video, the user, and the date.
3. Verify the block is managed (view, block, escalate repeat offenders).
**Expected Result:** The preventions are viewed — the preventions, the videos, the users, and the dates are visible; the block is managed.
**Priority:** High

### TC-SA-22-03-016 — Download prevention is audit-logged with the prevention, video, and timestamp
**Type:** Positive
**Covers:** 3.2 → Audit logging of the download prevention; Rule: download prevention is audit-logged with the prevention, video, and timestamp
**Preconditions:** A download attempt has been blocked.
**Steps:**
1. Open the audit trail and filter by "download prevention".
2. Verify entries show the prevention, the video, and the timestamp.
**Expected Result:** The download prevention is audit-logged with the prevention, video, and timestamp.
**Priority:** Critical

## 3.3 Watermarking for Piracy Prevention

### TC-SA-22-03-017 — Watermark: the watermark (the watermark, the content, the user, the date); the watermark is the mark
**Type:** Positive
**Covers:** 3.3 → Watermark: the watermark (the watermark, the content, the user, the date); Rule: the watermark is the trace (the watermark, the content, the user, the date); the watermark is the mark
**Preconditions:** Super Admin is logged in; platform content exists.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Watermarking for Piracy Prevention.
2. Apply the watermark: the watermark (the watermark, the content, the user, the date) — verify the watermark is the trace.
3. Verify the watermark shows the content, the user, and the date.
4. Play the watermarked content — verify the watermark is present and identifies the viewing user.
**Expected Result:** The watermark is applied — the watermark, the content, the user, and the date are the mark.
**Priority:** Critical

### TC-SA-22-03-018 — Content: the content (the content, the type, the date); the content is the asset
**Type:** Positive
**Covers:** 3.3 → Content: the content (the content, the type, the date); Rule: the content is the subject (the content, the type, the date); the content is the asset
**Preconditions:** Multiple content types exist on the platform.
**Steps:**
1. Select the content: the content (the content, the type, the date) — verify the content is the subject.
2. Verify the content shows the type and the date.
3. Verify watermarking can be applied to each content type.
**Expected Result:** The content is selected — the content, the type, and the date are the asset.
**Priority:** High

### TC-SA-22-03-019 — User: the user (the user, the name, the watermark); the user is the actor
**Type:** Positive
**Covers:** 3.3 → User: the user (the user, the name, the watermark); Rule: the user is the viewer (the user, the name, the watermark); the user is the actor
**Preconditions:** Multiple users have viewed watermarked content.
**Steps:**
1. Select the user: the user (the user, the name, the watermark) — verify the user is the viewer.
2. Verify the user shows the name and the watermark.
3. Verify each user's playback carries a watermark unique to that user (piracy traceability).
**Expected Result:** The user is selected — the user, the name, and the watermark are the actor; leaked copies can be traced to the leaking user.
**Priority:** High

### TC-SA-22-03-020 — Watermark type: the type (the type of the watermark, e.g., the visible, the invisible); the type is the style
**Type:** Positive
**Covers:** 3.3 → Watermark type: the type (the type of the watermark, e.g., the visible, the invisible); Rule: the watermark type is the mode (the type of the watermark, e.g., the visible, the invisible); the type is the style
**Preconditions:** Visible and invisible watermark types are available.
**Steps:**
1. Set the watermark type: the type (the type of the watermark, e.g., the visible, the invisible) — verify the watermark type is the mode.
2. Apply the visible type — verify the mark is visible on playback.
3. Apply the invisible type — verify the mark is embedded but not visible, and is extractable for tracing.
**Expected Result:** The watermark type is set — the type of the watermark (the visible, the invisible) is the style.
**Priority:** High

### TC-SA-22-03-021 — Watermark status: the status (the applied, the not-applied); the status is the control
**Type:** Edge
**Covers:** 3.3 → Watermark status: the status (the applied, the not-applied); Rule: the watermark status is the state (the applied, the not-applied); the status is the control
**Preconditions:** Watermarked content exists; newly uploaded premium content that has not yet been watermarked (not-applied edge) is also prepared.
**Steps:**
1. View the watermark status: the status (the applied, the not-applied) — verify the watermark status is the state.
2. Verify existing premium content shows applied.
3. Check the new not-applied premium content — verify it is flagged with an alert (premium content is never silently exposed without a watermark); the system either applies the watermark automatically or raises a visible warning.
**Expected Result:** The watermark status is shown — the applied and the not-applied are the control; no premium content is ever silently left unwatermarked.
**Priority:** High

### TC-SA-22-03-022 — Watermark count: the count (the count of the watermarks); the count is the measure
**Type:** Positive
**Covers:** 3.3 → Watermark count: the count (the count of the watermarks)
**Preconditions:** Multiple watermarks exist.
**Steps:**
1. View the watermark count: the count (the count of the watermarks) — verify the count is the measure.
2. Verify the count matches the actual number of watermarks.
3. Apply a new watermark — verify the count increments.
**Expected Result:** The watermark count is shown — the count of the watermarks is the measure.
**Priority:** High

### TC-SA-22-03-023 — Watermark view: the view (the watermarks, the content, the users, the dates); the trace is managed
**Type:** Positive
**Covers:** 3.3 → Watermark view: the view (the watermarks, the content, the users, the dates); Rule: the content is watermarked (the watermarks, the content, the users, the dates); the trace is managed
**Preconditions:** Multiple watermarks exist.
**Steps:**
1. View the watermarks: the view (the watermarks, the content, the users, the dates) — verify the content is watermarked.
2. Verify each watermark shows the content, the user, and the date.
3. Verify the trace is managed (view, trace leaks, act).
**Expected Result:** The watermarks are viewed — the watermarks, the content, the users, and the dates are visible; the trace is managed.
**Priority:** High

### TC-SA-22-03-024 — Content watermarking is audit-logged with the watermark, content, and timestamp
**Type:** Positive
**Covers:** 3.3 → Audit logging of the content watermarking; Rule: content watermarking is audit-logged with the watermark, content, and timestamp
**Preconditions:** Super Admin has applied a watermark.
**Steps:**
1. Open the audit trail and filter by "watermark".
2. Verify entries show the watermark, the content, and the timestamp.
**Expected Result:** The content watermarking is audit-logged with the watermark, content, and timestamp.
**Priority:** Critical

## 3.4 Screen Recording Detection

### TC-SA-22-03-025 — Detection: the detection (the detection, the user, the session, the date); the detection is the signal
**Type:** Positive
**Covers:** 3.4 → Detection: the detection (the detection, the user, the session, the date); Rule: the detection is the alert (the detection, the user, the session, the date); the detection is the signal
**Preconditions:** Super Admin is logged in; a user has screen-recorded protected content.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Screen Recording Detection.
2. Review the detection: the detection (the detection, the user, the session, the date) — verify the detection is the alert.
3. Verify the detection shows the user, the session, and the date.
4. Verify the detection triggers the documented response (alert to the user and/or Super Admin).
**Expected Result:** The detection is recorded — the detection, the user, the session, and the date are the signal.
**Priority:** Critical

### TC-SA-22-03-026 — User: the user (the user, the name, the detection); the user is the recorder
**Type:** Positive
**Covers:** 3.4 → User: the user (the user, the name, the detection); Rule: the user is the actor (the user, the name, the detection); the user is the recorder
**Preconditions:** Multiple users have screen-recording detections.
**Steps:**
1. Select the user: the user (the user, the name, the detection) — verify the user is the actor.
2. Verify the user shows the name and the detection.
3. Verify each detection is attributed to the correct user.
**Expected Result:** The user is selected — the user, the name, and the detection are the recorder.
**Priority:** High

### TC-SA-22-03-027 — Session: the session (the session, the user, the date); the session is the moment
**Type:** Positive
**Covers:** 3.4 → Session: the session (the session, the user, the date); Rule: the session is the context (the session, the user, the date); the session is the moment
**Preconditions:** Detections exist across multiple sessions.
**Steps:**
1. View the session: the session (the session, the user, the date) — verify the session is the context.
2. Verify the session shows the user and the date.
3. Verify the detection is tied to the exact session in which the recording occurred.
**Expected Result:** The session is shown — the session, the user, and the date are the moment.
**Priority:** High

### TC-SA-22-03-028 — Detection status: the status (the detected, the not-detected); the status is the control
**Type:** Edge
**Covers:** 3.4 → Detection status: the status (the detected, the not-detected); Rule: the detection status is the state (the detected, the not-detected); the status is the control
**Preconditions:** Detected and not-detected sessions exist; a session where the user disables the detection feature mid-session (evasion edge) is also prepared.
**Steps:**
1. View the detection status: the status (the detected, the not-detected) — verify the detection status is the state.
2. Verify a recording session shows detected.
3. Check the evasion session — verify the disabling event itself is flagged (a user cannot silently turn off detection); the session is marked detected or the disabling is recorded as a violation.
**Expected Result:** The detection status is shown — the detected and the not-detected are the control; detection cannot be silently disabled by the user.
**Priority:** High

### TC-SA-22-03-029 — Detection count: the count (the count of the detections); the count is the measure
**Type:** Positive
**Covers:** 3.4 → Detection count: the count (the count of the detections)
**Preconditions:** Multiple detections exist.
**Steps:**
1. View the detection count: the count (the count of the detections) — verify the count is the measure.
2. Verify the count matches the actual number of detections.
3. Trigger a new detection — verify the count increments.
**Expected Result:** The detection count is shown — the count of the detections is the measure.
**Priority:** High

### TC-SA-22-03-030 — Detection view: the view (the detections, the users, the sessions, the dates); the alert is managed
**Type:** Positive
**Covers:** 3.4 → Detection view: the view (the detections, the users, the sessions, the dates); Rule: the recording is detected (the detections, the users, the sessions, the dates); the alert is managed
**Preconditions:** Multiple detections exist.
**Steps:**
1. View the detections: the view (the detections, the users, the sessions, the dates) — verify the recording is detected.
2. Verify each detection shows the user, the session, and the date.
3. Verify the alert is managed (view, alert, escalate).
**Expected Result:** The detections are viewed — the detections, the users, the sessions, and the dates are visible; the alert is managed.
**Priority:** High

### TC-SA-22-03-031 — Detection export: the export (the detections, the format, the user); the export is the record
**Type:** Edge
**Covers:** 3.4 → Detection export: the export (the detections, the format, the user)
**Preconditions:** Detections exist for multiple users; a user with no detections (zero-row export edge) is also prepared.
**Steps:**
1. Export the detections: the export (the detections, the format, the user) — verify the export is the record.
2. Verify the export contains all detections for the selected user in the selected format.
3. Export the user with no detections — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The detections are exported — the detections, the format, and the user are the record; empty-user exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-03-032 — Screen recording detection is audit-logged with the detection, user, and timestamp
**Type:** Positive
**Covers:** 3.4 → Audit logging of the screen recording detection; Rule: screen recording detection is audit-logged with the detection, user, and timestamp
**Preconditions:** A screen recording detection has occurred.
**Steps:**
1. Open the audit trail and filter by "screen recording detection".
2. Verify entries show the detection, the user, and the timestamp.
**Expected Result:** The screen recording detection is audit-logged with the detection, user, and timestamp.
**Priority:** Critical

## 3.5 Geo-restrictions

### TC-SA-22-03-033 — Restriction: the restriction (the restriction, the content, the region, the date); the restriction is the boundary
**Type:** Positive
**Covers:** 3.5 → Restriction: the restriction (the restriction, the content, the region, the date); Rule: the restriction is the limit (the restriction, the content, the region, the date); the restriction is the boundary
**Preconditions:** Super Admin is logged in; platform content exists.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Geo-restrictions.
2. Apply the restriction: the restriction (the restriction, the content, the region, the date) — verify the restriction is the limit.
3. Verify the restriction shows the content, the region, and the date.
4. Access the restricted content from a restricted region — verify access is denied.
**Expected Result:** The restriction is applied — the restriction, the content, the region, and the date are the boundary.
**Priority:** Critical

### TC-SA-22-03-034 — Content: the content (the content, the type, the date); the content is the asset
**Type:** Positive
**Covers:** 3.5 → Content: the content (the content, the type, the date); Rule: the content is the subject (the content, the type, the date); the content is the asset
**Preconditions:** Multiple content types exist on the platform.
**Steps:**
1. Select the content: the content (the content, the type, the date) — verify the content is the subject.
2. Verify the content shows the type and the date.
3. Verify geo-restrictions can be applied to each content type.
**Expected Result:** The content is selected — the content, the type, and the date are the asset.
**Priority:** High

### TC-SA-22-03-035 — Region: the region (the region of the restriction, the country, the date); the region is the place
**Type:** Positive
**Covers:** 3.5 → Region: the region (the region of the restriction, the country, the date); Rule: the region is the location (the region of the restriction, the country, the date); the region is the place
**Preconditions:** Geo-restrictions exist for multiple regions.
**Steps:**
1. Set the region: the region (the region of the restriction, the country, the date) — verify the region is the location.
2. Verify the region shows the country and the date.
3. Verify restrictions can be filtered by region.
**Expected Result:** The region is set — the region of the restriction, the country, and the date are the place.
**Priority:** High

### TC-SA-22-03-036 — Restriction status: the status (the restricted, the unrestricted); the status is the control
**Type:** Edge
**Covers:** 3.5 → Restriction status: the status (the restricted, the unrestricted); Rule: the restriction status is the state (the restricted, the unrestricted); the status is the control
**Preconditions:** Restricted and unrestricted content exists; a user in a restricted region using a VPN to appear to be in an allowed region (VPN-bypass edge) is also prepared.
**Steps:**
1. View the restriction status: the status (the restricted, the unrestricted) — verify the restriction status is the state.
2. Verify restricted content shows restricted for the selected region.
3. Check the VPN user — verify the documented geo-check applies (the restriction is enforced per the documented geo-verification method); the bypass attempt is logged.
**Expected Result:** The restriction status is shown — the restricted and the unrestricted are the control; geo-restrictions are enforced per the documented method and bypass attempts are logged.
**Priority:** High

### TC-SA-22-03-037 — Restriction count: the count (the count of the restrictions); the count is the measure
**Type:** Positive
**Covers:** 3.5 → Restriction count: the count (the count of the restrictions)
**Preconditions:** Multiple restrictions exist.
**Steps:**
1. View the restriction count: the count (the count of the restrictions) — verify the count is the measure.
2. Verify the count matches the actual number of restrictions.
3. Apply a new restriction — verify the count increments.
**Expected Result:** The restriction count is shown — the count of the restrictions is the measure.
**Priority:** High

### TC-SA-22-03-038 — Restriction view: the view (the restrictions, the content, the regions, the dates); the limit is managed
**Type:** Positive
**Covers:** 3.5 → Restriction view: the view (the restrictions, the content, the regions, the dates); Rule: the content is restricted (the restrictions, the content, the regions, the dates); the limit is managed
**Preconditions:** Multiple restrictions exist.
**Steps:**
1. View the restrictions: the view (the restrictions, the content, the regions, the dates) — verify the content is restricted.
2. Verify each restriction shows the content, the region, and the date.
3. Verify the limit is managed (view, apply, lift).
**Expected Result:** The restrictions are viewed — the restrictions, the content, the regions, and the dates are visible; the limit is managed.
**Priority:** High

### TC-SA-22-03-039 — Restriction export: the export (the restrictions, the format, the region); the export is the record
**Type:** Edge
**Covers:** 3.5 → Restriction export: the export (the restrictions, the format, the region)
**Preconditions:** Restrictions exist for multiple regions; a region with no restrictions (zero-row export edge) is also prepared.
**Steps:**
1. Export the restrictions: the export (the restrictions, the format, the region) — verify the export is the record.
2. Verify the export contains all restrictions for the selected region in the selected format.
3. Export the empty region — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The restrictions are exported — the restrictions, the format, and the region are the record; empty-region exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-03-040 — Geo-restriction configuration is audit-logged with the restriction, region, and timestamp
**Type:** Positive
**Covers:** 3.5 → Audit logging of the geo-restriction configuration; Rule: geo-restriction configuration is audit-logged with the restriction, region, and timestamp
**Preconditions:** Super Admin has configured a geo-restriction.
**Steps:**
1. Open the audit trail and filter by "geo-restriction".
2. Verify entries show the restriction, the region, and the timestamp.
**Expected Result:** The geo-restriction configuration is audit-logged with the restriction, region, and timestamp.
**Priority:** Critical

## 3.6 Secure Video Streaming (DRM)

### TC-SA-22-03-041 — Streaming: the streaming (the streaming, the video, the user, the date); the streaming is the playback
**Type:** Positive
**Covers:** 3.6 → Streaming: the streaming (the streaming, the video, the user, the date); Rule: the streaming is the delivery (the streaming, the video, the user, the date); the streaming is the playback
**Preconditions:** Super Admin is logged in; DRM-protected videos exist.
**Steps:**
1. Open Data Protection & Compliance → Content Protection → Secure Video Streaming (DRM).
2. Stream the video securely: the streaming (the streaming, the video, the user, the date) — verify the streaming is the delivery.
3. Verify the streaming shows the video, the user, and the date.
4. Play the video — verify it streams through the DRM-protected pipeline (no raw file URL exposed).
**Expected Result:** The streaming is secure — the streaming, the video, the user, and the date are the playback.
**Priority:** Critical

### TC-SA-22-03-042 — Video: the video (the video, the title, the date); the video is the asset
**Type:** Positive
**Covers:** 3.6 → Video: the video (the video, the title, the date); Rule: the video is the content (the video, the title, the date); the video is the asset
**Preconditions:** Multiple DRM-protected videos exist.
**Steps:**
1. Select the video: the video (the video, the title, the date) — verify the video is the content.
2. Verify the video shows the title and the date.
3. Verify secure streaming can be applied per video.
**Expected Result:** The video is selected — the video, the title, and the date are the asset.
**Priority:** High

### TC-SA-22-03-043 — User: the user (the user, the name, the streaming); the user is the actor
**Type:** Positive
**Covers:** 3.6 → User: the user (the user, the name, the streaming); Rule: the user is the viewer (the user, the name, the streaming); the user is the actor
**Preconditions:** Multiple users have streamed DRM-protected videos.
**Steps:**
1. Select the user: the user (the user, the name, the streaming) — verify the user is the viewer.
2. Verify the user shows the name and the streaming.
3. Verify each streaming session is attributed to the correct licensed user.
**Expected Result:** The user is selected — the user, the name, and the streaming are the actor.
**Priority:** High

### TC-SA-22-03-044 — DRM: the DRM (the DRM of the streaming, the license, the date); the DRM is the shield
**Type:** Positive
**Covers:** 3.6 → DRM: the DRM (the DRM of the streaming, the license, the date)
**Preconditions:** DRM licenses are issued for streaming.
**Steps:**
1. View the DRM: the DRM (the DRM of the streaming, the license, the date) — verify the DRM is the shield.
2. Verify the DRM shows the license and the date.
3. Verify streaming is only possible with a valid DRM license.
**Expected Result:** The DRM is shown — the DRM of the streaming, the license, and the date are the shield.
**Priority:** High

### TC-SA-22-03-045 — Streaming status: the status (the secure, the insecure); the status is the control
**Type:** Edge
**Covers:** 3.6 → Streaming status: the status (the secure, the insecure); Rule: the streaming status is the state (the secure, the insecure); the status is the control
**Preconditions:** Secure streamings exist; a premium video whose DRM license has just expired (expired-license edge) is also prepared.
**Steps:**
1. View the streaming status: the status (the secure, the insecure) — verify the streaming status is the state.
2. Verify an active licensed stream shows secure.
3. Check the expired-license video — verify the stream is blocked (never served insecurely); the status shows the license lapse and the user is prompted to renew.
**Expected Result:** The streaming status is shown — the secure and the insecure are the control; expired licenses never result in insecure delivery of premium video.
**Priority:** High

### TC-SA-22-03-046 — Streaming count: the count (the count of the streamings); the count is the measure
**Type:** Positive
**Covers:** 3.6 → Streaming count: the count (the count of the streamings)
**Preconditions:** Multiple streamings exist.
**Steps:**
1. View the streaming count: the count (the count of the streamings) — verify the count is the measure.
2. Verify the count matches the actual number of streamings.
3. Start a new streaming — verify the count increments.
**Expected Result:** The streaming count is shown — the count of the streamings is the measure.
**Priority:** High

### TC-SA-22-03-047 — Streaming view: the view (the streamings, the videos, the users, the dates); the delivery is managed
**Type:** Positive
**Covers:** 3.6 → Streaming view: the view (the streamings, the videos, the users, the dates); Rule: the videos are streamed securely (the streamings, the videos, the users, the dates); the delivery is managed
**Preconditions:** Multiple streamings exist.
**Steps:**
1. View the streamings: the view (the streamings, the videos, the users, the dates) — verify the videos are streamed securely.
2. Verify each streaming shows the video, the user, and the date.
3. Verify the delivery is managed (view, monitor, revoke).
**Expected Result:** The streamings are viewed — the streamings, the videos, the users, and the dates are visible; the delivery is managed.
**Priority:** High

### TC-SA-22-03-048 — Secure video streaming is audit-logged with the streaming, video, and timestamp
**Type:** Positive
**Covers:** 3.6 → Audit logging of the secure video streaming; Rule: secure video streaming is audit-logged with the streaming, video, and timestamp
**Preconditions:** A secure video streaming has occurred.
**Steps:**
1. Open the audit trail and filter by "secure video streaming".
2. Verify entries show the streaming, the video, and the timestamp.
**Expected Result:** The secure video streaming is audit-logged with the streaming, video, and timestamp.
**Priority:** Critical
