# 1. Download Permissions

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Download Permissions

### 1.1 Content Download Enablement
**What it does:** The Super Admin controls which content types can be downloaded for offline use, so offline availability is governed per content type.

**Sub-features:**
- Download enablement per content type: videos, notes, resources, and worksheets toggled downloadable or not
- Download enablement per course: individual courses toggled downloadable or not
- Download enablement per institute: institute-level override for download availability
- DRM protection: digital rights management applied to downloaded content
- Watermarking: user-specific watermark applied to downloaded content
- Available on web
- Event logging (action performed)
- Audit logging of content download enablement

**Super Admin User Journey:**
1. As a Super Admin, open the download permissions configuration.
2. Toggle download enablement per content type (videos, notes, resources, worksheets).
3. Set course-level and institute-level overrides where needed.
4. Configure DRM protection and watermarking for downloaded content.
5. Save and verify a learner can download only the enabled content types.

**Rules & Edge Cases:**
- A content type disabled for download shows no download option to learners.
- A course-level override takes precedence over the content-type default.
- An institute-level override takes precedence over the course-level setting.
- DRM-protected content cannot be copied, screen-recorded, or redistributed.
- A watermark carries the learner's identifier and is visible on the downloaded content.
- A content item with no download permission is not listed in the downloadable catalog.
- Enablement changes apply to new downloads; already-downloaded content is not revoked unless explicitly purged.
- Configuration changes are audit-logged with the actor and timestamp.

### 1.2 Download Size and Format Limits
**What it does:** The Super Admin sets the size and format limits for downloadable content so downloads remain manageable and consistent.

**Sub-features:**
- Maximum file size: the maximum size per downloadable file
- Total download quota: the total offline storage quota per learner
- Allowed formats: the file formats permitted for download (MP4, PDF, etc.)
- Video quality for download: the video quality tiers available for offline download
- Format conversion: automatic conversion of source content to allowed download formats
- Available on web
- Event logging (action performed)
- Audit logging of download size and format limits

**Super Admin User Journey:**
1. As a Super Admin, open the download size and format limits.
2. Set the maximum file size and total download quota per learner.
3. Define the allowed formats and the video quality tiers for download.
4. Enable or disable automatic format conversion.
5. Save and verify a download exceeding the limit is blocked.

**Rules & Edge Cases:**
- A file exceeding the maximum size is not downloadable; the learner is shown the limit.
- A learner reaching the total download quota cannot download more until space is freed.
- A file in a disallowed format is not offered for download.
- A video quality tier above the configured maximum is not offered for download.
- Format conversion produces a file within the allowed formats; a conversion failure blocks the download.
- The quota is per learner, not per device.
- Limit changes apply to new downloads; existing downloads are not re-evaluated.
- Configuration changes are audit-logged with the actor and timestamp.

### 1.3 Download Expiry and Device Limits
**What it does:** The Super Admin controls how long downloaded content remains valid and on how many devices a learner can hold offline content.

**Sub-features:**
- Download expiry: the duration downloaded content remains valid
- Expiry enforcement: downloaded content expired and removed after the duration
- Device limit: the maximum number of devices per learner for offline content
- Device management: the learner's active download devices listed and removable
- Expiry reminder: a reminder before downloaded content expires
- Available on web
- Event logging (action performed)
- Audit logging of download expiry and device limits

**Super Admin User Journey:**
1. As a Super Admin, open the download expiry and device limits.
2. Set the download expiry duration and the device limit per learner.
3. Enable the expiry reminder.
4. Save and verify expired content is removed and a device over the limit is blocked.

**Rules & Edge Cases:**
- Expired downloaded content is no longer playable or viewable; it is removed from the device.
- A learner at the device limit must remove a device before downloading to a new one.
- An expiry reminder is sent before the expiry window ends; no reminder after expiry.
- A device removed by the learner frees a device slot immediately.
- A learner whose subscription lapses has downloaded content expired at the next sync.
- The expiry duration is per content item download, not per learner globally.
- Limit and expiry changes are audit-logged with the actor and timestamp.

### 1.4 Downloadable Content Catalog
**What it does:** The Super Admin manages the catalog of content available for download so learners see a clear, governed list of offline-eligible items.

**Sub-features:**
- Catalog listing: the downloadable content items listed per course
- Catalog filtering: the catalog filtered by content type, course, and availability
- Catalog status: the download state per item (available, downloading, downloaded, expired)
- Catalog search: the catalog searched by title and course
- Catalog refresh: the catalog refreshed to reflect permission and availability changes
- Available on web
- Event logging (action performed)
- Audit logging of downloadable content catalog management

**Super Admin User Journey:**
1. As a Super Admin, open the downloadable content catalog.
2. Review the catalog listing per course.
3. Filter and search the catalog by content type, course, and availability.
4. Check the download status per item.
5. Refresh the catalog and verify it reflects the current permissions.

**Rules & Edge Cases:**
- A catalog item not permitted for download is not listed.
- A catalog item whose course is unavailable to a learner is not listed for that learner.
- The catalog status reflects the learner's device state, not a global state.
- A catalog refresh picks up permission changes; a stale catalog is not trusted.
- A search with no matches shows an empty result, not an error.
- The catalog is scoped to the learner's enrolled courses.
- Catalog management actions are audit-logged with the actor and timestamp.

### 1.5 Download Permission by Subscription Tier
**What it does:** The Super Admin maps download permissions to subscription tiers so offline availability aligns with the plan a learner holds.

**Sub-features:**
- Tier mapping: download permissions mapped per subscription tier
- Tier quota: the download quota per subscription tier
- Tier content scope: the content types downloadable per tier
- Tier device limit: the device limit per subscription tier
- Tier upgrade effect: the permission change on tier upgrade or downgrade
- Available on web
- Event logging (action performed)
- Audit logging of download permission by subscription tier

**Super Admin User Journey:**
1. As a Super Admin, open the download permission by subscription tier.
2. Map download permissions, quota, content scope, and device limit per tier.
3. Define the tier upgrade and downgrade effect.
4. Save and verify a learner's download permissions match their tier.

**Rules & Edge Cases:**
- A learner's download permissions are derived from their active tier.
- A tier with no download permission shows no download option to its learners.
- A tier upgrade expands permissions immediately; a downgrade restricts at the next sync.
- A tier quota is a ceiling; a learner cannot exceed their tier's quota.
- A tier content scope limits which types are downloadable for that tier.
- A learner with a lapsed tier loses download permissions at the next sync.
- Tier mapping changes are audit-logged with the actor and timestamp.
