# Institute Sub-Admin Roles — Role Definition

User Type: **Super Administrator** (role definition) / **Institute Sub-Admin** (role holder)
Source: *Mi Digital Academy - Education CRM Features Document*

---

## Institute Sub-Admin Roles

### Overview
A Training Institute account operates through a primary **Institute Admin** account plus a set of sub-admin roles. From the Super Administrator's perspective, these are four role definitions scoped to a single institute: **Institute Admin (Primary)**, **Institute Academic Coordinator**, **Institute Billing Manager**, and **Institute Student Support**. Each role is a slice of the institute's operations, designed around separation of duties: no single sub-admin role combines billing with student management, or analytics with license purchasing.

The Institute Admin is the primary account holder with full institute portal access and the only role that can manage other institute sub-admins. The three supporting roles — Academic Coordinator, Billing Manager, and Student Support — each own one operational domain (academics, finance, and student-facing support respectively) and are explicitly barred from the others' domains.

### Assignment & Onboarding
- Sub-admin accounts are created by the **Institute Admin** within the institute portal (create, edit, deactivate, reassign roles).
- The **Super Administrator** can also assign sub-admin roles during institute onboarding (e.g., seeding the initial Billing Manager before the Institute Admin is fully active).
- Onboarding path: the institute registers → the Institute Admin account is activated → the Institute Admin invites sub-admins by email with a role → sub-admins verify and set passwords.
- Who can assign these roles: the Institute Admin (for sub-admin roles within their institute) and the Super Administrator (during onboarding or for governance interventions).
- Role changes are audit-logged (actor, timestamp, before/after role). Deactivating a sub-admin immediately revokes access; history is retained.

### Access & Permissions (Full Permission Matrix)
| Capability | Institute Admin | Academic Coordinator | Billing Manager | Student Support |
|-----------|:---:|:---:|:---:|:---:|
| Institute dashboard (full) | Full | Read-only (academic) | Read-only (billing) | Read-only (support) |
| Sub-admin management | Full | None | None | None |
| Bulk license purchase | Full | None | Full | None |
| Seat allocation / transfer | Full | None | None | None |
| License usage view | Full | None | Read-only | None |
| Student bulk registration | Full | None | None | Process requests |
| Course assignment to groups | Full | Full | None | Resolve access issues |
| Custom learning paths | Full | Full | None | None |
| Batch assessments & custom assessments | Full | Full | None | None |
| Batch-wide announcements | Full | Full | None | None |
| Student performance analytics | Full | Read-only | None | Read-only (individual) |
| Batch reports | Full | Full | None | None |
| Billing history & invoices | Full | None | Full | None |
| Discount eligibility & renewals/upgrades | Full | None | Full | None |
| License expiry alerts | Recipient | None | Recipient | None |
| Student queries & technical issues | Escalation target | None | None | Full |
| Account-related requests | Full | None | None | Full |
| Course/account access issues | Full | None | None | Full |
| Engagement monitoring & alerts | Full | None | None | Full |
| Student progress reports | Full | None | None | Full (individual) |
| Advanced analytics (cohort, predictive, ROI) | Full | None | None | None |
| Integration management (LMS, SIS) | Full | None | None | None |
| Custom learning paths & curriculum (institute) | Full | Contribute | None | None |
| White-label / branding configuration | Full | None | None | None |
| Full reporting & data export | Full | Batch reports only | Billing export only | Individual reports only |
| Platform-level course creation | None | None | None | None |
| System settings / user management (platform) | None | None | None | None |

### Panels & Views
- **Institute Admin:** full institute portal — Dashboard, Sub-Admins, Bulk License Management, Student Management, Billing & Licensing, Advanced Analytics, Integrations, Branding, Reporting.
- **Academic Coordinator:** Student Management (course assignment, learning paths), Assessments, Analytics (read-only), Batch Reports, Announcements.
- **Billing Manager:** License Usage, Purchase, Billing History & Invoices, Renewals & Upgrades, Expiry Alerts.
- **Student Support:** Query Inbox, Account Requests, Engagement Monitoring, Student Progress Reports.
- All four roles see a Profile → "Activity" view of their own event log.
- Key metrics per role: Admin — seat utilization, cohort performance, ROI; Coordinator — completion rates, at-risk students; Billing Manager — seats available, days-to-expiry, spend; Support — open tickets, response time, inactive students.

### Restrictions
- **Data scoping:** every sub-admin's data scope is limited to their own institute; cross-institute access is denied at the API layer.
- **Institute Admin** cannot be delegated or duplicated; it is the single primary role per institute.
- **Academic Coordinator:** no billing, license purchase, integrations, branding, or sub-admin management.
- **Billing Manager:** no student management, analytics, content, or integrations.
- **Student Support:** no billing, license management, analytics administration, content creation, or integrations.
- All restrictions are enforced at the API layer, not only the UI; denied attempts are event-logged and audit-logged.
- Sub-admins cannot change their own role or permissions.

### User Journey
1. The Super Administrator onboards the institute and activates the Institute Admin account (or the institute self-registers and the Admin is activated on verification).
2. The Institute Admin logs in, completes institute profile setup, and invites an Academic Coordinator, a Billing Manager, and a Student Support agent with the appropriate roles.
3. Each sub-admin verifies their email, sets a password, and logs in to a dashboard scoped to their role.
4. The Billing Manager purchases additional licenses; the Academic Coordinator assigns courses to the new cohort; the Student Support agent activates the registered students.
5. The Institute Admin reviews the sub-admin list, utilization, and audit trail to confirm everything is operating as intended.
6. When a staff member leaves, the Institute Admin deactivates their account; access is revoked immediately and the audit trail is retained.

### Rules & Edge Cases
- An institute can have multiple sub-admins per role (e.g., two Billing Managers).
- Deactivation is immediate; the sub-admin's past actions remain in the audit trail with the sub-admin identified as the actor.
- The Institute Admin role cannot be assigned to a sub-admin through the sub-admin management flow.
- When an institute's subscription lapses, all its sub-admins lose access; reactivation restores role-scoped access.
- Super Administrator governance: the Super Admin can view any institute's sub-admin list and audit trail, and can intervene (reassign/deactivate) where required; all interventions are audit-logged.
- Role definitions for the four roles are editable by the Super Administrator (permission sets), following the standard role-edit preview-and-propagate flow; the role identities themselves are predefined and not deletable.
