# Institute Sub-Admin Roles — Role Definition — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: institute_sub_admin_roles.md — every role, permission-matrix cell, onboarding path, restriction, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1. Onboarding & Assignment | Institute onboarding activates Institute Admin | TC-SA-INST-01-001 |
| 1. Onboarding & Assignment | Institute Admin invites sub-admins with roles | TC-SA-INST-01-002 |
| 1. Onboarding & Assignment | Sub-admin email verification and activation | TC-SA-INST-01-003 |
| 1. Onboarding & Assignment | Super Admin assigns sub-admin roles during onboarding | TC-SA-INST-01-004 |
| 1. Onboarding & Assignment | Role changes audit-logged (actor, timestamp, before/after) | TC-SA-INST-01-005 |
| 1. Onboarding & Assignment | Rule: deactivation immediate; history retained | TC-SA-INST-01-006 |
| 1. Onboarding & Assignment | Rule: multiple sub-admins per role allowed | TC-SA-INST-01-007 |
| 1. Onboarding & Assignment | Rule: Institute Admin role not assignable via sub-admin flow | TC-SA-INST-01-008 |
| 2. Permission Matrix — Institute Admin | Full institute portal access | TC-SA-INST-02-001 |
| 2. Permission Matrix — Institute Admin | Sub-admin management (create, edit, deactivate, reassign) | TC-SA-INST-02-002 |
| 2. Permission Matrix — Institute Admin | Bulk license purchase, allocation, transfer | TC-SA-INST-02-003 |
| 2. Permission Matrix — Institute Admin | Advanced analytics (cohort, predictive, ROI) | TC-SA-INST-02-004 |
| 2. Permission Matrix — Institute Admin | Integration management (LMS, SIS) | TC-SA-INST-02-005 |
| 2. Permission Matrix — Institute Admin | White-label/branding configuration | TC-SA-INST-02-006 |
| 2. Permission Matrix — Institute Admin | Full reporting and data export | TC-SA-INST-02-007 |
| 2. Permission Matrix — Academic Coordinator | Course assignment, learning paths, batch assessments | TC-SA-INST-02-008 |
| 2. Permission Matrix — Academic Coordinator | Read-only student performance analytics | TC-SA-INST-02-009 |
| 2. Permission Matrix — Academic Coordinator | Batch reports and batch-wide announcements | TC-SA-INST-02-010 |
| 2. Permission Matrix — Academic Coordinator | No billing, license purchase, integrations, branding | TC-SA-INST-02-011 |
| 2. Permission Matrix — Billing Manager | License usage view (read-only) | TC-SA-INST-02-012 |
| 2. Permission Matrix — Billing Manager | License purchase, invoices, renewals/upgrades | TC-SA-INST-02-013 |
| 2. Permission Matrix — Billing Manager | No student management, analytics, content, integrations | TC-SA-INST-02-014 |
| 2. Permission Matrix — Student Support | Queries, account requests, access issues | TC-SA-INST-02-015 |
| 2. Permission Matrix — Student Support | Engagement monitoring, alerts, individual progress reports | TC-SA-INST-02-016 |
| 2. Permission Matrix — Student Support | No billing, license mgmt, analytics admin, content creation | TC-SA-INST-02-017 |
| 2. Permission Matrix — Cross-Role | Separation of duties: no role combines billing + student mgmt | TC-SA-INST-02-018 |
| 2. Permission Matrix — Cross-Role | Expiry/utilization alerts reach correct roles | TC-SA-INST-02-019 |
| 3. Data Scoping & Enforcement | Sub-admin data scoped to own institute | TC-SA-INST-03-001 |
| 3. Data Scoping & Enforcement | Cross-institute API calls denied | TC-SA-INST-03-002 |
| 3. Data Scoping & Enforcement | Restrictions enforced at API layer (not only UI) | TC-SA-INST-03-003 |
| 3. Data Scoping & Enforcement | Denied attempts event-logged and audit-logged | TC-SA-INST-03-004 |
| 3. Data Scoping & Enforcement | Rule: sub-admins cannot change own role/permissions | TC-SA-INST-03-005 |
| 4. Lifecycle & Governance | Institute subscription lapse deactivates all sub-admins | TC-SA-INST-04-001 |
| 4. Lifecycle & Governance | Reactivation restores role-scoped access | TC-SA-INST-04-002 |
| 4. Lifecycle & Governance | Super Admin views any institute's sub-admin list and audit trail | TC-SA-INST-04-003 |
| 4. Lifecycle & Governance | Super Admin intervention (reassign/deactivate) audit-logged | TC-SA-INST-04-004 |
| 4. Lifecycle & Governance | Role permission sets editable via preview-and-propagate | TC-SA-INST-04-005 |
| 4. Lifecycle & Governance | Rule: role identities predefined and not deletable | TC-SA-INST-04-006 |

## 1. Onboarding & Assignment

### TC-SA-INST-01-001 — Institute onboarding activates the Institute Admin
**Type:** Positive
**Covers:** 1 → Institute onboarding activates Institute Admin
**Preconditions:** A new institute registration submitted.
**Steps:**
1. Complete institute registration and verification.
2. Log in with the Institute Admin credentials.
**Expected Result:** The Institute Admin account is active with full institute portal access.
**Priority:** Critical

### TC-SA-INST-01-002 — Institute Admin invites sub-admins with roles
**Type:** Positive
**Covers:** 1 → Institute Admin invites sub-admins with roles
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Invite an Academic Coordinator, a Billing Manager, and a Student Support agent by email with their roles.
**Expected Result:** Invitation emails are sent; the sub-admins appear in the list with status "Invited".
**Priority:** Critical

### TC-SA-INST-01-003 — Sub-admin email verification and activation
**Type:** Positive
**Covers:** 1 → Sub-admin email verification and activation
**Preconditions:** A sub-admin invitation sent.
**Steps:**
1. Open the invitation link, verify the email, and set a password.
2. Log in as the sub-admin.
**Expected Result:** The account becomes active; login succeeds; the dashboard is scoped to the assigned role.
**Priority:** Critical

### TC-SA-INST-01-004 — Super Admin assigns sub-admin roles during onboarding
**Type:** Positive
**Covers:** 1 → Super Admin assigns sub-admin roles during onboarding
**Preconditions:** Super Admin logged in; an institute being onboarded.
**Steps:**
1. Super Admin assigns the Billing Manager role to a user for the institute.
**Expected Result:** The user holds the role scoped to that institute; the assignment is visible in the institute's sub-admin list.
**Priority:** High

### TC-SA-INST-01-005 — Role changes are audit-logged
**Type:** Positive
**Covers:** 1 → Role changes audit-logged (actor, timestamp, before/after)
**Preconditions:** A sub-admin role reassignment performed.
**Steps:**
1. Review the audit trail for the reassignment.
**Expected Result:** The entry shows the actor, timestamp, user, and before/after roles.
**Priority:** High

### TC-SA-INST-01-006 — Deactivation is immediate with history retained
**Type:** Positive
**Covers:** 1 → Rule: deactivation immediate; history retained
**Preconditions:** An active sub-admin with prior actions and an open session.
**Steps:**
1. Deactivate the sub-admin.
2. Attempt a request with the sub-admin's session; review the audit trail.
**Expected Result:** The next request is denied immediately; prior actions remain in the audit trail.
**Priority:** Critical

### TC-SA-INST-01-007 — Multiple sub-admins per role
**Type:** Positive
**Covers:** 1 → Rule: multiple sub-admins per role allowed
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Create two sub-admins with the role "Billing Manager".
**Expected Result:** Both are created; the sub-admin list shows two holders of the role.
**Priority:** Medium

### TC-SA-INST-01-008 — Institute Admin role not assignable via sub-admin flow
**Type:** Negative
**Covers:** 1 → Rule: Institute Admin role not assignable via sub-admin flow
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Attempt to create a sub-admin with the role "Institute Admin".
**Expected Result:** The role is not offered in the picker; the action is rejected.
**Priority:** Critical

## 2. Permission Matrix

### TC-SA-INST-02-001 — Institute Admin has full institute portal access
**Type:** Positive
**Covers:** 2 → Institute Admin: full institute portal access
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Navigate every institute module: Dashboard, Sub-Admins, Bulk License Management, Student Management, Billing & Licensing, Advanced Analytics, Integrations, Branding, Reporting.
**Expected Result:** All modules are accessible and functional.
**Priority:** Critical

### TC-SA-INST-02-002 — Institute Admin manages sub-admins
**Type:** Positive
**Covers:** 2 → Institute Admin: sub-admin management
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Create, edit, reassign, and deactivate sub-admins.
**Expected Result:** All four operations succeed; the list reflects the changes.
**Priority:** Critical

### TC-SA-INST-02-003 — Institute Admin full license control
**Type:** Positive
**Covers:** 2 → Institute Admin: bulk license purchase, allocation, transfer
**Preconditions:** Institute Admin logged in; billing profile approved.
**Steps:**
1. Purchase a license package, allocate seats to a group, and transfer a license between students.
**Expected Result:** All three operations succeed; utilization updates accordingly.
**Priority:** Critical

### TC-SA-INST-02-004 — Institute Admin advanced analytics
**Type:** Positive
**Covers:** 2 → Institute Admin: advanced analytics (cohort, predictive, ROI)
**Preconditions:** Institute Admin logged in; institute data exists.
**Steps:**
1. Open cohort analysis, predictive insights, and ROI measurement.
**Expected Result:** All three analytics views render with accurate institute data.
**Priority:** High

### TC-SA-INST-02-005 — Institute Admin integration management
**Type:** Positive
**Covers:** 2 → Institute Admin: integration management (LMS, SIS)
**Preconditions:** Institute Admin logged in; LMS/SIS credentials available.
**Steps:**
1. Connect the LMS and SIS and run test syncs.
**Expected Result:** Both integrations connect; test syncs succeed and are logged.
**Priority:** High

### TC-SA-INST-02-006 — Institute Admin branding configuration
**Type:** Positive
**Covers:** 2 → Institute Admin: white-label/branding configuration
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Upload a logo, set colors, rename the portal, preview, and publish.
**Expected Result:** The branding is published institute-wide; the preview matched the result.
**Priority:** High

### TC-SA-INST-02-007 — Institute Admin full reporting and export
**Type:** Positive
**Covers:** 2 → Institute Admin: full reporting and data export
**Preconditions:** Institute Admin logged in.
**Steps:**
1. Generate reports across students, performance, licensing, and billing; export as CSV and PDF.
**Expected Result:** All reports generate with institute-scoped data; exports complete correctly.
**Priority:** High

### TC-SA-INST-02-008 — Academic Coordinator academic operations
**Type:** Positive
**Covers:** 2 → Academic Coordinator: course assignment, learning paths, batch assessments
**Preconditions:** Academic Coordinator logged in.
**Steps:**
1. Assign courses to a group, create a learning path, and schedule a batch assessment.
**Expected Result:** All three operations succeed within the coordinator's institute.
**Priority:** Critical

### TC-SA-INST-02-009 — Academic Coordinator read-only analytics
**Type:** Positive
**Covers:** 2 → Academic Coordinator: read-only student performance analytics
**Preconditions:** Academic Coordinator logged in; performance data exists.
**Steps:**
1. Open student performance analytics and attempt to modify a value.
**Expected Result:** Analytics render read-only; modification is rejected.
**Priority:** High

### TC-SA-INST-02-010 — Academic Coordinator reports and announcements
**Type:** Positive
**Covers:** 2 → Academic Coordinator: batch reports and batch-wide announcements
**Preconditions:** Academic Coordinator logged in.
**Steps:**
1. Generate a batch report and send a batch-wide announcement.
**Expected Result:** The report generates with batch data; the announcement is delivered to the batch.
**Priority:** High

### TC-SA-INST-02-011 — Academic Coordinator barred from finance and admin domains
**Type:** Negative
**Covers:** 2 → Academic Coordinator: no billing, license purchase, integrations, branding
**Preconditions:** Academic Coordinator logged in.
**Steps:**
1. Attempt to open Billing & Licensing, Bulk License Management, Integrations, and Branding (UI and direct endpoint calls).
**Expected Result:** All are denied; the screens are absent from navigation.
**Priority:** Critical

### TC-SA-INST-02-012 — Billing Manager read-only license usage
**Type:** Positive
**Covers:** 2 → Billing Manager: license usage view (read-only)
**Preconditions:** Billing Manager logged in.
**Steps:**
1. Open License Usage and attempt to allocate a seat.
**Expected Result:** Usage renders read-only; allocation is rejected.
**Priority:** High

### TC-SA-INST-02-013 — Billing Manager purchase and billing operations
**Type:** Positive
**Covers:** 2 → Billing Manager: license purchase, invoices, renewals/upgrades
**Preconditions:** Billing Manager logged in; billing profile approved.
**Steps:**
1. Purchase licenses, open an invoice, and renew a package.
**Expected Result:** All three operations succeed; entitlements and invoices update.
**Priority:** Critical

### TC-SA-INST-02-014 — Billing Manager barred from academic and admin domains
**Type:** Negative
**Covers:** 2 → Billing Manager: no student management, analytics, content, integrations
**Preconditions:** Billing Manager logged in.
**Steps:**
1. Attempt to open Student Management, Analytics, content screens, and Integrations (UI and direct endpoint calls).
**Expected Result:** All are denied; the screens are absent from navigation.
**Priority:** Critical

### TC-SA-INST-02-015 — Student Support query and account operations
**Type:** Positive
**Covers:** 2 → Student Support: queries, account requests, access issues
**Preconditions:** Student Support agent logged in; open tickets and requests exist.
**Steps:**
1. Resolve a query, process a registration request, and fix a course access issue.
**Expected Result:** All three operations succeed; statuses update.
**Priority:** Critical

### TC-SA-INST-02-016 — Student Support engagement and reports
**Type:** Positive
**Covers:** 2 → Student Support: engagement monitoring, alerts, individual progress reports
**Preconditions:** Student Support agent logged in.
**Steps:**
1. Review the inactive student list, send an alert, and generate an individual progress report.
**Expected Result:** All three operations succeed; the alert is delivered and the report is generated.
**Priority:** High

### TC-SA-INST-02-017 — Student Support barred from finance and content domains
**Type:** Negative
**Covers:** 2 → Student Support: no billing, license mgmt, analytics admin, content creation
**Preconditions:** Student Support agent logged in.
**Steps:**
1. Attempt to open Billing & Licensing, Bulk License Management, Advanced Analytics administration, and content creation (UI and direct endpoint calls).
**Expected Result:** All are denied; the screens are absent from navigation.
**Priority:** Critical

### TC-SA-INST-02-018 — Separation of duties holds across roles
**Type:** Negative
**Covers:** 2 → Separation of duties: no role combines billing + student mgmt
**Preconditions:** All four role types logged in (separate sessions).
**Steps:**
1. For each role, enumerate accessible modules and check for any role holding both billing purchase and student management.
**Expected Result:** No single role holds both; the matrix matches the documented permission matrix exactly.
**Priority:** Critical

### TC-SA-INST-02-019 — Alerts reach the correct roles
**Type:** Positive
**Covers:** 2 → Expiry/utilization alerts reach correct roles
**Preconditions:** A package approaching expiry and 80% utilization.
**Steps:**
1. Trigger the utilization and expiry alerts.
2. Check notifications for all four roles.
**Expected Result:** Utilization alerts reach Institute Admin and Billing Manager; expiry alerts reach Institute Admin and Billing Manager; Coordinator and Support receive neither.
**Priority:** High

## 3. Data Scoping & Enforcement

### TC-SA-INST-03-001 — Sub-admin data scoped to own institute
**Type:** Positive
**Covers:** 3 → Sub-admin data scoped to own institute
**Preconditions:** A sub-admin logged in; multiple institutes exist.
**Steps:**
1. Review the sub-admin's student, billing, and report data.
**Expected Result:** Only the sub-admin's own institute data is visible.
**Priority:** Critical

### TC-SA-INST-03-002 — Cross-institute API calls denied
**Type:** Negative
**Covers:** 3 → Cross-institute API calls denied
**Preconditions:** A sub-admin's session token; another institute's data exists.
**Steps:**
1. Call student-list and billing endpoints with another institute's ID.
**Expected Result:** Both calls are denied (403) or return empty; no cross-institute data is exposed.
**Priority:** Critical

### TC-SA-INST-03-003 — Restrictions enforced at API layer
**Type:** Negative
**Covers:** 3 → Restrictions enforced at API layer (not only UI)
**Preconditions:** A sub-admin's session token for a restricted domain.
**Steps:**
1. Call an endpoint in a domain the role cannot access, bypassing the UI.
**Expected Result:** The API returns a denial (403); no data or mutation occurs.
**Priority:** Critical

### TC-SA-INST-03-004 — Denied attempts are event-logged and audit-logged
**Type:** Positive
**Covers:** 3 → Denied attempts event-logged and audit-logged
**Preconditions:** Denied access attempts made by a sub-admin.
**Steps:**
1. Open the sub-admin's Profile → "Activity" and the institute audit log.
**Expected Result:** Each denied attempt appears in both with the account, target, and timestamp.
**Priority:** High

### TC-SA-INST-03-005 — Sub-admins cannot change own role or permissions
**Type:** Negative
**Covers:** 3 → Rule: sub-admins cannot change own role/permissions
**Preconditions:** A sub-admin logged in.
**Steps:**
1. Attempt to change own role or permissions via UI and direct endpoint calls.
**Expected Result:** All attempts are denied; only the Institute Admin or Super Administrator can change the role.
**Priority:** Critical

## 4. Lifecycle & Governance

### TC-SA-INST-04-001 — Subscription lapse deactivates all sub-admins
**Type:** Positive
**Covers:** 4 → Institute subscription lapse deactivates all sub-admins
**Preconditions:** An institute with active sub-admins; subscription lapses.
**Steps:**
1. Let the institute subscription lapse (or simulate it).
2. Attempt to log in as each sub-admin.
**Expected Result:** All sub-admin logins are denied; access is suspended institute-wide.
**Priority:** Critical

### TC-SA-INST-04-002 — Reactivation restores role-scoped access
**Type:** Positive
**Covers:** 4 → Reactivation restores role-scoped access
**Preconditions:** A lapsed institute reactivated.
**Steps:**
1. Reactivate the institute.
2. Log in as each sub-admin.
**Expected Result:** Each sub-admin regains exactly their role-scoped access; no roles changed during the lapse.
**Priority:** High

### TC-SA-INST-04-003 — Super Admin views any institute's sub-admin list and audit trail
**Type:** Positive
**Covers:** 4 → Super Admin views any institute's sub-admin list and audit trail
**Preconditions:** Super Admin logged in; multiple institutes exist.
**Steps:**
1. Open an institute's sub-admin list and audit trail from the Super Admin console.
**Expected Result:** The list and audit trail are visible and accurate.
**Priority:** High

### TC-SA-INST-04-004 — Super Admin intervention is audit-logged
**Type:** Positive
**Covers:** 4 → Super Admin intervention (reassign/deactivate) audit-logged
**Preconditions:** Super Admin logged in.
**Steps:**
1. Super Admin reassigns a sub-admin's role and deactivates another.
2. Review the audit trail.
**Expected Result:** Both interventions are audit-logged with the Super Admin as actor, timestamp, and before/after state.
**Priority:** High

### TC-SA-INST-04-005 — Role permission sets editable via preview-and-propagate
**Type:** Positive
**Covers:** 4 → Role permission sets editable via preview-and-propagate
**Preconditions:** Super Admin logged in; holders exist for an institute sub-admin role.
**Steps:**
1. Edit the role's permission set and review the change preview (affected holder count).
2. Save and verify a holder's access on their next request.
**Expected Result:** The preview shows the holder count; the change propagates without re-login; the edit is audit-logged.
**Priority:** High

### TC-SA-INST-04-006 — Role identities are predefined and not deletable
**Type:** Negative
**Covers:** 4 → Rule: role identities predefined and not deletable
**Preconditions:** Super Admin logged in.
**Steps:**
1. Attempt to delete the Institute Admin, Academic Coordinator, Billing Manager, and Student Support role definitions.
**Expected Result:** Deletion is unavailable for all four; only permission-set edits are allowed.
**Priority:** Critical
