# 1. Institute Login & Access

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Institute Login & Access

### 1.1 Institute Portal Login
**What it does:** Lets the Training Institute sign in to the institute portal with the institute's registered email and password. The Institute sees the login screen, enters the credentials, and is taken to the institute dashboard on success. Failed attempts are limited and the Institute is informed of the reason. This is the primary entry point to the institute portal.

**Sub-features:**
- Institute portal login screen
- Sign in with registered email and password
- Redirect to the institute dashboard on success
- Failed attempts limited with lockout
- Reason shown on failed sign-in
- Login available on web and mobile
- Login event logging (success, failure)
- Audit logging of the institute portal login

**Training Institute User Journey:**
1. Training Institute opens the institute portal login screen.
2. Training Institute enters the registered email and password.
3. Training Institute is redirected to the institute dashboard on success.
4. The failed attempts are limited with lockout.
5. The reason is shown on a failed sign-in.
6. Training Institute opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- The failed attempts are limited with lockout.
- The reason is shown on a failed sign-in.
- Login events (success, failure) are logged with the account and the timestamp.
- The institute portal login is audit-logged with the account and the timestamp.

### 1.2 Single Sign-On (SSO) Login
**What it does:** Lets the Training Institute sign in using the organization's single sign-on provider. The Institute clicks the SSO option, is redirected to the provider, and is signed in automatically on success. This lets the Institute use the organization's existing identity.

**Sub-features:**
- SSO login option on the login screen
- Redirect to the organization's SSO provider
- Automatic sign-in on success
- SSO session mapped to the institute account
- SSO available on web and mobile
- SSO event logging (initiated, success)
- Audit logging of the single sign-on login

**Training Institute User Journey:**
1. Training Institute opens the login screen.
2. Training Institute clicks the SSO login option.
3. Training Institute is redirected to the organization's SSO provider.
4. Training Institute is signed in automatically on success.
5. The SSO session is mapped to the institute account.
6. Training Institute opens Profile → "Activity" and confirms the SSO events are recorded.

**Rules & Edge Cases:**
- The SSO session is mapped to the institute account.
- The SSO sign-in is automatic on success.
- SSO events (initiated, success) are logged with the account and the timestamp.
- The single sign-on login is audit-logged with the account and the timestamp.

### 1.3 Two-Factor Authentication (2FA)
**What it does:** Adds a second factor to the Training Institute's sign-in: a one-time code sent to the registered device or email. The Institute enters the code after the password to complete the sign-in. The 2FA can be enabled, disabled, and the device re-registered. This protects the institute account, which controls many student licenses.

**Sub-features:**
- Enable two-factor authentication
- One-time code after the password
- Code sent to the registered device or email
- Disable two-factor authentication
- Re-register the 2FA device
- 2FA available on web and mobile
- 2FA event logging (enabled, code verified)
- Audit logging of the two-factor authentication

**Training Institute User Journey:**
1. Training Institute opens the security settings.
2. Training Institute enables two-factor authentication.
3. Training Institute signs in and enters the one-time code after the password.
4. The code is sent to the registered device or email.
5. Training Institute can disable two-factor authentication.
6. Training Institute re-registers the 2FA device.
7. Training Institute opens Profile → "Activity" and confirms the 2FA events are recorded.

**Rules & Edge Cases:**
- The one-time code is required after the password.
- The 2FA device can be re-registered.
- 2FA events (enabled, code verified) are logged with the account and the timestamp.
- The two-factor authentication is audit-logged with the account and the timestamp.
