# Institute Student Support — Test Cases

User Type: **Training Institute** (Sub-Admin: Institute Student Support)
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: student_support_role.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 Student Queries & Technical Issues | Student query inbox (priority, status) | TC-INST-SUPP-01-001 |
| 1.1 Student Queries & Technical Issues | Triage and categorize queries | TC-INST-SUPP-01-002 |
| 1.1 Student Queries & Technical Issues | Respond to and resolve queries | TC-INST-SUPP-01-003 |
| 1.1 Student Queries & Technical Issues | Escalate unresolved queries | TC-INST-SUPP-01-004 |
| 1.1 Student Queries & Technical Issues | Query history and resolution notes | TC-INST-SUPP-01-005 |
| 1.1 Student Queries & Technical Issues | Available on web and mobile | TC-INST-SUPP-01-006 |
| 1.1 Student Queries & Technical Issues | Event logging (received, triaged, responded, resolved, escalated) | TC-INST-SUPP-01-007 |
| 1.1 Student Queries & Technical Issues | Audit logging of query handling | TC-INST-SUPP-01-008 |
| 1.1 Student Queries & Technical Issues | Rule: tickets scoped to own institute | TC-INST-SUPP-01-009 |
| 1.1 Student Queries & Technical Issues | Rule: cannot close without resolution note | TC-INST-SUPP-01-010 |
| 1.1 Student Queries & Technical Issues | Rule: escalated tickets remain visible with status | TC-INST-SUPP-01-011 |
| 1.1 Student Queries & Technical Issues | Rule: response/resolution timestamps recorded | TC-INST-SUPP-01-012 |
| 1.2 Account & Access Requests | Process registration requests | TC-INST-SUPP-02-001 |
| 1.2 Account & Access Requests | Process account change requests | TC-INST-SUPP-02-002 |
| 1.2 Account & Access Requests | Resolve course access issues | TC-INST-SUPP-02-003 |
| 1.2 Account & Access Requests | Resolve account access issues | TC-INST-SUPP-02-004 |
| 1.2 Account & Access Requests | Request status tracking per student | TC-INST-SUPP-02-005 |
| 1.2 Account & Access Requests | Available on web and mobile | TC-INST-SUPP-02-006 |
| 1.2 Account & Access Requests | Event logging (received, processed, access fixed) | TC-INST-SUPP-02-007 |
| 1.2 Account & Access Requests | Audit logging of account and access actions | TC-INST-SUPP-02-008 |
| 1.2 Account & Access Requests | Rule: activation requires available seat; else queued + BM notified | TC-INST-SUPP-02-009 |
| 1.2 Account & Access Requests | Rule: license/billing fields not editable | TC-INST-SUPP-02-010 |
| 1.2 Account & Access Requests | Rule: changes recorded with before/after values | TC-INST-SUPP-02-011 |
| 1.3 Engagement Monitoring & Alerts | Monitor student engagement | TC-INST-SUPP-03-001 |
| 1.3 Engagement Monitoring & Alerts | Inactive student list | TC-INST-SUPP-03-002 |
| 1.3 Engagement Monitoring & Alerts | Send alerts to individual students | TC-INST-SUPP-03-003 |
| 1.3 Engagement Monitoring & Alerts | Send in-app communication | TC-INST-SUPP-03-004 |
| 1.3 Engagement Monitoring & Alerts | Communication history per student | TC-INST-SUPP-03-005 |
| 1.3 Engagement Monitoring & Alerts | Available on web and mobile | TC-INST-SUPP-03-006 |
| 1.3 Engagement Monitoring & Alerts | Event logging (alert sent, message sent) | TC-INST-SUPP-03-007 |
| 1.3 Engagement Monitoring & Alerts | Audit logging of alerts and communication | TC-INST-SUPP-03-008 |
| 1.3 Engagement Monitoring & Alerts | Rule: inactivity threshold set by Institute Admin | TC-INST-SUPP-03-009 |
| 1.3 Engagement Monitoring & Alerts | Rule: sends limited to own institute students | TC-INST-SUPP-03-010 |
| 1.3 Engagement Monitoring & Alerts | Rule: bulk sends rate-limited | TC-INST-SUPP-03-011 |
| 1.4 Student Progress Reports | Generate individual student progress reports | TC-INST-SUPP-04-001 |
| 1.4 Student Progress Reports | Report content (progress, results, activity) | TC-INST-SUPP-04-002 |
| 1.4 Student Progress Reports | Export reports (PDF) | TC-INST-SUPP-04-003 |
| 1.4 Student Progress Reports | Share reports by secure link | TC-INST-SUPP-04-004 |
| 1.4 Student Progress Reports | Report generation history | TC-INST-SUPP-04-005 |
| 1.4 Student Progress Reports | Available on web and mobile | TC-INST-SUPP-04-006 |
| 1.4 Student Progress Reports | Event logging (generated, exported, shared) | TC-INST-SUPP-04-007 |
| 1.4 Student Progress Reports | Audit logging of report generation and sharing | TC-INST-SUPP-04-008 |
| 1.4 Student Progress Reports | Rule: reports scoped to own institute students | TC-INST-SUPP-04-009 |
| 1.4 Student Progress Reports | Rule: share links controlled and expirable | TC-INST-SUPP-04-010 |
| 1.4 Student Progress Reports | Rule: progress data read-only for agent | TC-INST-SUPP-04-011 |
| 1.5 Role Restrictions | No access to billing, invoices, payments | TC-INST-SUPP-05-001 |
| 1.5 Role Restrictions | No access to license purchase or seat management | TC-INST-SUPP-05-002 |
| 1.5 Role Restrictions | No access to advanced analytics administration | TC-INST-SUPP-05-003 |
| 1.5 Role Restrictions | No access to content creation or curriculum | TC-INST-SUPP-05-004 |
| 1.5 Role Restrictions | No access to integration management | TC-INST-SUPP-05-005 |
| 1.5 Role Restrictions | No access to sub-admin management or branding | TC-INST-SUPP-05-006 |
| 1.5 Role Restrictions | Available on web and mobile | TC-INST-SUPP-05-007 |
| 1.5 Role Restrictions | Event logging (denied access attempts) | TC-INST-SUPP-05-008 |
| 1.5 Role Restrictions | Audit logging of denied access attempts | TC-INST-SUPP-05-009 |
| 1.5 Role Restrictions | Rule: restrictions enforced at API layer | TC-INST-SUPP-05-010 |
| 1.5 Role Restrictions | Rule: data scope own institute students | TC-INST-SUPP-05-011 |
| 1.5 Role Restrictions | Rule: restrictions not overridable by agent | TC-INST-SUPP-05-012 |

## 1.1 Student Queries & Technical Issues

### TC-INST-SUPP-01-001 — Query inbox shows priority and status
**Type:** Positive
**Covers:** 1.1 → Student query inbox (tickets with priority and status)
**Preconditions:** Student Support agent logged in; open tickets exist.
**Steps:**
1. Open the Query Inbox.
**Expected Result:** All open tickets are listed with priority and status; data matches the actual tickets.
**Priority:** High

### TC-INST-SUPP-01-002 — Triage and categorize a query
**Type:** Positive
**Covers:** 1.1 → Triage and categorize queries
**Preconditions:** An untriaged ticket exists.
**Steps:**
1. Open the ticket and categorize it as "technical".
**Expected Result:** The ticket's category is updated and reflected in the inbox.
**Priority:** High

### TC-INST-SUPP-01-003 — Respond to and resolve a query
**Type:** Positive
**Covers:** 1.1 → Respond to and resolve queries
**Preconditions:** A triaged ticket exists.
**Steps:**
1. Respond with the resolution and mark the ticket resolved with a resolution note.
**Expected Result:** The student receives the response; the ticket status becomes "Resolved" with the note recorded.
**Priority:** Critical

### TC-INST-SUPP-01-004 — Escalate an unresolved query
**Type:** Positive
**Covers:** 1.1 → Escalate unresolved queries
**Preconditions:** An unresolved ticket exists.
**Steps:**
1. Select "Escalate" and attach the student's device details.
**Expected Result:** The ticket is escalated to platform support; its status shows "Escalated".
**Priority:** High

### TC-INST-SUPP-01-005 — Query history and resolution notes
**Type:** Positive
**Covers:** 1.1 → Query history and resolution notes
**Preconditions:** Resolved tickets exist.
**Steps:**
1. Open the query history and a resolved ticket.
**Expected Result:** The full history and resolution notes are shown with timestamps.
**Priority:** Medium

### TC-INST-SUPP-01-006 — Query handling on web and mobile
**Type:** Positive
**Covers:** 1.1 → Available on web and mobile
**Preconditions:** Agent logged in on both surfaces.
**Steps:**
1. Triage a ticket on mobile; resolve one on web.
**Expected Result:** Both surfaces render the features correctly without horizontal scroll.
**Priority:** High

### TC-INST-SUPP-01-007 — Query events are logged
**Type:** Positive
**Covers:** 1.1 → Event logging (received, triaged, responded, resolved, escalated)
**Preconditions:** Query actions performed.
**Steps:**
1. Open Profile → "Activity".
**Expected Result:** Each action appears as an event with the actor and timestamp.
**Priority:** High

### TC-INST-SUPP-01-008 — Query handling is audit-logged
**Type:** Positive
**Covers:** 1.1 → Audit logging of query handling
**Preconditions:** Query actions performed.
**Steps:**
1. Review the institute audit log.
**Expected Result:** Every action is audit-logged with the actor and timestamp.
**Priority:** High

### TC-INST-SUPP-01-009 — Tickets scoped to own institute
**Type:** Negative
**Covers:** 1.1 → Rule: tickets scoped to own institute
**Preconditions:** Another institute's tickets exist.
**Steps:**
1. Attempt to view another institute's tickets via direct endpoint call.
**Expected Result:** The call is denied; only own-institute tickets are accessible.
**Priority:** Critical

### TC-INST-SUPP-01-010 — Cannot close without resolution note
**Type:** Negative
**Covers:** 1.1 → Rule: cannot close without resolution note
**Preconditions:** An open ticket exists.
**Steps:**
1. Attempt to resolve the ticket without entering a resolution note.
**Expected Result:** The action is blocked with a validation error.
**Priority:** High

### TC-INST-SUPP-01-011 — Escalated tickets remain visible
**Type:** Positive
**Covers:** 1.1 → Rule: escalated tickets remain visible with status
**Preconditions:** An escalated ticket exists.
**Steps:**
1. Open the Query Inbox and locate the escalated ticket.
**Expected Result:** The ticket is visible with status "Escalated" and the escalation details.
**Priority:** Medium

### TC-INST-SUPP-01-012 — Response and resolution timestamps recorded
**Type:** Positive
**Covers:** 1.1 → Rule: response/resolution timestamps recorded
**Preconditions:** A ticket responded to and resolved.
**Steps:**
1. Open the ticket history.
**Expected Result:** The response and resolution timestamps are recorded and accurate.
**Priority:** Medium

## 1.2 Account & Access Requests

### TC-INST-SUPP-02-001 — Process a registration request
**Type:** Positive
**Covers:** 1.2 → Process registration requests (verify and activate)
**Preconditions:** A registration request exists; an available seat exists.
**Steps:**
1. Verify the student's details against the enrollment list.
2. Activate the account.
**Expected Result:** The account is activated; the student can log in; the seat is consumed.
**Priority:** Critical

### TC-INST-SUPP-02-002 — Process an account change request
**Type:** Positive
**Covers:** 1.2 → Process account change requests (name, email, grade, batch)
**Preconditions:** An account change request exists.
**Steps:**
1. Update the student's batch from "Batch A" to "Batch B".
**Expected Result:** The change is applied; the before/after values are recorded.
**Priority:** High

### TC-INST-SUPP-02-003 — Resolve a course access issue
**Type:** Positive
**Covers:** 1.2 → Resolve course access issues (missing assignment, wrong batch)
**Preconditions:** A student is missing a course assignment.
**Steps:**
1. Re-assign the Mathematics course to the student.
**Expected Result:** The course appears in the student's portal.
**Priority:** High

### TC-INST-SUPP-02-004 — Resolve an account access issue
**Type:** Positive
**Covers:** 1.2 → Resolve account access issues (locked, suspended, seat not active)
**Preconditions:** A student's account is locked.
**Steps:**
1. Review the lock reason and unlock the account.
**Expected Result:** The student can log in; the unlock is recorded.
**Priority:** High

### TC-INST-SUPP-02-005 — Request status tracking per student
**Type:** Positive
**Covers:** 1.2 → Request status tracking per student
**Preconditions:** Multiple requests for a student exist.
**Steps:**
1. Open the student's request status list.
**Expected Result:** All requests show their current status and history.
**Priority:** Medium

### TC-INST-SUPP-02-006 — Account requests on web and mobile
**Type:** Positive
**Covers:** 1.2 → Available on web and mobile
**Preconditions:** Agent logged in on both surfaces.
**Steps:**
1. Process a request on mobile; resolve an access issue on web.
**Expected Result:** Both surfaces render the features correctly without horizontal scroll.
**Priority:** High

### TC-INST-SUPP-02-007 — Account and access events are logged
**Type:** Positive
**Covers:** 1.2 → Event logging (received, processed, access fixed)
**Preconditions:** Account and access actions performed.
**Steps:**
1. Open Profile → "Activity".
**Expected Result:** Each action appears as an event with the actor and timestamp.
**Priority:** High

### TC-INST-SUPP-02-008 — Account and access actions are audit-logged
**Type:** Positive
**Covers:** 1.2 → Audit logging of account and access actions
**Preconditions:** Account and access actions performed.
**Steps:**
1. Review the institute audit log.
**Expected Result:** Every action is audit-logged with the actor, before/after values, and timestamp.
**Priority:** High

### TC-INST-SUPP-02-009 — Activation without a seat queues and notifies BM
**Type:** Positive
**Covers:** 1.2 → Rule: activation requires available seat; else queued + BM notified
**Preconditions:** A registration request exists; no seats available.
**Steps:**
1. Attempt to activate the account.
**Expected Result:** Activation is blocked; the request is queued; the Billing Manager is notified.
**Priority:** Critical

### TC-INST-SUPP-02-010 — License and billing fields not editable
**Type:** Negative
**Covers:** 1.2 → Rule: license/billing fields not editable
**Preconditions:** Agent logged in; a student record open.
**Steps:**
1. Attempt to edit the student's license or billing fields.
**Expected Result:** The fields are not editable; the attempt is rejected.
**Priority:** Critical

### TC-INST-SUPP-02-011 — Changes recorded with before/after values
**Type:** Positive
**Covers:** 1.2 → Rule: changes recorded with before/after values
**Preconditions:** An account change performed.
**Steps:**
1. Review the audit entry for the change.
**Expected Result:** The entry shows the field, before value, after value, actor, and timestamp.
**Priority:** High

## 1.3 Engagement Monitoring & Alerts

### TC-INST-SUPP-03-001 — Monitor student engagement
**Type:** Positive
**Covers:** 1.3 → Monitor student engagement (activity, inactivity, drop-off)
**Preconditions:** Agent logged in; engagement data exists.
**Steps:**
1. Open Engagement Monitoring.
**Expected Result:** Engagement metrics (activity, inactivity, drop-off) are shown for the institute's students.
**Priority:** High

### TC-INST-SUPP-03-002 — Inactive student list
**Type:** Positive
**Covers:** 1.3 → Inactive student list (no activity beyond threshold)
**Preconditions:** Students with no activity beyond the threshold.
**Steps:**
1. Open the inactive student list.
**Expected Result:** Only students beyond the inactivity threshold are listed.
**Priority:** High

### TC-INST-SUPP-03-003 — Send an alert to a student
**Type:** Positive
**Covers:** 1.3 → Send alerts to individual students
**Preconditions:** A student with an assessment due soon.
**Steps:**
1. Select the student and send an alert.
**Expected Result:** The student receives the alert; the send is recorded.
**Priority:** High

### TC-INST-SUPP-03-004 — Send in-app communication
**Type:** Positive
**Covers:** 1.3 → Send in-app communication (messages, nudges)
**Preconditions:** An inactive student exists.
**Steps:**
1. Send an in-app nudge to the student.
**Expected Result:** The message appears in the student's in-app inbox.
**Priority:** High

### TC-INST-SUPP-03-005 — Communication history per student
**Type:** Positive
**Covers:** 1.3 → Communication history per student
**Preconditions:** Communications sent to a student.
**Steps:**
1. Open the student's communication history.
**Expected Result:** All messages show content summary and timestamp.
**Priority:** Medium

### TC-INST-SUPP-03-006 — Engagement and alerts on web and mobile
**Type:** Positive
**Covers:** 1.3 → Available on web and mobile
**Preconditions:** Agent logged in on both surfaces.
**Steps:**
1. View the inactive list on mobile; send an alert on web.
**Expected Result:** Both surfaces render the features correctly without horizontal scroll.
**Priority:** High

### TC-INST-SUPP-03-007 — Alert and message events are logged
**Type:** Positive
**Covers:** 1.3 → Event logging (alert sent, message sent)
**Preconditions:** Alerts and messages sent.
**Steps:**
1. Open Profile → "Activity".
**Expected Result:** Each send appears as an event with the actor and timestamp.
**Priority:** High

### TC-INST-SUPP-03-008 — Alerts and communication are audit-logged
**Type:** Positive
**Covers:** 1.3 → Audit logging of alerts and communication
**Preconditions:** Alerts and messages sent.
**Steps:**
1. Review the institute audit log.
**Expected Result:** Every send is audit-logged with the actor, recipient, and timestamp.
**Priority:** High

### TC-INST-SUPP-03-009 — Inactivity threshold set by Institute Admin
**Type:** Negative
**Covers:** 1.3 → Rule: inactivity threshold set by Institute Admin
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to change the inactivity threshold.
**Expected Result:** The setting is not editable by the agent.
**Priority:** High

### TC-INST-SUPP-03-010 — Sends limited to own institute students
**Type:** Negative
**Covers:** 1.3 → Rule: sends limited to own institute students
**Preconditions:** Another institute's students exist.
**Steps:**
1. Attempt to send an alert to another institute's student via direct endpoint call.
**Expected Result:** The call is denied; the student is not in the selectable list.
**Priority:** Critical

### TC-INST-SUPP-03-011 — Bulk sends are rate-limited
**Type:** Positive
**Covers:** 1.3 → Rule: bulk sends rate-limited
**Preconditions:** A large student selection.
**Steps:**
1. Attempt a bulk send exceeding the rate limit.
**Expected Result:** The send is throttled or split; students are not overloaded.
**Priority:** Medium

## 1.4 Student Progress Reports

### TC-INST-SUPP-04-001 — Generate an individual student progress report
**Type:** Positive
**Covers:** 1.4 → Generate individual student progress reports
**Preconditions:** A student with progress data.
**Steps:**
1. Open the student's record and generate a progress report.
**Expected Result:** The report is generated for that student only.
**Priority:** High

### TC-INST-SUPP-04-002 — Report content is complete
**Type:** Positive
**Covers:** 1.4 → Report content (progress, results, activity)
**Preconditions:** A generated report.
**Steps:**
1. Review the report sections.
**Expected Result:** Course progress, assessment results, and activity summary are all present and accurate.
**Priority:** High

### TC-INST-SUPP-04-003 — Export a report as PDF
**Type:** Positive
**Covers:** 1.4 → Export reports (PDF)
**Preconditions:** A generated report.
**Steps:**
1. Export the report as PDF.
**Expected Result:** The PDF downloads with content matching the report.
**Priority:** High

### TC-INST-SUPP-04-004 — Share a report by secure link
**Type:** Positive
**Covers:** 1.4 → Share reports by secure link
**Preconditions:** A generated report.
**Steps:**
1. Share the report by secure link.
2. Open the link; then open it after expiry.
**Expected Result:** The link grants access until expiry; after expiry it is rejected.
**Priority:** High

### TC-INST-SUPP-04-005 — Report generation history
**Type:** Positive
**Covers:** 1.4 → Report generation history
**Preconditions:** Reports generated.
**Steps:**
1. Open the report generation history.
**Expected Result:** Each report shows the student, actor, and timestamp.
**Priority:** Medium

### TC-INST-SUPP-04-006 — Progress reports on web and mobile
**Type:** Positive
**Covers:** 1.4 → Available on web and mobile
**Preconditions:** Agent logged in on both surfaces.
**Steps:**
1. Generate a report on mobile; export on web.
**Expected Result:** Both surfaces render the features correctly without horizontal scroll.
**Priority:** High

### TC-INST-SUPP-04-007 — Report events are logged
**Type:** Positive
**Covers:** 1.4 → Event logging (generated, exported, shared)
**Preconditions:** Report actions performed.
**Steps:**
1. Open Profile → "Activity".
**Expected Result:** Each action appears as an event with the account and timestamp.
**Priority:** High

### TC-INST-SUPP-04-008 — Report actions are audit-logged
**Type:** Positive
**Covers:** 1.4 → Audit logging of report generation and sharing
**Preconditions:** Report actions performed.
**Steps:**
1. Review the institute audit log.
**Expected Result:** Every action is audit-logged with the account and timestamp.
**Priority:** High

### TC-INST-SUPP-04-009 — Reports scoped to own institute students
**Type:** Negative
**Covers:** 1.4 → Rule: reports scoped to own institute students
**Preconditions:** Another institute's students exist.
**Steps:**
1. Attempt to generate a report for another institute's student via direct endpoint call.
**Expected Result:** The call is denied; the student is not selectable.
**Priority:** Critical

### TC-INST-SUPP-04-010 — Share links are controlled and expirable
**Type:** Positive
**Covers:** 1.4 → Rule: share links controlled and expirable
**Preconditions:** A shared report link.
**Steps:**
1. Open the link with an unauthorized account; then after expiry.
**Expected Result:** Unauthorized access is rejected; the link expires as configured.
**Priority:** Medium

### TC-INST-SUPP-04-011 — Progress data is read-only for the agent
**Type:** Negative
**Covers:** 1.4 → Rule: progress data read-only for agent
**Preconditions:** Agent logged in; a student's progress open.
**Steps:**
1. Attempt to modify a progress value or assessment result.
**Expected Result:** No modification controls exist; the attempt is rejected.
**Priority:** Critical

## 1.5 Role Restrictions

### TC-INST-SUPP-05-001 — No billing access
**Type:** Negative
**Covers:** 1.5 → No access to billing, invoices, payments
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open Billing & Licensing.
**Expected Result:** Access is denied; the screen is not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-002 — No license purchase or seat management
**Type:** Negative
**Covers:** 1.5 → No access to license purchase or seat management
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open Bulk License Management.
**Expected Result:** Access is denied; the screen is not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-003 — No advanced analytics administration
**Type:** Negative
**Covers:** 1.5 → No access to advanced analytics administration
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open Advanced Analytics administration.
**Expected Result:** Access is denied; the screen is not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-004 — No content creation or curriculum access
**Type:** Negative
**Covers:** 1.5 → No access to content creation or curriculum
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open content creation or curriculum screens.
**Expected Result:** Access is denied; the screens are not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-005 — No integration management access
**Type:** Negative
**Covers:** 1.5 → No access to integration management
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open Integrations.
**Expected Result:** Access is denied; the screen is not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-006 — No sub-admin management or branding access
**Type:** Negative
**Covers:** 1.5 → No access to sub-admin management or branding
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to open Sub-Admins and Branding.
**Expected Result:** Access is denied for both; the screens are not in navigation.
**Priority:** Critical

### TC-INST-SUPP-05-007 — Restrictions consistent on web and mobile
**Type:** Positive
**Covers:** 1.5 → Available on web and mobile
**Preconditions:** Agent logged in on both surfaces.
**Steps:**
1. Review navigation on web and mobile.
**Expected Result:** The same restricted screens are absent on both surfaces; no horizontal scroll.
**Priority:** High

### TC-INST-SUPP-05-008 — Denied access attempts are event-logged
**Type:** Positive
**Covers:** 1.5 → Event logging (denied access attempts)
**Preconditions:** Denied access attempts made.
**Steps:**
1. Open Profile → "Activity".
**Expected Result:** Each denied attempt appears with the account, target screen, and timestamp.
**Priority:** High

### TC-INST-SUPP-05-009 — Denied access attempts are audit-logged
**Type:** Positive
**Covers:** 1.5 → Audit logging of denied access attempts
**Preconditions:** Denied access attempts made.
**Steps:**
1. Review the institute audit log.
**Expected Result:** Each denied attempt is audit-logged with the account and timestamp.
**Priority:** High

### TC-INST-SUPP-05-010 — Restrictions enforced at API layer
**Type:** Negative
**Covers:** 1.5 → Rule: restrictions enforced at API layer
**Preconditions:** Agent's session token.
**Steps:**
1. Call a billing endpoint directly with the token.
**Expected Result:** The API returns a denial (403); no data is returned.
**Priority:** Critical

### TC-INST-SUPP-05-011 — Data scope is own institute students
**Type:** Negative
**Covers:** 1.5 → Rule: data scope own institute students
**Preconditions:** Agent's session token.
**Steps:**
1. Call a student-list endpoint with another institute's ID.
**Expected Result:** The call is denied or returns empty; no cross-institute data is exposed.
**Priority:** Critical

### TC-INST-SUPP-05-012 — Restrictions not overridable by agent
**Type:** Negative
**Covers:** 1.5 → Rule: restrictions not overridable by agent
**Preconditions:** Agent logged in.
**Steps:**
1. Attempt to change own role or permissions via any UI or endpoint.
**Expected Result:** All attempts are denied; only Institute Admin or Super Administrator can change the role.
**Priority:** Critical
