# 4. Session & Account Management

User Type: **Affiliate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 4. Session & Account Management

### 4.1 Active Sessions and Sign Out
**What it does:** Shows the Affiliate their active sessions: the devices and locations where they are signed in, with the last activity time. The Affiliate can sign out of individual sessions or all other sessions. This lets the Affiliate manage where their account is active.

**Sub-features:**
- List of active sessions
- Device and location per session
- Last activity time per session
- Sign out of an individual session
- Sign out of all other sessions
- Current session indicator
- Sessions available on web and mobile
- Session event logging (viewed, signed out)
- Audit logging of the active sessions and sign out

**Affiliate User Journey:**
1. Affiliate opens the active sessions view.
2. The active sessions are listed with device and location.
3. The last activity time is shown per session.
4. Affiliate signs out of an individual session.
5. Affiliate signs out of all other sessions.
6. The current session is indicated.
7. Affiliate opens Profile → "Activity" and confirms the session events are recorded.

**Rules & Edge Cases:**
- The sessions show device, location, and last activity.
- An individual session can be signed out.
- All other sessions can be signed out.
- Session events (viewed, signed out) are logged with the account and the timestamp.
- The active sessions and sign out is audit-logged with the account and the timestamp.

### 4.2 Affiliate Profile Management
**What it does:** Lets the Affiliate manage their profile: name, contact details, avatar, and public affiliate details. The Affiliate updates the profile, and the changes are saved. The public details are shown on the Affiliate's referral pages. This keeps the Affiliate's identity current.

**Sub-features:**
- Update name and contact details
- Upload an avatar
- Edit public affiliate details
- Profile save confirmation
- Public details shown on referral pages
- Profile available on web and mobile
- Profile event logging (updated)
- Audit logging of the affiliate profile management

**Affiliate User Journey:**
1. Affiliate opens the profile settings.
2. Affiliate updates their name and contact details.
3. Affiliate uploads an avatar.
4. Affiliate edits their public affiliate details.
5. A profile save confirmation is shown.
6. The public details are shown on the referral pages.
7. Affiliate opens Profile → "Activity" and confirms the profile events are recorded.

**Rules & Edge Cases:**
- The profile includes name, contact, avatar, and public details.
- A save confirmation is shown.
- The public details are shown on the referral pages.
- Profile events (updated) are logged with the account and the timestamp.
- The affiliate profile management is audit-logged with the account and the timestamp.

### 4.3 Account Deactivation
**What it does:** Lets the Affiliate deactivate their account. The Affiliate initiates the deactivation, reviews the consequences (loss of referral tools, pending commission handling), and confirms. The account is deactivated and the Affiliate is signed out. This gives the Affiliate control over their account.

**Sub-features:**
- Initiate the account deactivation
- Review the deactivation consequences
- Pending commission handling on deactivation
- Deactivation confirmation
- Account deactivated and signed out
- Deactivation available on web and mobile
- Deactivation event logging (initiated, confirmed)
- Audit logging of the account deactivation

**Affiliate User Journey:**
1. Affiliate opens the account settings.
2. Affiliate initiates the deactivation.
3. Affiliate reviews the deactivation consequences.
4. The pending commission handling is shown.
5. Affiliate confirms the deactivation.
6. The account is deactivated and the Affiliate is signed out.
7. Affiliate opens Profile → "Activity" and confirms the deactivation events are recorded.

**Rules & Edge Cases:**
- The deactivation is initiated by the Affiliate.
- The consequences are reviewed before confirmation.
- The pending commission is handled on deactivation.
- Deactivation events (initiated, confirmed) are logged with the account and the timestamp.
- The account deactivation is audit-logged with the account and the timestamp.
