# 3. Institute Security & Password Management

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 3. Institute Security & Password Management

### 3.1 Change Password
**What it does:** Lets the Training Institute change the account password: the Institute enters the current password and a new password meeting the strength requirements. The password is updated and the other sessions are optionally signed out. This keeps the institute account secure.

**Sub-features:**
- Change password form
- Current password required
- New password strength requirements
- Password updated on save
- Other sessions optionally signed out
- Change available on web and mobile
- Change event logging (password changed)
- Audit logging of the change password

**Training Institute User Journey:**
1. Training Institute opens the change password form.
2. Training Institute enters the current password.
3. Training Institute enters a new password meeting the strength requirements.
4. The password is updated on save.
5. The other sessions are optionally signed out.
6. Training Institute opens Profile → "Activity" and confirms the change events are recorded.

**Rules & Edge Cases:**
- The current password is required.
- The new password must meet the strength requirements.
- Change events (password changed) are logged with the account and the timestamp.
- The change password is audit-logged with the account and the timestamp.

### 3.2 Forgot Password
**What it does:** Lets the Training Institute reset a forgotten password: the Institute enters the registered email, receives a reset link, and sets a new password. The reset link is single-use and time-limited. This recovers access without compromising the account.

**Sub-features:**
- Forgot password form
- Reset link sent to the registered email
- New password set via the link
- Reset link single-use
- Reset link time-limited
- Reset available on web and mobile
- Reset event logging (link sent, password reset)
- Audit logging of the forgot password

**Training Institute User Journey:**
1. Training Institute opens the forgot password form.
2. Training Institute enters the registered email.
3. The reset link is sent to the registered email.
4. Training Institute sets a new password via the link.
5. The reset link is single-use.
6. The reset link is time-limited.
7. Training Institute opens Profile → "Activity" and confirms the reset events are recorded.

**Rules & Edge Cases:**
- The reset link is single-use.
- The reset link is time-limited.
- Reset events (link sent, password reset) are logged with the account and the timestamp.
- The forgot password is audit-logged with the account and the timestamp.

### 3.3 Active Sessions & Sign Out
**What it does:** Shows the Training Institute the active sessions on the account: the device, location, and last activity for each. The Institute can sign out a specific session or all other sessions. This lets the Institute revoke access from a lost or shared device.

**Sub-features:**
- Active sessions list
- Device, location, and last activity per session
- Sign out a specific session
- Sign out all other sessions
- Current session marked
- Sessions available on web and mobile
- Sessions event logging (signed out)
- Audit logging of the active sessions and sign out

**Training Institute User Journey:**
1. Training Institute opens the active sessions.
2. The active sessions list is shown.
3. The device, location, and last activity are shown per session.
4. Training Institute signs out a specific session.
5. Training Institute signs out all other sessions.
6. The current session is marked.
7. Training Institute opens Profile → "Activity" and confirms the sessions events are recorded.

**Rules & Edge Cases:**
- The current session cannot be signed out from the list.
- A signed-out session is terminated immediately.
- Sessions events (signed out) are logged with the account and the timestamp.
- The active sessions and sign out is audit-logged with the account and the timestamp.
