# 4. Session Management & Privacy — Test Cases

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: session_management_privacy.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 4.1 Active Sessions and Sign Out | List of active sessions (device, location, time) | TC-PT-1-04-001 |
| 4.1 Active Sessions and Sign Out | Sign out of the current session | TC-PT-1-04-002 |
| 4.1 Active Sessions and Sign Out | Remotely sign out another device | TC-PT-1-04-003 |
| 4.1 Active Sessions and Sign Out | Session list available on web and mobile | TC-PT-1-04-004 |
| 4.1 Active Sessions and Sign Out | Sign out confirmation | TC-PT-1-04-005 |
| 4.1 Active Sessions and Sign Out | Session event logging (signed out, remote sign out) | TC-PT-1-04-006 |
| 4.1 Active Sessions and Sign Out | Audit logging of the active sessions and sign out | TC-PT-1-04-007 |
| 4.1 Active Sessions and Sign Out | Rule: The session list shows device, location, and time. | TC-PT-1-04-001 |
| 4.1 Active Sessions and Sign Out | Rule: The current session can be signed out. | TC-PT-1-04-002 |
| 4.1 Active Sessions and Sign Out | Rule: Another device can be remotely signed out. | TC-PT-1-04-003 |
| 4.1 Active Sessions and Sign Out | Rule: Session events (signed out, remote sign out) are logged with the account and the timestamp. | TC-PT-1-04-004 |
| 4.1 Active Sessions and Sign Out | Rule: The active sessions and sign out is audit-logged with the account and the timestamp. | TC-PT-1-04-005 |
| 4.2 Privacy and Data Controls | View the data the platform holds | TC-PT-1-04-008 |
| 4.2 Privacy and Data Controls | Download the Parent's data | TC-PT-1-04-009 |
| 4.2 Privacy and Data Controls | Request account deletion | TC-PT-1-04-010 |
| 4.2 Privacy and Data Controls | Control data usage | TC-PT-1-04-011 |
| 4.2 Privacy and Data Controls | Privacy settings on the account | TC-PT-1-04-012 |
| 4.2 Privacy and Data Controls | Privacy event logging (data downloaded, deletion requested) | TC-PT-1-04-013 |
| 4.2 Privacy and Data Controls | Audit logging of the privacy and data controls | TC-PT-1-04-014 |
| 4.2 Privacy and Data Controls | Rule: The Parent can view and download their data. | TC-PT-1-04-008 |
| 4.2 Privacy and Data Controls | Rule: An account deletion can be requested. | TC-PT-1-04-009 |
| 4.2 Privacy and Data Controls | Rule: Data usage can be controlled. | TC-PT-1-04-010 |
| 4.2 Privacy and Data Controls | Rule: Privacy events (data downloaded, deletion requested) are logged with the account and the timestamp. | TC-PT-1-04-011 |
| 4.2 Privacy and Data Controls | Rule: The privacy and data controls is audit-logged with the account and the timestamp. | TC-PT-1-04-012 |

## 4.1 Active Sessions and Sign Out

### TC-PT-1-04-001 — List of active sessions (device, location, time)
**Type:** Positive
**Covers:** 4.1 → List of active sessions (device, location, time); Rule: The session list shows device, location, and time.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: List of active sessions (device.
2. Observe the result and verify the full behavior: List of active sessions (device, location, time).
**Expected Result:** List of active sessions (device, location, time) — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-04-002 — Sign out of the current session
**Type:** Positive
**Covers:** 4.1 → Sign out of the current session; Rule: The current session can be signed out.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Sign out of the current session.
2. Observe the result and verify the full behavior: Sign out of the current session.
**Expected Result:** Sign out of the current session — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-003 — Remotely sign out another device
**Type:** Positive
**Covers:** 4.1 → Remotely sign out another device; Rule: Another device can be remotely signed out.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Remotely sign out another device.
2. Observe the result and verify the full behavior: Remotely sign out another device.
**Expected Result:** Remotely sign out another device — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-004 — Session list available on web and mobile
**Type:** Positive
**Covers:** 4.1 → Session list available on web and mobile; Rule: Session events (signed out, remote sign out) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Session list available on web and mobile.
2. Observe the result and verify the full behavior: Session list available on web and mobile.
**Expected Result:** Session list available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-005 — Sign out confirmation
**Type:** Positive
**Covers:** 4.1 → Sign out confirmation; Rule: The active sessions and sign out is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Sign out confirmation.
2. Observe the result and verify the full behavior: Sign out confirmation.
**Expected Result:** Sign out confirmation — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-006 — Session event logging (signed out, remote sign out)
**Type:** Positive
**Covers:** 4.1 → Session event logging (signed out, remote sign out)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Session event logging (signed out.
2. Observe the result and verify the full behavior: Session event logging (signed out, remote sign out).
**Expected Result:** Session event logging (signed out, remote sign out) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-007 — Audit logging of the active sessions and sign out
**Type:** Positive
**Covers:** 4.1 → Audit logging of the active sessions and sign out
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the active sessions and sign out.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 4.2 Privacy and Data Controls

### TC-PT-1-04-008 — View the data the platform holds
**Type:** Positive
**Covers:** 4.2 → View the data the platform holds; Rule: The Parent can view and download their data.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: View the data the platform holds.
2. Observe the result and verify the full behavior: View the data the platform holds.
**Expected Result:** View the data the platform holds — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-04-009 — Download the Parent's data
**Type:** Positive
**Covers:** 4.2 → Download the Parent's data; Rule: An account deletion can be requested.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Download the Parent's data.
2. Observe the result and verify the full behavior: Download the Parent's data.
**Expected Result:** Download the Parent's data — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-010 — Request account deletion
**Type:** Positive
**Covers:** 4.2 → Request account deletion; Rule: Data usage can be controlled.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Request account deletion.
2. Observe the result and verify the full behavior: Request account deletion.
**Expected Result:** Request account deletion — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-011 — Control data usage
**Type:** Positive
**Covers:** 4.2 → Control data usage; Rule: Privacy events (data downloaded, deletion requested) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Control data usage.
2. Observe the result and verify the full behavior: Control data usage.
**Expected Result:** Control data usage — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-012 — Privacy settings on the account
**Type:** Positive
**Covers:** 4.2 → Privacy settings on the account; Rule: The privacy and data controls is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Privacy settings on the account.
2. Observe the result and verify the full behavior: Privacy settings on the account.
**Expected Result:** Privacy settings on the account — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-013 — Privacy event logging (data downloaded, deletion requested)
**Type:** Positive
**Covers:** 4.2 → Privacy event logging (data downloaded, deletion requested)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Privacy event logging (data downloaded.
2. Observe the result and verify the full behavior: Privacy event logging (data downloaded, deletion requested).
**Expected Result:** Privacy event logging (data downloaded, deletion requested) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-04-014 — Audit logging of the privacy and data controls
**Type:** Positive
**Covers:** 4.2 → Audit logging of the privacy and data controls
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the privacy and data controls.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
