# 3. Verifying Child Relationships

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 3. Verifying Child Relationships

### 3.1 Relationship Verification
**What it does:** Verifies the relationship between the Parent and the child before the link is fully activated. The platform checks that the requester is a legitimate guardian of the child (matching school/institute records where available, or a verification step). This protects the child's data from being accessed by an unauthorized adult.

**Sub-features:**
- Relationship verification before full link activation
- Verification via school/institute records (where available)
- Verification step for the Parent
- Verification status (verified, pending, failed)
- Child data limited until verified
- Verification event logging (verified, failed)
- Audit logging of the relationship verification

**Parent User Journey:**
1. A link request is accepted; relationship verification starts.
2. The platform checks the relationship via available records.
3. A verification step is completed by the Parent.
4. The verification status is "verified".
5. The child's data is fully accessible to the Parent.
6. If verification fails, the link is not activated.
7. Parent opens Profile → "Activity" and confirms the verification events are recorded.

**Rules & Edge Cases:**
- The relationship is verified before full link activation.
- The child's data is limited until verified.
- A failed verification does not activate the link.
- Verification events (verified, failed) are logged with the account and the timestamp.
- The relationship verification is audit-logged with the account and the timestamp.

### 3.2 Consent and Permission
**What it does:** Manages the consent and permissions for the Parent's access to the child's data. The child (or a guardian on the child's account) consents to the Parent's monitoring, and the scope of access is defined. The Parent can see what data they are permitted to view. This respects the child's consent and the platform's privacy rules.

**Sub-features:**
- Child consent for the Parent's monitoring
- Scope of Parent access defined
- Consent status (granted, withdrawn)
- Parent can see the permitted data scope
- Consent can be withdrawn
- Consent event logging (granted, withdrawn)
- Audit logging of the consent and permission

**Parent User Journey:**
1. The child consents to the Parent's monitoring.
2. The scope of the Parent's access is defined.
3. The consent status is "granted".
4. The Parent sees the permitted data scope.
5. If the consent is withdrawn, the Parent's access is reduced.
6. The consent events are recorded.
7. Parent opens Profile → "Activity" and confirms the consent events are recorded.

**Rules & Edge Cases:**
- The child's consent is required for the Parent's monitoring.
- The scope of access is defined by the consent.
- The consent can be withdrawn.
- Consent events (granted, withdrawn) are logged with the account and the timestamp.
- The consent and permission is audit-logged with the account and the timestamp.

### 3.3 Link Security
**What it does:** Protects the child-Parent link from unauthorized access. The link is bound to the verified Parent account, and the Parent must be authenticated to view the child's data. Suspicious access attempts are flagged, and the link can be revoked. This secures the child's data within the linked relationship.

**Sub-features:**
- Link bound to the verified Parent account
- Authentication required to view the child's data
- Suspicious access attempts flagged
- Link can be revoked
- Link security event logging (flagged, revoked)
- Audit logging of the link security

**Parent User Journey:**
1. The link is bound to the verified Parent account.
2. The Parent must be authenticated to view the child's data.
3. A suspicious access attempt is flagged.
4. The link can be revoked by the Parent or the platform.
5. The link security events are recorded.
6. Parent opens Profile → "Activity" and confirms the link security events are recorded.

**Rules & Edge Cases:**
- The link is bound to the verified Parent account.
- Authentication is required to view the child's data.
- Suspicious access attempts are flagged.
- Link security events (flagged, revoked) are logged with the account and the timestamp.
- The link security is audit-logged with the account and the timestamp.
