# 6. Policies & Agreements — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: policies_agreements.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature,
  expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 6.1 Terms of Service | Terms: the terms (the terms, the clause, the date) | TC-SA-22-06-001 |
| 6.1 Terms of Service | Clause: the clause (the clause of the terms, the text, the date) | TC-SA-22-06-002 |
| 6.1 Terms of Service | Terms version: the version (the version of the terms, the number, the date) | TC-SA-22-06-003 |
| 6.1 Terms of Service | Terms status: the status (the active, the archived) | TC-SA-22-06-004 |
| 6.1 Terms of Service | Terms count: the count (the count of the clauses) | TC-SA-22-06-005 |
| 6.1 Terms of Service | Terms view: the view (the terms, the clauses, the versions, the dates) | TC-SA-22-06-006 |
| 6.1 Terms of Service | Terms export: the export (the terms, the format, the version) | TC-SA-22-06-007 |
| 6.1 Terms of Service | Audit logging of the terms of service configuration | TC-SA-22-06-008 |
| 6.1 Terms of Service | Rule: the terms are the agreement (the terms, the clause, the date); the terms are the contract | TC-SA-22-06-001 |
| 6.1 Terms of Service | Rule: the clause is the rule (the clause of the terms, the text, the date); the clause is the provision | TC-SA-22-06-002 |
| 6.1 Terms of Service | Rule: the terms version is the iteration (the version of the terms, the number, the date); the version is the revision | TC-SA-22-06-003 |
| 6.1 Terms of Service | Rule: the terms status is the state (the active, the archived); the status is the control | TC-SA-22-06-004 |
| 6.1 Terms of Service | Rule: the terms are provided (the terms, the clauses, the versions, the dates); the agreement is managed | TC-SA-22-06-006 |
| 6.1 Terms of Service | Rule: terms of service configuration is audit-logged with the terms, version, and timestamp | TC-SA-22-06-008 |
| 6.2 Privacy Policy | Policy: the policy (the policy, the clause, the date) | TC-SA-22-06-009 |
| 6.2 Privacy Policy | Clause: the clause (the clause of the policy, the text, the date) | TC-SA-22-06-010 |
| 6.2 Privacy Policy | Policy version: the version (the version of the policy, the number, the date) | TC-SA-22-06-011 |
| 6.2 Privacy Policy | Policy status: the status (the active, the archived) | TC-SA-22-06-012 |
| 6.2 Privacy Policy | Policy count: the count (the count of the clauses) | TC-SA-22-06-013 |
| 6.2 Privacy Policy | Policy view: the view (the policies, the clauses, the versions, the dates) | TC-SA-22-06-014 |
| 6.2 Privacy Policy | Policy export: the export (the policies, the format, the version) | TC-SA-22-06-015 |
| 6.2 Privacy Policy | Audit logging of the privacy policy configuration | TC-SA-22-06-016 |
| 6.2 Privacy Policy | Rule: the policy is the commitment (the policy, the clause, the date); the policy is the promise | TC-SA-22-06-009 |
| 6.2 Privacy Policy | Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision | TC-SA-22-06-010 |
| 6.2 Privacy Policy | Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision | TC-SA-22-06-011 |
| 6.2 Privacy Policy | Rule: the policy status is the state (the active, the archived); the status is the control | TC-SA-22-06-012 |
| 6.2 Privacy Policy | Rule: the policy is provided (the policies, the clauses, the versions, the dates); the commitment is managed | TC-SA-22-06-014 |
| 6.2 Privacy Policy | Rule: privacy policy configuration is audit-logged with the policy, version, and timestamp | TC-SA-22-06-016 |
| 6.3 Refund Policy | Policy: the policy (the policy, the clause, the date) | TC-SA-22-06-017 |
| 6.3 Refund Policy | Clause: the clause (the clause of the policy, the text, the date) | TC-SA-22-06-018 |
| 6.3 Refund Policy | Policy version: the version (the version of the policy, the number, the date) | TC-SA-22-06-019 |
| 6.3 Refund Policy | Policy status: the status (the active, the archived) | TC-SA-22-06-020 |
| 6.3 Refund Policy | Policy count: the count (the count of the clauses) | TC-SA-22-06-021 |
| 6.3 Refund Policy | Policy view: the view (the policies, the clauses, the versions, the dates) | TC-SA-22-06-022 |
| 6.3 Refund Policy | Policy export: the export (the policies, the format, the version) | TC-SA-22-06-023 |
| 6.3 Refund Policy | Audit logging of the refund policy configuration | TC-SA-22-06-024 |
| 6.3 Refund Policy | Rule: the policy is the rule (the policy, the clause, the date); the policy is the commitment | TC-SA-22-06-017 |
| 6.3 Refund Policy | Rule: the clause is the provision (the clause of the policy, the text, the date); the clause is the detail | TC-SA-22-06-018 |
| 6.3 Refund Policy | Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision | TC-SA-22-06-019 |
| 6.3 Refund Policy | Rule: the policy status is the state (the active, the archived); the status is the control | TC-SA-22-06-020 |
| 6.3 Refund Policy | Rule: the policy is provided (the policies, the clauses, the versions, the dates); the rule is managed | TC-SA-22-06-022 |
| 6.3 Refund Policy | Rule: refund policy configuration is audit-logged with the policy, version, and timestamp | TC-SA-22-06-024 |
| 6.4 Acceptable Use Policy | Policy: the policy (the policy, the clause, the date) | TC-SA-22-06-025 |
| 6.4 Acceptable Use Policy | Clause: the clause (the clause of the policy, the text, the date) | TC-SA-22-06-026 |
| 6.4 Acceptable Use Policy | Policy version: the version (the version of the policy, the number, the date) | TC-SA-22-06-027 |
| 6.4 Acceptable Use Policy | Policy status: the status (the active, the archived) | TC-SA-22-06-028 |
| 6.4 Acceptable Use Policy | Policy count: the count (the count of the clauses) | TC-SA-22-06-029 |
| 6.4 Acceptable Use Policy | Policy view: the view (the policies, the clauses, the versions, the dates) | TC-SA-22-06-030 |
| 6.4 Acceptable Use Policy | Policy export: the export (the policies, the format, the version) | TC-SA-22-06-031 |
| 6.4 Acceptable Use Policy | Audit logging of the acceptable use policy configuration | TC-SA-22-06-032 |
| 6.4 Acceptable Use Policy | Rule: the policy is the boundary (the policy, the clause, the date); the policy is the limit | TC-SA-22-06-025 |
| 6.4 Acceptable Use Policy | Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision | TC-SA-22-06-026 |
| 6.4 Acceptable Use Policy | Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision | TC-SA-22-06-027 |
| 6.4 Acceptable Use Policy | Rule: the policy status is the state (the active, the archived); the status is the control | TC-SA-22-06-028 |
| 6.4 Acceptable Use Policy | Rule: the policy is provided (the policies, the clauses, the versions, the dates); the boundary is managed | TC-SA-22-06-030 |
| 6.4 Acceptable Use Policy | Rule: acceptable use policy configuration is audit-logged with the policy, version, and timestamp | TC-SA-22-06-032 |
| 6.5 Cookie Policy | Policy: the policy (the policy, the clause, the date) | TC-SA-22-06-033 |
| 6.5 Cookie Policy | Clause: the clause (the clause of the policy, the text, the date) | TC-SA-22-06-034 |
| 6.5 Cookie Policy | Policy version: the version (the version of the policy, the number, the date) | TC-SA-22-06-035 |
| 6.5 Cookie Policy | Policy status: the status (the active, the archived) | TC-SA-22-06-036 |
| 6.5 Cookie Policy | Policy count: the count (the count of the clauses) | TC-SA-22-06-037 |
| 6.5 Cookie Policy | Policy view: the view (the policies, the clauses, the versions, the dates) | TC-SA-22-06-038 |
| 6.5 Cookie Policy | Policy export: the export (the policies, the format, the version) | TC-SA-22-06-039 |
| 6.5 Cookie Policy | Audit logging of the cookie policy configuration | TC-SA-22-06-040 |
| 6.5 Cookie Policy | Rule: the policy is the disclosure (the policy, the clause, the date); the policy is the notice | TC-SA-22-06-033 |
| 6.5 Cookie Policy | Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision | TC-SA-22-06-034 |
| 6.5 Cookie Policy | Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision | TC-SA-22-06-035 |
| 6.5 Cookie Policy | Rule: the policy status is the state (the active, the archived); the status is the control | TC-SA-22-06-036 |
| 6.5 Cookie Policy | Rule: the policy is provided (the policies, the clauses, the versions, the dates); the disclosure is managed | TC-SA-22-06-038 |
| 6.5 Cookie Policy | Rule: cookie policy configuration is audit-logged with the policy, version, and timestamp | TC-SA-22-06-040 |
| 6.6 Click-through Acceptance | Acceptance: the acceptance (the acceptance, the user, the policy, the date) | TC-SA-22-06-041 |
| 6.6 Click-through Acceptance | User: the user (the user, the name, the acceptance) | TC-SA-22-06-042 |
| 6.6 Click-through Acceptance | Policy: the policy (the policy, the name, the date) | TC-SA-22-06-043 |
| 6.6 Click-through Acceptance | Acceptance status: the status (the accepted, the not-accepted) | TC-SA-22-06-044 |
| 6.6 Click-through Acceptance | Acceptance count: the count (the count of the acceptances) | TC-SA-22-06-045 |
| 6.6 Click-through Acceptance | Acceptance view: the view (the acceptances, the users, the policies, the dates) | TC-SA-22-06-046 |
| 6.6 Click-through Acceptance | Acceptance export: the export (the acceptances, the format, the policy) | TC-SA-22-06-047 |
| 6.6 Click-through Acceptance | Audit logging of the click-through acceptance | TC-SA-22-06-048 |
| 6.6 Click-through Acceptance | Rule: the acceptance is the agreement (the acceptance, the user, the policy, the date); the acceptance is the consent | TC-SA-22-06-041 |
| 6.6 Click-through Acceptance | Rule: the user is the acceptor (the user, the name, the acceptance); the user is the party | TC-SA-22-06-042 |
| 6.6 Click-through Acceptance | Rule: the policy is the document (the policy, the name, the date); the policy is the terms | TC-SA-22-06-043 |
| 6.6 Click-through Acceptance | Rule: the acceptance status is the state (the accepted, the not-accepted); the status is the control | TC-SA-22-06-044 |
| 6.6 Click-through Acceptance | Rule: the policies are accepted (the acceptances, the users, the policies, the dates); the agreement is managed | TC-SA-22-06-046 |
| 6.6 Click-through Acceptance | Rule: click-through acceptance is audit-logged with the acceptance, user, and timestamp | TC-SA-22-06-048 |
| 6.7 Version Control for Policies | Version: the version (the version, the policy, the change, the date) | TC-SA-22-06-049 |
| 6.7 Version Control for Policies | Policy: the policy (the policy, the name, the date) | TC-SA-22-06-050 |
| 6.7 Version Control for Policies | Version change: the change (the change of the version, the edit, the date) | TC-SA-22-06-051 |
| 6.7 Version Control for Policies | Version number: the number (the number of the version, the sequence) | TC-SA-22-06-052 |
| 6.7 Version Control for Policies | Version status: the status (the active, the archived) | TC-SA-22-06-053 |
| 6.7 Version Control for Policies | Version count: the count (the count of the versions) | TC-SA-22-06-054 |
| 6.7 Version Control for Policies | Version view: the view (the versions, the policies, the changes, the dates) | TC-SA-22-06-055 |
| 6.7 Version Control for Policies | Audit logging of the policy version control | TC-SA-22-06-056 |
| 6.7 Version Control for Policies | Rule: the version is the history (the version, the policy, the change, the date); the version is the record | TC-SA-22-06-049 |
| 6.7 Version Control for Policies | Rule: the policy is the document (the policy, the name, the date); the policy is the terms | TC-SA-22-06-050 |
| 6.7 Version Control for Policies | Rule: the version change is the edit (the change of the version, the edit, the date); the change is the modification | TC-SA-22-06-051 |
| 6.7 Version Control for Policies | Rule: the version status is the state (the active, the archived); the status is the control | TC-SA-22-06-053 |
| 6.7 Version Control for Policies | Rule: the policies are versioned (the versions, the policies, the changes, the dates); the history is managed | TC-SA-22-06-055 |
| 6.7 Version Control for Policies | Rule: policy version control is audit-logged with the version, policy, and timestamp | TC-SA-22-06-056 |
| 6.8 Notification of Policy Changes | Notification: the notification (the notification, the policy, the change, the date) | TC-SA-22-06-057 |
| 6.8 Notification of Policy Changes | Policy: the policy (the policy, the name, the date) | TC-SA-22-06-058 |
| 6.8 Notification of Policy Changes | Change: the change (the change of the policy, the edit, the date) | TC-SA-22-06-059 |
| 6.8 Notification of Policy Changes | Notification status: the status (the sent, the read, the acknowledged) | TC-SA-22-06-060 |
| 6.8 Notification of Policy Changes | Notification count: the count (the count of the notifications) | TC-SA-22-06-061 |
| 6.8 Notification of Policy Changes | Notification view: the view (the notifications, the policies, the changes, the dates) | TC-SA-22-06-062 |
| 6.8 Notification of Policy Changes | Notification export: the export (the notifications, the format, the policy) | TC-SA-22-06-063 |
| 6.8 Notification of Policy Changes | Audit logging of the policy change notification | TC-SA-22-06-064 |
| 6.8 Notification of Policy Changes | Rule: the notification is the update (the notification, the policy, the change, the date); the notification is the notice | TC-SA-22-06-057 |
| 6.8 Notification of Policy Changes | Rule: the policy is the document (the policy, the name, the date); the policy is the terms | TC-SA-22-06-058 |
| 6.8 Notification of Policy Changes | Rule: the change is the edit (the change of the policy, the edit, the date); the change is the modification | TC-SA-22-06-059 |
| 6.8 Notification of Policy Changes | Rule: the notification status is the state (the sent, the read, the acknowledged); the status is the control | TC-SA-22-06-060 |
| 6.8 Notification of Policy Changes | Rule: the users are informed (the notifications, the policies, the changes, the dates); the update is managed | TC-SA-22-06-062 |
| 6.8 Notification of Policy Changes | Rule: policy change notification is audit-logged with the notification, policy, and timestamp | TC-SA-22-06-064 |

## 6.1 Terms of Service

### TC-SA-22-06-001 — Terms: the terms (the terms, the clause, the date); the terms are the contract
**Type:** Positive
**Covers:** 6.1 → Terms: the terms (the terms, the clause, the date); Rule: the terms are the agreement (the terms, the clause, the date); the terms are the contract
**Preconditions:** Super Admin is logged in; the terms of service exist.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Terms of Service.
2. Configure the terms: the terms (the terms, the clause, the date) — verify the terms are the agreement.
3. Verify the terms show the clause and the date.
4. Verify the terms are published and visible to users at signup and on the platform.
**Expected Result:** The terms are configured — the terms, the clause, and the date are the contract.
**Priority:** Critical

### TC-SA-22-06-002 — Clause: the clause (the clause of the terms, the text, the date); the clause is the provision
**Type:** Positive
**Covers:** 6.1 → Clause: the clause (the clause of the terms, the text, the date); Rule: the clause is the rule (the clause of the terms, the text, the date); the clause is the provision
**Preconditions:** The terms of service contain multiple clauses.
**Steps:**
1. Edit the clause: the clause (the clause of the terms, the text, the date) — verify the clause is the rule.
2. Verify the clause shows the text and the date.
3. Verify each clause is individually editable and ordered correctly.
**Expected Result:** The clause is edited — the clause of the terms, the text, and the date are the provision.
**Priority:** High

### TC-SA-22-06-003 — Terms version: the version (the version of the terms, the number, the date); the version is the revision
**Type:** Positive
**Covers:** 6.1 → Terms version: the version (the version of the terms, the number, the date); Rule: the terms version is the iteration (the version of the terms, the number, the date); the version is the revision
**Preconditions:** Multiple versions of the terms exist.
**Steps:**
1. View the terms version: the version (the version of the terms, the number, the date) — verify the terms version is the iteration.
2. Verify the version shows the number and the date.
3. Verify publishing a new version increments the version number and preserves the prior version.
**Expected Result:** The terms version is shown — the version of the terms, the number, and the date are the revision.
**Priority:** High

### TC-SA-22-06-004 — Terms status: the status (the active, the archived); the status is the control
**Type:** Edge
**Covers:** 6.1 → Terms status: the status (the active, the archived); Rule: the terms status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived terms versions exist; a scenario where the only active terms version is archived (no-active-terms edge) is also prepared.
**Steps:**
1. View the terms status: the status (the active, the archived) — verify the terms status is the state.
2. Verify the current terms show active and prior versions show archived.
3. Attempt to archive the only active version — verify the system blocks it (or forces a replacement active version first); the platform never has zero active terms of service.
**Expected Result:** The terms status is shown — the active and the archived are the control; the platform always has exactly one active terms of service.
**Priority:** High

### TC-SA-22-06-005 — Terms count: the count (the count of the clauses); the count is the measure
**Type:** Positive
**Covers:** 6.1 → Terms count: the count (the count of the clauses)
**Preconditions:** The terms of service contain multiple clauses.
**Steps:**
1. View the terms count: the count (the count of the clauses) — verify the count is the measure.
2. Verify the count matches the actual number of clauses.
3. Add a new clause — verify the count increments.
**Expected Result:** The terms count is shown — the count of the clauses is the measure.
**Priority:** High

### TC-SA-22-06-006 — Terms view: the view (the terms, the clauses, the versions, the dates); the agreement is managed
**Type:** Positive
**Covers:** 6.1 → Terms view: the view (the terms, the clauses, the versions, the dates); Rule: the terms are provided (the terms, the clauses, the versions, the dates); the agreement is managed
**Preconditions:** Multiple terms versions exist.
**Steps:**
1. View the terms: the view (the terms, the clauses, the versions, the dates) — verify the terms are provided.
2. Verify each version shows the clauses and the dates.
3. Verify the agreement is managed (view, edit, publish, archive).
**Expected Result:** The terms are viewed — the terms, the clauses, the versions, and the dates are visible; the agreement is managed.
**Priority:** High

### TC-SA-22-06-007 — Terms export: the export (the terms, the format, the version); the export is the record
**Type:** Edge
**Covers:** 6.1 → Terms export: the export (the terms, the format, the version)
**Preconditions:** Terms versions exist; a version with no clauses (empty-version export edge) is also prepared.
**Steps:**
1. Export the terms: the export (the terms, the format, the version) — verify the export is the record.
2. Verify the export contains all clauses of the selected version in the selected format.
3. Export the empty version — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The terms are exported — the terms, the format, and the version are the record; empty-version exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-008 — Terms of service configuration is audit-logged with the terms, version, and timestamp
**Type:** Positive
**Covers:** 6.1 → Audit logging of the terms of service configuration; Rule: terms of service configuration is audit-logged with the terms, version, and timestamp
**Preconditions:** Super Admin has configured the terms of service.
**Steps:**
1. Open the audit trail and filter by "terms of service".
2. Verify entries show the terms, the version, and the timestamp.
**Expected Result:** The terms of service configuration is audit-logged with the terms, version, and timestamp.
**Priority:** Critical

## 6.2 Privacy Policy

### TC-SA-22-06-009 — Policy: the policy (the policy, the clause, the date); the policy is the promise
**Type:** Positive
**Covers:** 6.2 → Policy: the policy (the policy, the clause, the date); Rule: the policy is the commitment (the policy, the clause, the date); the policy is the promise
**Preconditions:** Super Admin is logged in; the privacy policy exists.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Privacy Policy.
2. Configure the policy: the policy (the policy, the clause, the date) — verify the policy is the commitment.
3. Verify the policy shows the clause and the date.
4. Verify the privacy policy is published and visible to users.
**Expected Result:** The policy is configured — the policy, the clause, and the date are the promise.
**Priority:** Critical

### TC-SA-22-06-010 — Clause: the clause (the clause of the policy, the text, the date); the clause is the provision
**Type:** Positive
**Covers:** 6.2 → Clause: the clause (the clause of the policy, the text, the date); Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision
**Preconditions:** The privacy policy contains multiple clauses.
**Steps:**
1. Edit the clause: the clause (the clause of the policy, the text, the date) — verify the clause is the rule.
2. Verify the clause shows the text and the date.
3. Verify each clause is individually editable and ordered correctly.
**Expected Result:** The clause is edited — the clause of the policy, the text, and the date are the provision.
**Priority:** High

### TC-SA-22-06-011 — Policy version: the version (the version of the policy, the number, the date); the version is the revision
**Type:** Positive
**Covers:** 6.2 → Policy version: the version (the version of the policy, the number, the date); Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision
**Preconditions:** Multiple versions of the privacy policy exist.
**Steps:**
1. View the policy version: the version (the version of the policy, the number, the date) — verify the policy version is the iteration.
2. Verify the version shows the number and the date.
3. Verify publishing a new version increments the version number and preserves the prior version.
**Expected Result:** The policy version is shown — the version of the policy, the number, and the date are the revision.
**Priority:** High

### TC-SA-22-06-012 — Policy status: the status (the active, the archived); the status is the control
**Type:** Edge
**Covers:** 6.2 → Policy status: the status (the active, the archived); Rule: the policy status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived privacy policy versions exist; a scenario where the only active version is archived (no-active-policy edge) is also prepared.
**Steps:**
1. View the policy status: the status (the active, the archived) — verify the policy status is the state.
2. Verify the current policy shows active and prior versions show archived.
3. Attempt to archive the only active version — verify the system blocks it (or forces a replacement active version first); the platform never has zero active privacy policies.
**Expected Result:** The policy status is shown — the active and the archived are the control; the platform always has exactly one active privacy policy.
**Priority:** High

### TC-SA-22-06-013 — Policy count: the count (the count of the clauses); the count is the measure
**Type:** Positive
**Covers:** 6.2 → Policy count: the count (the count of the clauses)
**Preconditions:** The privacy policy contains multiple clauses.
**Steps:**
1. View the policy count: the count (the count of the clauses) — verify the count is the measure.
2. Verify the count matches the actual number of clauses.
3. Add a new clause — verify the count increments.
**Expected Result:** The policy count is shown — the count of the clauses is the measure.
**Priority:** High

### TC-SA-22-06-014 — Policy view: the view (the policies, the clauses, the versions, the dates); the commitment is managed
**Type:** Positive
**Covers:** 6.2 → Policy view: the view (the policies, the clauses, the versions, the dates); Rule: the policy is provided (the policies, the clauses, the versions, the dates); the commitment is managed
**Preconditions:** Multiple privacy policy versions exist.
**Steps:**
1. View the policies: the view (the policies, the clauses, the versions, the dates) — verify the policy is provided.
2. Verify each version shows the clauses and the dates.
3. Verify the commitment is managed (view, edit, publish, archive).
**Expected Result:** The policies are viewed — the policies, the clauses, the versions, and the dates are visible; the commitment is managed.
**Priority:** High

### TC-SA-22-06-015 — Policy export: the export (the policies, the format, the version); the export is the record
**Type:** Edge
**Covers:** 6.2 → Policy export: the export (the policies, the format, the version)
**Preconditions:** Privacy policy versions exist; a version with no clauses (empty-version export edge) is also prepared.
**Steps:**
1. Export the policies: the export (the policies, the format, the version) — verify the export is the record.
2. Verify the export contains all clauses of the selected version in the selected format.
3. Export the empty version — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The policies are exported — the policies, the format, and the version are the record; empty-version exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-016 — Privacy policy configuration is audit-logged with the policy, version, and timestamp
**Type:** Positive
**Covers:** 6.2 → Audit logging of the privacy policy configuration; Rule: privacy policy configuration is audit-logged with the policy, version, and timestamp
**Preconditions:** Super Admin has configured the privacy policy.
**Steps:**
1. Open the audit trail and filter by "privacy policy".
2. Verify entries show the policy, the version, and the timestamp.
**Expected Result:** The privacy policy configuration is audit-logged with the policy, version, and timestamp.
**Priority:** Critical

## 6.3 Refund Policy

### TC-SA-22-06-017 — Policy: the policy (the policy, the clause, the date); the policy is the commitment
**Type:** Positive
**Covers:** 6.3 → Policy: the policy (the policy, the clause, the date); Rule: the policy is the rule (the policy, the clause, the date); the policy is the commitment
**Preconditions:** Super Admin is logged in; the refund policy exists.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Refund Policy.
2. Configure the policy: the policy (the policy, the clause, the date) — verify the policy is the rule.
3. Verify the policy shows the clause and the date.
4. Verify the refund policy is published and visible to users.
**Expected Result:** The policy is configured — the policy, the clause, and the date are the commitment.
**Priority:** Critical

### TC-SA-22-06-018 — Clause: the clause (the clause of the policy, the text, the date); the clause is the detail
**Type:** Positive
**Covers:** 6.3 → Clause: the clause (the clause of the policy, the text, the date); Rule: the clause is the provision (the clause of the policy, the text, the date); the clause is the detail
**Preconditions:** The refund policy contains multiple clauses.
**Steps:**
1. Edit the clause: the clause (the clause of the policy, the text, the date) — verify the clause is the provision.
2. Verify the clause shows the text and the date.
3. Verify each clause is individually editable and ordered correctly.
**Expected Result:** The clause is edited — the clause of the policy, the text, and the date are the detail.
**Priority:** High

### TC-SA-22-06-019 — Policy version: the version (the version of the policy, the number, the date); the version is the revision
**Type:** Positive
**Covers:** 6.3 → Policy version: the version (the version of the policy, the number, the date); Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision
**Preconditions:** Multiple versions of the refund policy exist.
**Steps:**
1. View the policy version: the version (the version of the policy, the number, the date) — verify the policy version is the iteration.
2. Verify the version shows the number and the date.
3. Verify publishing a new version increments the version number and preserves the prior version.
**Expected Result:** The policy version is shown — the version of the policy, the number, and the date are the revision.
**Priority:** High

### TC-SA-22-06-020 — Policy status: the status (the active, the archived); the status is the control
**Type:** Edge
**Covers:** 6.3 → Policy status: the status (the active, the archived); Rule: the policy status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived refund policy versions exist; a scenario where the only active version is archived (no-active-policy edge) is also prepared.
**Steps:**
1. View the policy status: the status (the active, the archived) — verify the policy status is the state.
2. Verify the current policy shows active and prior versions show archived.
3. Attempt to archive the only active version — verify the system blocks it (or forces a replacement active version first); the platform never has zero active refund policies.
**Expected Result:** The policy status is shown — the active and the archived are the control; the platform always has exactly one active refund policy.
**Priority:** High

### TC-SA-22-06-021 — Policy count: the count (the count of the clauses); the count is the measure
**Type:** Positive
**Covers:** 6.3 → Policy count: the count (the count of the clauses)
**Preconditions:** The refund policy contains multiple clauses.
**Steps:**
1. View the policy count: the count (the count of the clauses) — verify the count is the measure.
2. Verify the count matches the actual number of clauses.
3. Add a new clause — verify the count increments.
**Expected Result:** The policy count is shown — the count of the clauses is the measure.
**Priority:** High

### TC-SA-22-06-022 — Policy view: the view (the policies, the clauses, the versions, the dates); the rule is managed
**Type:** Positive
**Covers:** 6.3 → Policy view: the view (the policies, the clauses, the versions, the dates); Rule: the policy is provided (the policies, the clauses, the versions, the dates); the rule is managed
**Preconditions:** Multiple refund policy versions exist.
**Steps:**
1. View the policies: the view (the policies, the clauses, the versions, the dates) — verify the policy is provided.
2. Verify each version shows the clauses and the dates.
3. Verify the rule is managed (view, edit, publish, archive).
**Expected Result:** The policies are viewed — the policies, the clauses, the versions, and the dates are visible; the rule is managed.
**Priority:** High

### TC-SA-22-06-023 — Policy export: the export (the policies, the format, the version); the export is the record
**Type:** Edge
**Covers:** 6.3 → Policy export: the export (the policies, the format, the version)
**Preconditions:** Refund policy versions exist; a version with no clauses (empty-version export edge) is also prepared.
**Steps:**
1. Export the policies: the export (the policies, the format, the version) — verify the export is the record.
2. Verify the export contains all clauses of the selected version in the selected format.
3. Export the empty version — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The policies are exported — the policies, the format, and the version are the record; empty-version exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-024 — Refund policy configuration is audit-logged with the policy, version, and timestamp
**Type:** Positive
**Covers:** 6.3 → Audit logging of the refund policy configuration; Rule: refund policy configuration is audit-logged with the policy, version, and timestamp
**Preconditions:** Super Admin has configured the refund policy.
**Steps:**
1. Open the audit trail and filter by "refund policy".
2. Verify entries show the policy, the version, and the timestamp.
**Expected Result:** The refund policy configuration is audit-logged with the policy, version, and timestamp.
**Priority:** Critical

## 6.4 Acceptable Use Policy

### TC-SA-22-06-025 — Policy: the policy (the policy, the clause, the date); the policy is the limit
**Type:** Positive
**Covers:** 6.4 → Policy: the policy (the policy, the clause, the date); Rule: the policy is the boundary (the policy, the clause, the date); the policy is the limit
**Preconditions:** Super Admin is logged in; the acceptable use policy exists.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Acceptable Use Policy.
2. Configure the policy: the policy (the policy, the clause, the date) — verify the policy is the boundary.
3. Verify the policy shows the clause and the date.
4. Verify the acceptable use policy is published and visible to users.
**Expected Result:** The policy is configured — the policy, the clause, and the date are the limit.
**Priority:** Critical

### TC-SA-22-06-026 — Clause: the clause (the clause of the policy, the text, the date); the clause is the provision
**Type:** Positive
**Covers:** 6.4 → Clause: the clause (the clause of the policy, the text, the date); Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision
**Preconditions:** The acceptable use policy contains multiple clauses.
**Steps:**
1. Edit the clause: the clause (the clause of the policy, the text, the date) — verify the clause is the rule.
2. Verify the clause shows the text and the date.
3. Verify each clause is individually editable and ordered correctly.
**Expected Result:** The clause is edited — the clause of the policy, the text, and the date are the provision.
**Priority:** High

### TC-SA-22-06-027 — Policy version: the version (the version of the policy, the number, the date); the version is the revision
**Type:** Positive
**Covers:** 6.4 → Policy version: the version (the version of the policy, the number, the date); Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision
**Preconditions:** Multiple versions of the acceptable use policy exist.
**Steps:**
1. View the policy version: the version (the version of the policy, the number, the date) — verify the policy version is the iteration.
2. Verify the version shows the number and the date.
3. Verify publishing a new version increments the version number and preserves the prior version.
**Expected Result:** The policy version is shown — the version of the policy, the number, and the date are the revision.
**Priority:** High

### TC-SA-22-06-028 — Policy status: the status (the active, the archived); the status is the control
**Type:** Edge
**Covers:** 6.4 → Policy status: the status (the active, the archived); Rule: the policy status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived acceptable use policy versions exist; a scenario where the only active version is archived (no-active-policy edge) is also prepared.
**Steps:**
1. View the policy status: the status (the active, the archived) — verify the policy status is the state.
2. Verify the current policy shows active and prior versions show archived.
3. Attempt to archive the only active version — verify the system blocks it (or forces a replacement active version first); the platform never has zero active acceptable use policies.
**Expected Result:** The policy status is shown — the active and the archived are the control; the platform always has exactly one active acceptable use policy.
**Priority:** High

### TC-SA-22-06-029 — Policy count: the count (the count of the clauses); the count is the measure
**Type:** Positive
**Covers:** 6.4 → Policy count: the count (the count of the clauses)
**Preconditions:** The acceptable use policy contains multiple clauses.
**Steps:**
1. View the policy count: the count (the count of the clauses) — verify the count is the measure.
2. Verify the count matches the actual number of clauses.
3. Add a new clause — verify the count increments.
**Expected Result:** The policy count is shown — the count of the clauses is the measure.
**Priority:** High

### TC-SA-22-06-030 — Policy view: the view (the policies, the clauses, the versions, the dates); the boundary is managed
**Type:** Positive
**Covers:** 6.4 → Policy view: the view (the policies, the clauses, the versions, the dates); Rule: the policy is provided (the policies, the clauses, the versions, the dates); the boundary is managed
**Preconditions:** Multiple acceptable use policy versions exist.
**Steps:**
1. View the policies: the view (the policies, the clauses, the versions, the dates) — verify the policy is provided.
2. Verify each version shows the clauses and the dates.
3. Verify the boundary is managed (view, edit, publish, archive).
**Expected Result:** The policies are viewed — the policies, the clauses, the versions, and the dates are visible; the boundary is managed.
**Priority:** High

### TC-SA-22-06-031 — Policy export: the export (the policies, the format, the version); the export is the record
**Type:** Edge
**Covers:** 6.4 → Policy export: the export (the policies, the format, the version)
**Preconditions:** Acceptable use policy versions exist; a version with no clauses (empty-version export edge) is also prepared.
**Steps:**
1. Export the policies: the export (the policies, the format, the version) — verify the export is the record.
2. Verify the export contains all clauses of the selected version in the selected format.
3. Export the empty version — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The policies are exported — the policies, the format, and the version are the record; empty-version exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-032 — Acceptable use policy configuration is audit-logged with the policy, version, and timestamp
**Type:** Positive
**Covers:** 6.4 → Audit logging of the acceptable use policy configuration; Rule: acceptable use policy configuration is audit-logged with the policy, version, and timestamp
**Preconditions:** Super Admin has configured the acceptable use policy.
**Steps:**
1. Open the audit trail and filter by "acceptable use policy".
2. Verify entries show the policy, the version, and the timestamp.
**Expected Result:** The acceptable use policy configuration is audit-logged with the policy, version, and timestamp.
**Priority:** Critical

## 6.5 Cookie Policy

### TC-SA-22-06-033 — Policy: the policy (the policy, the clause, the date); the policy is the notice
**Type:** Positive
**Covers:** 6.5 → Policy: the policy (the policy, the clause, the date); Rule: the policy is the disclosure (the policy, the clause, the date); the policy is the notice
**Preconditions:** Super Admin is logged in; the cookie policy exists.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Cookie Policy.
2. Configure the policy: the policy (the policy, the clause, the date) — verify the policy is the disclosure.
3. Verify the policy shows the clause and the date.
4. Verify the cookie policy is published and visible to users (including in the cookie banner).
**Expected Result:** The policy is configured — the policy, the clause, and the date are the notice.
**Priority:** Critical

### TC-SA-22-06-034 — Clause: the clause (the clause of the policy, the text, the date); the clause is the provision
**Type:** Positive
**Covers:** 6.5 → Clause: the clause (the clause of the policy, the text, the date); Rule: the clause is the rule (the clause of the policy, the text, the date); the clause is the provision
**Preconditions:** The cookie policy contains multiple clauses.
**Steps:**
1. Edit the clause: the clause (the clause of the policy, the text, the date) — verify the clause is the rule.
2. Verify the clause shows the text and the date.
3. Verify each clause is individually editable and ordered correctly.
**Expected Result:** The clause is edited — the clause of the policy, the text, and the date are the provision.
**Priority:** High

### TC-SA-22-06-035 — Policy version: the version (the version of the policy, the number, the date); the version is the revision
**Type:** Positive
**Covers:** 6.5 → Policy version: the version (the version of the policy, the number, the date); Rule: the policy version is the iteration (the version of the policy, the number, the date); the version is the revision
**Preconditions:** Multiple versions of the cookie policy exist.
**Steps:**
1. View the policy version: the version (the version of the policy, the number, the date) — verify the policy version is the iteration.
2. Verify the version shows the number and the date.
3. Verify publishing a new version increments the version number and preserves the prior version.
**Expected Result:** The policy version is shown — the version of the policy, the number, and the date are the revision.
**Priority:** High

### TC-SA-22-06-036 — Policy status: the status (the active, the archived); the status is the control
**Type:** Edge
**Covers:** 6.5 → Policy status: the status (the active, the archived); Rule: the policy status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived cookie policy versions exist; a scenario where the only active version is archived (no-active-policy edge) is also prepared.
**Steps:**
1. View the policy status: the status (the active, the archived) — verify the policy status is the state.
2. Verify the current policy shows active and prior versions show archived.
3. Attempt to archive the only active version — verify the system blocks it (or forces a replacement active version first); the platform never has zero active cookie policies.
**Expected Result:** The policy status is shown — the active and the archived are the control; the platform always has exactly one active cookie policy.
**Priority:** High

### TC-SA-22-06-037 — Policy count: the count (the count of the clauses); the count is the measure
**Type:** Positive
**Covers:** 6.5 → Policy count: the count (the count of the clauses)
**Preconditions:** The cookie policy contains multiple clauses.
**Steps:**
1. View the policy count: the count (the count of the clauses) — verify the count is the measure.
2. Verify the count matches the actual number of clauses.
3. Add a new clause — verify the count increments.
**Expected Result:** The policy count is shown — the count of the clauses is the measure.
**Priority:** High

### TC-SA-22-06-038 — Policy view: the view (the policies, the clauses, the versions, the dates); the disclosure is managed
**Type:** Positive
**Covers:** 6.5 → Policy view: the view (the policies, the clauses, the versions, the dates); Rule: the policy is provided (the policies, the clauses, the versions, the dates); the disclosure is managed
**Preconditions:** Multiple cookie policy versions exist.
**Steps:**
1. View the policies: the view (the policies, the clauses, the versions, the dates) — verify the policy is provided.
2. Verify each version shows the clauses and the dates.
3. Verify the disclosure is managed (view, edit, publish, archive).
**Expected Result:** The policies are viewed — the policies, the clauses, the versions, and the dates are visible; the disclosure is managed.
**Priority:** High

### TC-SA-22-06-039 — Policy export: the export (the policies, the format, the version); the export is the record
**Type:** Edge
**Covers:** 6.5 → Policy export: the export (the policies, the format, the version)
**Preconditions:** Cookie policy versions exist; a version with no clauses (empty-version export edge) is also prepared.
**Steps:**
1. Export the policies: the export (the policies, the format, the version) — verify the export is the record.
2. Verify the export contains all clauses of the selected version in the selected format.
3. Export the empty version — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The policies are exported — the policies, the format, and the version are the record; empty-version exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-040 — Cookie policy configuration is audit-logged with the policy, version, and timestamp
**Type:** Positive
**Covers:** 6.5 → Audit logging of the cookie policy configuration; Rule: cookie policy configuration is audit-logged with the policy, version, and timestamp
**Preconditions:** Super Admin has configured the cookie policy.
**Steps:**
1. Open the audit trail and filter by "cookie policy".
2. Verify entries show the policy, the version, and the timestamp.
**Expected Result:** The cookie policy configuration is audit-logged with the policy, version, and timestamp.
**Priority:** Critical

## 6.6 Click-through Acceptance

### TC-SA-22-06-041 — Acceptance: the acceptance (the acceptance, the user, the policy, the date); the acceptance is the consent
**Type:** Positive
**Covers:** 6.6 → Acceptance: the acceptance (the acceptance, the user, the policy, the date); Rule: the acceptance is the agreement (the acceptance, the user, the policy, the date); the acceptance is the consent
**Preconditions:** Super Admin is logged in; a user has accepted a policy via click-through.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Click-through Acceptance.
2. Record the acceptance: the acceptance (the acceptance, the user, the policy, the date) — verify the acceptance is the agreement.
3. Verify the acceptance shows the user, the policy, and the date.
4. Verify the acceptance is captured only when the user actively clicks to accept (no pre-ticked box, no implied consent).
**Expected Result:** The acceptance is recorded — the acceptance, the user, the policy, and the date are the consent.
**Priority:** Critical

### TC-SA-22-06-042 — User: the user (the user, the name, the acceptance); the user is the party
**Type:** Positive
**Covers:** 6.6 → User: the user (the user, the name, the acceptance); Rule: the user is the acceptor (the user, the name, the acceptance); the user is the party
**Preconditions:** Multiple users have acceptances.
**Steps:**
1. Select the user: the user (the user, the name, the acceptance) — verify the user is the acceptor.
2. Verify the user shows the name and the acceptance.
3. Verify each acceptance is tied to exactly one user account.
**Expected Result:** The user is selected — the user, the name, and the acceptance are the party.
**Priority:** High

### TC-SA-22-06-043 — Policy: the policy (the policy, the name, the date); the policy is the terms
**Type:** Positive
**Covers:** 6.6 → Policy: the policy (the policy, the name, the date); Rule: the policy is the document (the policy, the name, the date); the policy is the terms
**Preconditions:** Multiple policies require click-through acceptance.
**Steps:**
1. Select the policy: the policy (the policy, the name, the date) — verify the policy is the document.
2. Verify the policy shows the name and the date.
3. Verify acceptances can be filtered by policy.
**Expected Result:** The policy is selected — the policy, the name, and the date are the terms.
**Priority:** High

### TC-SA-22-06-044 — Acceptance status: the status (the accepted, the not-accepted); the status is the control
**Type:** Edge
**Covers:** 6.6 → Acceptance status: the status (the accepted, the not-accepted); Rule: the acceptance status is the state (the accepted, the not-accepted); the status is the control
**Preconditions:** Accepted and not-accepted users exist; a user who has not accepted the newly updated policy (stale-acceptance edge) is also prepared.
**Steps:**
1. View the acceptance status: the status (the accepted, the not-accepted) — verify the acceptance status is the state.
2. Verify a user who clicked accept shows accepted.
3. Check the user with the stale acceptance — verify they show not-accepted for the new version and are prompted to re-accept before continuing (an old-version acceptance is never treated as valid for the new version).
**Expected Result:** The acceptance status is shown — the accepted and the not-accepted are the control; policy updates always require fresh acceptance.
**Priority:** High

### TC-SA-22-06-045 — Acceptance count: the count (the count of the acceptances); the count is the measure
**Type:** Positive
**Covers:** 6.6 → Acceptance count: the count (the count of the acceptances)
**Preconditions:** Multiple acceptances exist.
**Steps:**
1. View the acceptance count: the count (the count of the acceptances) — verify the count is the measure.
2. Verify the count matches the actual number of acceptances.
3. Record a new acceptance — verify the count increments.
**Expected Result:** The acceptance count is shown — the count of the acceptances is the measure.
**Priority:** High

### TC-SA-22-06-046 — Acceptance view: the view (the acceptances, the users, the policies, the dates); the agreement is managed
**Type:** Positive
**Covers:** 6.6 → Acceptance view: the view (the acceptances, the users, the policies, the dates); Rule: the policies are accepted (the acceptances, the users, the policies, the dates); the agreement is managed
**Preconditions:** Multiple acceptances exist.
**Steps:**
1. View the acceptances: the view (the acceptances, the users, the policies, the dates) — verify the policies are accepted.
2. Verify each acceptance shows the user, the policy, and the date.
3. Verify the agreement is managed (view, track, re-prompt).
**Expected Result:** The acceptances are viewed — the acceptances, the users, the policies, and the dates are visible; the agreement is managed.
**Priority:** High

### TC-SA-22-06-047 — Acceptance export: the export (the acceptances, the format, the policy); the export is the record
**Type:** Edge
**Covers:** 6.6 → Acceptance export: the export (the acceptances, the format, the policy)
**Preconditions:** Acceptances exist for multiple policies; a policy with no acceptances (zero-row export edge) is also prepared.
**Steps:**
1. Export the acceptances: the export (the acceptances, the format, the policy) — verify the export is the record.
2. Verify the export contains all acceptances for the selected policy in the selected format.
3. Export the policy with no acceptances — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The acceptances are exported — the acceptances, the format, and the policy are the record; empty-policy exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-048 — Click-through acceptance is audit-logged with the acceptance, user, and timestamp
**Type:** Positive
**Covers:** 6.6 → Audit logging of the click-through acceptance; Rule: click-through acceptance is audit-logged with the acceptance, user, and timestamp
**Preconditions:** A click-through acceptance has been recorded.
**Steps:**
1. Open the audit trail and filter by "click-through acceptance".
2. Verify entries show the acceptance, the user, and the timestamp.
**Expected Result:** The click-through acceptance is audit-logged with the acceptance, user, and timestamp.
**Priority:** Critical

## 6.7 Version Control for Policies

### TC-SA-22-06-049 — Version: the version (the version, the policy, the change, the date); the version is the record
**Type:** Positive
**Covers:** 6.7 → Version: the version (the version, the policy, the change, the date); Rule: the version is the history (the version, the policy, the change, the date); the version is the record
**Preconditions:** Super Admin is logged in; policies with multiple versions exist.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Version Control for Policies.
2. Create the version: the version (the version, the policy, the change, the date) — verify the version is the history.
3. Verify the version shows the policy, the change, and the date.
4. Verify each version is immutable once published (no silent edits to past versions).
**Expected Result:** The version is created — the version, the policy, the change, and the date are the record.
**Priority:** Critical

### TC-SA-22-06-050 — Policy: the policy (the policy, the name, the date); the policy is the terms
**Type:** Positive
**Covers:** 6.7 → Policy: the policy (the policy, the name, the date); Rule: the policy is the document (the policy, the name, the date); the policy is the terms
**Preconditions:** Multiple policies are under version control.
**Steps:**
1. Select the policy: the policy (the policy, the name, the date) — verify the policy is the document.
2. Verify the policy shows the name and the date.
3. Verify each policy's full version history is accessible.
**Expected Result:** The policy is selected — the policy, the name, and the date are the terms.
**Priority:** High

### TC-SA-22-06-051 — Version change: the change (the change of the version, the edit, the date); the change is the modification
**Type:** Positive
**Covers:** 6.7 → Version change: the change (the change of the version, the edit, the date); Rule: the version change is the edit (the change of the version, the edit, the date); the change is the modification
**Preconditions:** A policy version contains multiple changes.
**Steps:**
1. View the version change: the change (the change of the version, the edit, the date) — verify the version change is the edit.
2. Verify the change shows the edit and the date.
3. Verify the change is diffable against the prior version (what changed is visible).
**Expected Result:** The version change is shown — the change of the version, the edit, and the date are the modification.
**Priority:** High

### TC-SA-22-06-052 — Version number: the number (the number of the version, the sequence); the number is the order
**Type:** Edge
**Covers:** 6.7 → Version number: the number (the number of the version, the sequence)
**Preconditions:** A policy with multiple versions exists; a scenario where two editors publish versions simultaneously (concurrent-version edge) is also prepared.
**Steps:**
1. View the version number: the number (the number of the version, the sequence) — verify the number is the sequence.
2. Verify version numbers are sequential with no gaps or duplicates.
3. Trigger the concurrent publish — verify the system serializes the versions (one becomes N, the other N+1); no two versions ever share a number, and no number is skipped.
**Expected Result:** The version number is shown — the number of the version, the sequence, is the order; concurrent publishes never create duplicate or gapped version numbers.
**Priority:** High

### TC-SA-22-06-053 — Version status: the status (the active, the archived); the status is the control
**Type:** Positive
**Covers:** 6.7 → Version status: the status (the active, the archived); Rule: the version status is the state (the active, the archived); the status is the control
**Preconditions:** Active and archived versions exist.
**Steps:**
1. View the version status: the status (the active, the archived) — verify the version status is the state.
2. Verify the current version shows active and prior versions show archived.
3. Verify exactly one version per policy is active at any time.
**Expected Result:** The version status is shown — the active and the archived are the state; exactly one active version per policy.
**Priority:** High

### TC-SA-22-06-054 — Version count: the count (the count of the versions); the count is the measure
**Type:** Positive
**Covers:** 6.7 → Version count: the count (the count of the versions)
**Preconditions:** Multiple policy versions exist.
**Steps:**
1. View the version count: the count (the count of the versions) — verify the count is the measure.
2. Verify the count matches the actual number of versions.
3. Publish a new version — verify the count increments.
**Expected Result:** The version count is shown — the count of the versions is the measure.
**Priority:** High

### TC-SA-22-06-055 — Version view: the view (the versions, the policies, the changes, the dates); the history is managed
**Type:** Positive
**Covers:** 6.7 → Version view: the view (the versions, the policies, the changes, the dates); Rule: the policies are versioned (the versions, the policies, the changes, the dates); the history is managed
**Preconditions:** Multiple policy versions exist.
**Steps:**
1. View the versions: the view (the versions, the policies, the changes, the dates) — verify the policies are versioned.
2. Verify each version shows the policy, the change, and the date.
3. Verify the history is managed (view, compare, restore reference).
**Expected Result:** The versions are viewed — the versions, the policies, the changes, and the dates are visible; the history is managed.
**Priority:** High

### TC-SA-22-06-056 — Policy version control is audit-logged with the version, policy, and timestamp
**Type:** Positive
**Covers:** 6.7 → Audit logging of the policy version control; Rule: policy version control is audit-logged with the version, policy, and timestamp
**Preconditions:** Super Admin has created a policy version.
**Steps:**
1. Open the audit trail and filter by "policy version".
2. Verify entries show the version, the policy, and the timestamp.
**Expected Result:** The policy version control is audit-logged with the version, policy, and timestamp.
**Priority:** Critical

## 6.8 Notification of Policy Changes

### TC-SA-22-06-057 — Notification: the notification (the notification, the policy, the change, the date); the notification is the notice
**Type:** Positive
**Covers:** 6.8 → Notification: the notification (the notification, the policy, the change, the date); Rule: the notification is the update (the notification, the policy, the change, the date); the notification is the notice
**Preconditions:** Super Admin is logged in; a policy has been changed.
**Steps:**
1. Open Data Protection & Compliance → Policies & Agreements → Notification of Policy Changes.
2. Send the notification: the notification (the notification, the policy, the change, the date) — verify the notification is the update.
3. Verify the notification shows the policy, the change, and the date.
4. Verify affected users receive the notification per the documented channel.
**Expected Result:** The notification is sent — the notification, the policy, the change, and the date are the notice.
**Priority:** Critical

### TC-SA-22-06-058 — Policy: the policy (the policy, the name, the date); the policy is the terms
**Type:** Positive
**Covers:** 6.8 → Policy: the policy (the policy, the name, the date); Rule: the policy is the document (the policy, the name, the date); the policy is the terms
**Preconditions:** Notifications exist for multiple policies.
**Steps:**
1. Select the policy: the policy (the policy, the name, the date) — verify the policy is the document.
2. Verify the policy shows the name and the date.
3. Verify notifications can be filtered by policy.
**Expected Result:** The policy is selected — the policy, the name, and the date are the terms.
**Priority:** High

### TC-SA-22-06-059 — Change: the change (the change of the policy, the edit, the date); the change is the modification
**Type:** Positive
**Covers:** 6.8 → Change: the change (the change of the policy, the edit, the date); Rule: the change is the edit (the change of the policy, the edit, the date); the change is the modification
**Preconditions:** A policy change has been notified.
**Steps:**
1. View the change: the change (the change of the policy, the edit, the date) — verify the change is the edit.
2. Verify the change shows the edit and the date.
3. Verify the notification links to the exact changed version (users can see what changed).
**Expected Result:** The change is shown — the change of the policy, the edit, and the date are the modification.
**Priority:** High

### TC-SA-22-06-060 — Notification status: the status (the sent, the read, the acknowledged); the status is the control
**Type:** Edge
**Covers:** 6.8 → Notification status: the status (the sent, the read, the acknowledged); Rule: the notification status is the state (the sent, the read, the acknowledged); the status is the control
**Preconditions:** Notifications with sent, read, and acknowledged statuses exist; a notification that bounces to an invalid email address (delivery-failure edge) is also prepared.
**Steps:**
1. View the notification status: the status (the sent, the read, the acknowledged) — verify the notification status is the state.
2. Verify a delivered notification moves sent → read when opened, → acknowledged when the user confirms.
3. Check the bounced notification — verify the failure is recorded (never silently marked sent-and-delivered); the user is reached via the documented fallback channel or flagged for follow-up.
**Expected Result:** The notification status is shown — the sent, the read, and the acknowledged are the control; delivery failures are never misreported as delivered.
**Priority:** High

### TC-SA-22-06-061 — Notification count: the count (the count of the notifications); the count is the measure
**Type:** Positive
**Covers:** 6.8 → Notification count: the count (the count of the notifications)
**Preconditions:** Multiple notifications exist.
**Steps:**
1. View the notification count: the count (the count of the notifications) — verify the count is the measure.
2. Verify the count matches the actual number of notifications.
3. Send a new notification — verify the count increments.
**Expected Result:** The notification count is shown — the count of the notifications is the measure.
**Priority:** High

### TC-SA-22-06-062 — Notification view: the view (the notifications, the policies, the changes, the dates); the update is managed
**Type:** Positive
**Covers:** 6.8 → Notification view: the view (the notifications, the policies, the changes, the dates); Rule: the users are informed (the notifications, the policies, the changes, the dates); the update is managed
**Preconditions:** Multiple notifications exist.
**Steps:**
1. View the notifications: the view (the notifications, the policies, the changes, the dates) — verify the users are informed.
2. Verify each notification shows the policy, the change, and the date.
3. Verify the update is managed (view, send, track, follow up).
**Expected Result:** The notifications are viewed — the notifications, the policies, the changes, and the dates are visible; the update is managed.
**Priority:** High

### TC-SA-22-06-063 — Notification export: the export (the notifications, the format, the policy); the export is the record
**Type:** Edge
**Covers:** 6.8 → Notification export: the export (the notifications, the format, the policy)
**Preconditions:** Notifications exist for multiple policies; a policy with no notifications (zero-row export edge) is also prepared.
**Steps:**
1. Export the notifications: the export (the notifications, the format, the policy) — verify the export is the record.
2. Verify the export contains all notifications for the selected policy in the selected format.
3. Export the policy with no notifications — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The notifications are exported — the notifications, the format, and the policy are the record; empty-policy exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-06-064 — Policy change notification is audit-logged with the notification, policy, and timestamp
**Type:** Positive
**Covers:** 6.8 → Audit logging of the policy change notification; Rule: policy change notification is audit-logged with the notification, policy, and timestamp
**Preconditions:** A policy change notification has been sent.
**Steps:**
1. Open the audit trail and filter by "policy change notification".
2. Verify entries show the notification, the policy, and the timestamp.
**Expected Result:** The policy change notification is audit-logged with the notification, policy, and timestamp.
**Priority:** Critical
