# MDA Commercial, Engagement, Analytics & Data Ownership Model

**Status:** APPROVED (v1.0) — 2026-09-24
**Scope:** Commercial, engagement and analytical behaviour across MDA; information ownership and cross-domain data flow across the five approved data domains.
**Out of scope (per mandate):** application code, database table design, implementation details for Redis/Object Storage (flagged for CTO approval only).

**Source basis:** full analysis of `Documents/` — super_admin (membership plans, pricing, payment/billing, revenue, financial overview, discounts, affiliate commission config, marketing communication, dashboards, automated reports, custom reporting, data protection, backup/export), student (subscription management, notifications, gamification, social, live sessions, course access, assessment, AI companion, target exam, learning tools, progress analytics), parent (subscription/billing, monitoring, insights, reports, collaboration, communication), affiliate (all 9 modules), training_institute (bulk licensing, billing, analytics), corporate (billing, performance reporting), csr (funding, impact reporting), sponsor (sponsorship, impact reporting).

**Domains:** `identity_billing` · `catalog` · `learning` · `engagement` · `analytics`

---

## 1. Billing & Commercial Process Map

### 1.1 Plan
- **What:** Membership plans of six types — academic (single subject / multi-subject bundle / full grade / custom combo; monthly, quarterly, semi-annual, annual), professional (pay-per-course, fixed-duration or **lifetime**, installments, bundles), skill-path (career track, certification track, monthly all-access over the **live** catalog, premium + mentorship), family (N children, consolidated billing, sibling volume discount tiers), bulk license packages (tiers 10–50 / 51–200 / 201–500 / 500+; custom enterprise), trial/freemium (7-day full-access trial, **no credit card**; freemium = free courses + forum + basic planner + limited AI).
- **Key attributes:** type, features, limits (AI questions/day, downloads/month, concurrent devices), price, period, visibility (visible/hidden) × availability (available/unavailable) — independent toggles.
- **Lifecycle:** `active` / `deactivated`. Deactivation triggers a grace + migration window; existing subscribers are **never dropped**.
- **Owner:** `catalog` (plan definitions, features, limits).
- **Readers:** `identity_billing` (pricing/subscription creation), `analytics` (plan mix reporting).
- **Modifiers:** `catalog` only (Super Admin).

### 1.2 Pricing
- **What:** Price rules per grade / subject / bundle / full-grade / course / skill-path / lifetime, with effective dates, visibility control (item/region/time), multi-currency (INR/USD/EUR, base currency, FX refresh daily/weekly), tax per region (GST/VAT), price history (retained, superseded versions), grandfathering of existing subscriptions at old price.
- **Lifecycle:** `active` / `superseded` (price history).
- **Owner:** `catalog` (price rules, price history).
- **Readers:** `identity_billing` (checkout, renewal amounts), `analytics` (revenue-by-price-point).
- **Modifiers:** `catalog` only.
- **OPEN DECISION (OD-10):** grandfathering duration ("if applicable" in docs) is undefined.

### 1.3 Purchase
- **Flow:** select plan → optional discount code (validate eligibility, expiry, per-user and total-usage limits, single-use) → payment → **subscription activates only on successful payment** → receipt.
- **Variants:**
  - Student: self-purchase; add-on purchases by a child require **parental approval** (auto-approved within a monthly spending limit; above → approval required).
  - Parent: purchase for child (plan/subjects/duration).
  - Institute: bulk purchase → **licenses added to pool immediately on successful payment**.
  - Corporate: seat-based; seat count captured at cycle start.
  - CSR: program agreement + funding schedule. Sponsor: sponsorship agreement (course/content tiers bronze–platinum, or scholarships).
- **Discount codes:** unique string, % or fixed amount, scope (items/plans/courses), per-user limit, total-uses limit, validity window; states `active` / `deactivated` / `expired`.
- **Promotional campaigns:** offer, period, target segment (new/returning/lapsed/high-value), channels (email blast, popup), A/B split with conversion metric; states `scheduled` / `live` / `ended`.
- **Owners:** discount codes & campaigns → `catalog` (offer definitions) with usage counters; the purchase transaction itself → `identity_billing`.
- **OPEN DECISION (OD-11):** whether purchases via an **affiliate** discount code generate affiliate commission (vs link-only attribution) is unspecified.

### 1.4 Subscription
- **What:** plan + subjects + start/end + next renewal date/amount + auto-renew flag.
- **Lifecycle:** `active` / `expiring` / `lapsed`. The student docs explicitly call subscription status **"the single source of truth for access."**
- **Upgrades/add-subjects:** immediate, pay the prorated difference; unused duration transfers on plan change.
- **Family:** one payment, one invoice, per-child progress.
- **Professional installments:** **access granted on first installment**; overdue → reminder → suspension risk.
- **Owner:** `identity_billing`.
- **Readers:** `learning` (access gating for content), `engagement` (renewal/dunning notifications), `analytics` (MRR, churn, health).
- **Modifiers:** `identity_billing` only (state transitions driven by payment events and user/admin actions).
- **OPEN DECISION (OD-12):** installment overdue suspension timing is undefined.

### 1.5 Entitlement / Access
- **Feature limits** enforced per plan (AI Q/day, downloads/month, devices): breach → notification + upgrade prompt; locked content → "Upgrade to unlock".
- **Bulk licenses:** assignment to a student → access immediate; one active license per student; reassignment revokes the previous student; release → access revoked immediately, license returns to pool. Pool counts are **real-time** on assign/release. Entitlement change history is **immutable, append-only**. Usage vs entitlement: warning at a configurable threshold, hard block at entitlement reached.
- **Corporate:** seat count at cycle start governs the invoice; mid-cycle churn does not change the current invoice.
- **Owners:** subscription entitlement → `identity_billing`; license pool/assignment state → `identity_billing` (bulk licenses); per-user consumption counters (downloads used, AI questions used) → `learning` (high-volume writes).
- **OPEN DECISION (OD-13):** where per-user feature-limit counters (AI Q/day, downloads/month) are authoritatively counted — `learning` counters vs `identity_billing` — needs confirmation (this model proposes `learning` as writer, `identity_billing` as policy owner).

### 1.6 Payment
- **Methods:** credit card, debit card, UPI, wallet, bank transfer. Gateway mapping (Stripe/PayPal/local) with per-gateway status monitoring (`active`/`inactive`/`error`).
- **Lifecycle:** `pending` / `successful` / `failed`. Encrypted; receipt on success.
- **Owner:** `identity_billing` (payments, gateway config, transaction ledger).
- **Readers:** `analytics` (payment success/failure trends), `engagement` (payment-failure notifications).
- **OPEN DECISION (OD-14):** bank-transfer success confirmation / reconciliation flow is not detailed.

### 1.7 Renewal
- Auto-renew on/off; charge on renewal date via default payment method; **notification before renewal** (journey example: 3 days; rule says "per platform's lead time").
- Proration = remaining-period daily rate (configurable rounding); upgrade = prorated difference; unused duration transfers on plan change.
- Corporate: proration = seat price / days in cycle × remaining days, **never negative**, no mid-cycle refund for removed seats.
- Sponsor: renewal invoice + tier-change pricing + mid-cycle proration. Bulk licenses: expiry extended from current expiry.
- **Renewal commissions:** referred-subscription renewals pay a recurring commission (test case: 10% of renewal amount); only renewals of **referred** subscriptions are tracked.
- **Owner:** `identity_billing` (renewal execution, invoices). **Readers:** `engagement` (renewal reminders), `analytics` (renewal rates).
- **OPEN DECISION (OD-15):** renewal notification lead time (3 days appears only in a journey example).
- **OPEN DECISION (OD-16):** how many renewal cycles pay affiliate commission, renewal rate vs initial rate, and lapse-then-resubscribe treatment are undefined.

### 1.8 Failure / Dunning
- Retry logic **configurable** (docs example: 3 retries, daily interval, user notified) → after retries fail → **grace period** (length platform-set) → user can fix payment to keep access → **access suspended after grace ends** → reactivation immediate on payment.
- **Natural expiry (no failed payment): access ends at period end, no grace** — asymmetric with failed-renewal grace.
- Lapsed bulk license revokes affected students' access. Enterprise priority-support SLA breach → alert + escalation.
- **Owner:** `identity_billing` (dunning state machine). **Readers:** `engagement` (dunning notifications), `analytics` (payment-failure/churn metrics).
- **OPEN DECISION (OD-17):** retry count/interval and grace-period length are examples, not policy.
- **OPEN DECISION (OD-18):** confirm the intended asymmetry: grace on failed renewal but none on natural expiry.

### 1.9 Refund
- States: `pending` / `approved` / `processed` / `rejected`. Policy conditions (e.g., 7-day window) and limits (partial refunds); approval-gated. Billing adjustments also approval-gated. Corporate issues credit notes.
- **Owner:** `identity_billing`.
- **Downstream effects (must be modelled as events):** refund → subscription state change → access revocation → **affiliate commission clawback** (see OD-19) → analytics correction.
- **OPEN DECISION (OD-19):** refund window value (7 days is an example) and the **affiliate commission clawback/reversal rule are not stated anywhere** (commission states are only pending/earned/paid — no `voided`).
- **OPEN DECISION (OD-20):** downgrade credit rule missing — only "prorated billing adjustment"; no refund/credit of unused value.

### 1.10 Cancellation
- Cancel → **access retained until end of paid period**; optional cancellation reason captured (feeds churn analysis: price/content/support). Auto-renew can be disabled separately (access continues to period end).
- Corporate downgrade blocked if seats exceed target tier cap; effective next cycle.
- **Owner:** `identity_billing`. **Readers:** `engagement` (cancellation confirmation), `analytics` (churn rate + reason).
- **OPEN DECISION (OD-21):** churn-reason collection mechanism (survey vs inference) is unspecified.

### 1.11 Cross-cutting money rules
- Multi-currency INR/USD/EUR with base currency + FX conversion/settlement; tax per region; revenue recognition by source (subscription vs one-time) and period; reconciliation = match transactions vs gateway records (`matched`/`unmatched`/`mismatched`; discrepancy `identified`/`resolved`/`pending`); accrual/settlement tracking (`accrued`/`settled`/`pending`).
- **Owner:** all in `identity_billing` (money and identity stay together).
- **OPEN DECISION (OD-22):** billing currency after mid-cycle FX rate change is unspecified.

---

## 2. Engagement Event Map

### 2.1 Login / Auth events
| Event | Captured | Notes |
|---|---|---|
| Login success/failure | user, timestamp, device | login frequency feeds engagement analytics |
| New-device login | device, location | triggers **critical security alert** (cannot be disabled) |
| Password change | timestamp | critical alert |
| Session idle timeout | e.g., 30 min | auth/session management |

### 2.2 Learning activity events (owner: `learning`)
| Activity | Events |
|---|---|
| Video | start, pause, complete, speed change; position saved per video; status `not started → in progress → complete`; re-watch doesn't revert; cross-device sync |
| Podcast | start, pause, complete per episode; background playback (mobile); download started/completed/deleted (subscription-gated) |
| Quiz | session start, each answer, end; modes timed/untimed/focus; unlimited retakes; per-question correctness; feeds weak-topic identification |
| Exam (adaptive/mock) | start, each answer (adaptive difficulty), end; question states; timer + auto-submit; submission timestamp; mock = single submission per window, readiness score |
| Flashcards / SRS | deck created, card CRUD, study session started, per-card rating (Again/Good/Easy), completed summary; **one SRS interval adjustment per recall**; rating history **immutable** |
| Notes / bookmarks / highlights | create/edit/delete; video-timestamp bookmarks; cross-device sync |
| Study plan (AI) | generated, regenerated, task completed, rescheduled, check-in prompted/acknowledged/adjusted; adherence on-track/behind |
| Target exam | progress updated (real time), countdown viewed, actual result recorded (feeds prediction accuracy) |
| AI companion | question asked, answer shown, doubt resolved/escalated, mood check-in, burnout detected, recommendation shown/acted on |

### 2.3 Notification events (owner: `engagement`)
- **Lifecycle:** triggered → preference evaluation (category on/off, channel per category, critical override) → timing rules (quiet hours, real-time vs daily digest) → channel delivery (in-app / email / push / SMS) → delivery status (`sent → delivered → read/opened`) → click/deep-link → history retention.
- **Events:** sent, delivered, opened, marked read, deleted, cleared, preference changed, push disabled.
- **Critical alerts** (security, subscription status, payout issues) **always real-time, cannot be muted/batched**; non-critical batched into daily digest with quiet hours.
- **Campaigns:** `draft → scheduled → active → completed`; segments; drip sequences (trigger + delay); A/B tests; performance = open/click/conversion rates.
- **OPEN DECISION (OD-23):** no queue/rate-limit/batching/dedup spec for the notification pipeline; notification retention period is "platform-defined" everywhere.
- **OPEN DECISION (OD-24):** whether critical alerts bypass quiet hours is unstated.

### 2.4 Interaction events (owner: `engagement`)
| Area | Events |
|---|---|
| Forum | thread posted/replied/edited/deleted, followed/unfollowed, marked read, upvoted (one per user, reversible, self-vote blocked), marked helpful, solved, reported, moderation outcome (moderation log **immutable**) |
| Study group | created, joined, left, member added/removed, posted, shared, reacted, session scheduled/attended/cancelled; dissolution preserves history per retention policy |
| Live session | calendar viewed, reminder set, joined, admitted (waiting room/late), left (join/leave timestamps), attendance `attended/missed/late/no-show`, raised hand, chat posted, question submitted/upvoted/answered (anonymous still attributable in backend log), poll answered, quiz submitted, whiteboard annotated, breakout assigned/joined/returned, material viewed/downloaded, recording viewed, feedback submitted |
| Resource sharing | shared, unshared, liked, commented, copied (community library) |
| Recognition | reputation awarded, "Helpful Peer"; optional decay over inactivity |
| Parent | alert sent/opened, teacher message sent/delivered, goal proposed/agreed/reviewed/adjusted, reward defined/earned/redeemed, privilege set/unlocked, token earned/spent |
| Affiliate | link/QR generated/copied/regenerated/deleted, click, sign-up attributed, purchase attributed, code created/used, sequence created/sent/delivered/paused, dispute raised/resolved, payout submitted/processed/paid |

### 2.5 Gamification events (owner: `learning` for state, `engagement` for social surfaces)
- **Points/XP:** earned for video completion, quiz pass, exam taken, flashcard study, streak maintenance, quality content, daily goal, peer help, tutor sessions. Per-student **point ledger** (earnings, expiries, balance); values applied at event time, **no retroactive revaluation**. Rewards catalog with point costs; redemption requires sufficient points.
- **Streak:** consecutive days with ≥1 study action; missed day resets **subject to a configured grace rule**; streak protection can preserve a missed day; milestone badges at **7 / 30 / 100 days**; preservation alert "when at risk".
- **Badges:** categories (subject mastery, streak, challenge, top performer, seasonal); awarded once; **revocable** with reason; celebration notification on earn.
- **Leaderboards:** scope class/grade/subject/overall; period weekly/monthly/all-time; metric points/streak/accuracy; anonymous or opt-in; **updated on a schedule, not real time**; period rollover resets period boards.
- **Challenges:** `draft → active → completed`; entry rules, scoring rules, documented tie-break, reward issuance recorded.
- **OPEN DECISION (OD-25):** no concrete XP values anywhere; point expiry policy ("rolling period or none") unspecified.
- **OPEN DECISION (OD-26):** streak rules underspecified — grace mechanics, "at risk" threshold, and which actions count as "a study action" are undefined.
- **OPEN DECISION (OD-27):** student "points" vs parent "digital tokens" — same ledger or separate currencies is undefined.
- **OPEN DECISION (OD-28):** badge revocation — are associated points clawed back? Unstated.

### 2.6 Engagement / drop-off signals
| Signal | Trigger (as documented) |
|---|---|
| Streak break / at risk | missed day (grace rule); alert when "at risk" |
| Gentle nudge | inactivity beyond threshold (not quantified) |
| Re-engagement email | inactivity **7 days / 30 days** (examples) |
| Inactivity alert | **7 days** no activity (configurable) |
| Engagement drop alert | **30%** drop (configurable) |
| Low performance alert | score **< 40%** (configurable) |
| Parent inactivity alert | child inactive for a selectable period |
| Churn | cancelled subscription; reason price/content/support; lost revenue |
| Dormant accounts | account marked dormant; seat may be reclaimable |
| No-shows | enrolled in live session, never joined (distinct from late) |
| Non-participants | eligible but inactive in period (social analytics) |
| Burnout | declining performance + reduced engagement → rest-day suggestion |
| Plan adherence | "behind" → check-in + re-plan suggestion |
- **OPEN DECISION (OD-29):** no single canonical "inactive user" definition (7-day, 30-day, and "configurable" definitions coexist across features).

---

## 3. Analytics Input Map

What must be collected, from which domain, for what analytical purpose.

| # | Information collected | Source domain | Analytical purpose | Freshness |
|---|---|---|---|---|
| A1 | Subscription counts, states, MRR, renewal rates, upgrade/downgrade | `identity_billing` | Revenue dashboard, subscription health, churn | Real-time counts; trends pre-computed |
| A2 | Payment events (pending/successful/failed + reason) | `identity_billing` | Payment success rate, dunning effectiveness | Real-time; trends pre-computed |
| A3 | Refunds, adjustments, credit notes | `identity_billing` | Refund rate, revenue correction | Pre-computed |
| A4 | Commission events (pending/earned/paid), payouts | `identity_billing` (payout ledger) | Commission overview, affiliate performance | Real-time buckets; monthly trends pre-computed |
| A5 | Bulk license seats (total/assigned/expiring) | `identity_billing` | License utilization, 30/60-day expiry alerts | Real-time seat counts; utilization % pre-computed |
| A6 | CSR funding, disbursements, budget burn | `identity_billing` | CSR program health, burn rate, ROI | Real-time; burn pre-computed |
| A7 | Sponsorship spend, cost-per-X | `identity_billing` | Sponsorship ROI | Pre-computed |
| A8 | Plan/price/discount reference data | `catalog` | Revenue by course/plan/region, price elasticity | Static |
| A9 | Content metadata + approval status | `catalog` | Library stats, content performance | Real-time counts |
| A10 | Watch progress, time spent, completion, drop-off timestamps | `learning` | Content completion, drop-off analysis, course quality | Views real-time; completion/drop-off pre-computed |
| A11 | Quiz/exam scores, accuracy, mastery, weak topics | `learning` | Performance analytics, benchmarks, at-risk detection | Real-time current; aggregates pre-computed |
| A12 | XP, streaks, badges, SRS retention predictions | `learning` | Engagement score, habit formation, retention prediction | Pre-computed |
| A13 | DAU/WAU/MAU, login frequency | `learning` events → `analytics` | Engagement dashboard | Pre-computed |
| A14 | Referral clicks, sign-ups, purchases (live feed) | `engagement` | Affiliate funnel (clicks → sign-ups → purchases), conversion rate | **Real-time** (explicitly "as they happen") |
| A15 | Notification sent/delivered/opened/clicked | `engagement` | Campaign performance, open rates, alert response time (median; 7-day unacknowledged cutoff) | Real-time log; stats pre-computed |
| A16 | Campaign/A/B test results | `engagement` | Marketing effectiveness | Pre-computed |
| A17 | Brand impressions, logo placements, audience reach, geo distribution | `engagement` (marketing) | Sponsor brand exposure, reach, ROI | Pre-computed (monthly trend) |
| A18 | Live session attendance, engagement score, quality score | `engagement` | Session quality, instructor performance, no-show analysis | Pre-computed |
| A19 | Forum/group activity, reputation | `engagement` | Social analytics, non-participant lists, community health | Pre-computed |
| A20 | Compliance obligations, cert expiry (30/60/90-day), overdue (30+ days) | `learning` → `analytics` | Corporate compliance score 0–100, 12-month trend | Pre-computed; **15-min refresh** (only explicit freshness SLA) |
| A21 | Learning velocity (courses/month, rolling 30-day) | `learning` → `analytics` | Corporate performance reporting | Pre-computed |
| A22 | Engagement score 0–100 (logins + hours + course starts) | `learning` + `engagement` → `analytics` | Corporate/institute at-risk bands | Pre-computed |
| A23 | Grade-level percentile benchmarks, anonymized industry averages | `analytics` | Student/parent benchmarking, institute benchmarks | Pre-computed |
| A24 | Churned users, dates, reasons (price/content/support) | `identity_billing` + `engagement` → `analytics` | Churn rate, churn impact on revenue | Pre-computed |
| A25 | Acquisition source (organic/referral/affiliate) | `engagement` (attribution) + `identity_billing` | Growth by segment, affiliate ROI | Pre-computed |
| A26 | Cost-per-employee (billing ÷ active seats) | `identity_billing` | Corporate HR monthly report | Pre-computed monthly |
| A27 | Skill gap inventory / coverage matrix | `catalog` (skill catalog) + `learning` (mastery) | Corporate skill-gap reporting, course recommendations | Pre-computed |
| A28 | Support tickets, SLA met/at-risk/breached | **no domain assigned** | Support overview dashboard | Real-time |
| A29 | Uptime (99.9% SLA), component health, errors, incidents | **infrastructure telemetry — outside the 5 domains** | System health dashboard | Real-time |
- **OPEN DECISION (OD-30):** support tickets/SLA data have no home in the 5-domain split (proposed: `engagement`, pending confirmation).
- **OPEN DECISION (OD-31):** infrastructure telemetry is outside the 5-domain split entirely.
- **OPEN DECISION (OD-32):** benchmark data source, population, and refresh cadence are unspecified.
- **OPEN DECISION (OD-33):** engagement score formula weights and band cutoffs are undefined.
- **OPEN DECISION (OD-34):** "active user" definition is inconsistent (30-day corporate, configurable institute, 30-day super admin) — no canonical definition.

---

## 4. Data Ownership Matrix

Legend — **O** = owns (system of record, sole writer) · **R** = reads · **W** = may modify (secondary writer, event-driven) · — = no access.

| Business object | Owner | Reads | May modify |
|---|---|---|---|
| User account (all roles) | `identity_billing` | all four | `identity_billing` |
| Role / permission | `identity_billing` | `identity_billing` (authz) | `identity_billing` |
| Auth token / 2FA / OTP | `identity_billing` | — | `identity_billing` |
| Parent–child link | `identity_billing` | `learning`, `engagement`, `analytics` | `identity_billing` |
| Membership plan | `catalog` | `identity_billing`, `analytics` | `catalog` |
| Price rule / price history | `catalog` | `identity_billing`, `analytics` | `catalog` |
| Discount code (definition) | `catalog` | `identity_billing` (checkout) | `catalog`; usage counters written by `identity_billing` at redemption |
| Promotional campaign (definition) | `catalog` | `engagement` (delivery), `analytics` | `catalog` |
| Course / content metadata | `catalog` | `learning`, `engagement`, `analytics` | `catalog` |
| Skill catalog | `catalog` | `learning`, `analytics` | `catalog` |
| Subscription | `identity_billing` | `learning` (access gate), `engagement` (notifications), `analytics` | `identity_billing` |
| Payment / transaction | `identity_billing` | `analytics`, `engagement` | `identity_billing` |
| Invoice / receipt / credit note | `identity_billing` | `analytics` | `identity_billing` |
| Refund / billing adjustment | `identity_billing` | `analytics`, `engagement` | `identity_billing` |
| Gateway configuration | `identity_billing` | — | `identity_billing` |
| Reconciliation record | `identity_billing` | `analytics` | `identity_billing` |
| Revenue recognition (accrual/settlement) | `identity_billing` | `analytics` | `identity_billing` |
| Bulk license / license pool | `identity_billing` | `analytics` | `identity_billing` (assignment state); entitlement change history append-only |
| CSR program funding / disbursement | `identity_billing` | `analytics` | `identity_billing` |
| Sponsorship agreement / spend | `identity_billing` | `engagement` (placements), `analytics` | `identity_billing` |
| Corporate seat allocation / cost center | `identity_billing` | `analytics` | `identity_billing` |
| Affiliate account / program status / level | `identity_billing` | `engagement`, `analytics` | `identity_billing` |
| Commission event / commission ledger | `identity_billing` | `analytics` | `identity_billing` (state transitions on purchase/renewal/refund events) |
| Payout / payout request / statement | `identity_billing` | `analytics` | `identity_billing` |
| Referral link / QR / campaign link | `engagement` | `analytics` | `engagement` |
| Referral click / sign-up / purchase attribution | `engagement` | `identity_billing` (commission trigger), `analytics` | `engagement` |
| Referred-customer renewal tracking | `engagement` (event) + `identity_billing` (commission) | `analytics` | both, per side |
| Commission dispute | `engagement` | `identity_billing` | `engagement` |
| Marketing automation sequence | `engagement` | `analytics` | `engagement` |
| Notification / delivery record | `engagement` | `analytics` | `engagement` |
| Notification preference | `engagement` | — | `engagement` (user) |
| Campaign send / A/B result | `engagement` | `analytics` | `engagement` |
| Forum thread / post / moderation log | `engagement` | `analytics` | `engagement` (moderation log immutable) |
| Study group / group content | `engagement` | `analytics` | `engagement` |
| Live session / attendance / recording ref | `engagement` | `analytics` | `engagement` |
| Leaderboard (period state) | `engagement` (social boards) / `analytics` (computed) | — | `engagement` on schedule |
| Challenge | `engagement` | `analytics` | `engagement` |
| Watch progress / resume position | `learning` | `analytics` | `learning` |
| Quiz / exam attempt + per-question answers | `learning` | `analytics`, `engagement` (parent alerts) | `learning` |
| SRS card state / rating history | `learning` | `analytics` | `learning` (rating history immutable) |
| XP / point ledger | `learning` | `engagement` (rewards), `analytics` | `learning` |
| Streak state | `learning` | `engagement` (alerts), `analytics` | `learning` |
| Badge / achievement (award state) | `learning` | `engagement` (celebration), `analytics` | `learning` (revocation with reason) |
| Bookmark / note / highlight | `learning` | — | `learning` |
| Study plan (AI) / adherence | `learning` | `analytics` | `learning` |
| Target exam state / prediction | `learning` | `analytics` | `learning` |
| AI companion state (conversations, mood, burnout) | `learning` | — | `learning` |
| Feature-limit counters (AI Q/day, downloads/mo) | **OD-13** (proposed `learning`) | `identity_billing` (policy) | `learning` |
| Pre-computed aggregates (all dashboards) | `analytics` | all (read-only consumers) | `analytics` **only** (write-once, queue-fed) |
| Benchmarks (percentiles, industry averages) | `analytics` | `learning` surfaces, dashboards | `analytics` |
| Audit log (per domain) | each domain (own audit trail) | `identity_billing` (compliance) | owning domain, append-only |

**Enforcement notes (from architecture rules):**
- No cross-database joins. Any metric needing two domains (e.g., revenue-by-course = `identity_billing` × `catalog`) is either a two-query PHP merge or a pre-materialized `analytics` aggregate.
- Cross-domain references are plain indexed columns (e.g., `learning.attempts.user_id` → `identity_billing.users.id`), never FK constraints.
- `analytics` is write-once: transactional domains never read from it; it is fed via queued jobs consuming events from the other domains.
- High-volume writes (progress, attempts, notifications) live in `learning` / `engagement` — never in `identity_billing` or `catalog`.

---

## 5. Cross-Domain Flow Map

### 5.1 Primary commercial→learning→analytics flow
```
catalog (Plan + Price + Discount)
   → identity_billing (Purchase → Payment → Subscription)
   → identity_billing (Entitlement decision)
   → learning (Access granted → Learning activity events)
   → learning (XP / streak / mastery updates)
   → engagement (notifications: reminders, alerts, celebrations)
   → analytics (queued aggregates: progress, engagement, revenue rollups)
```

### 5.2 Renewal & dunning flow
```
identity_billing (renewal date reached → charge)
   ├─ success → identity_billing (subscription extended)
   │              → engagement (renewal confirmation)
   │              → identity_billing (renewal commission event, if referred)
   │              → engagement (renewal commission credited)
   └─ failure  → identity_billing (retry loop → grace → suspend)
                  → engagement (dunning notifications, each retry)
                  → identity_billing (access suspended after grace)
                  → learning (access gate blocks content)
                  → analytics (payment-failure / churn metrics)
```

### 5.3 Refund / cancellation flow
```
identity_billing (refund approved / cancellation)
   → identity_billing (subscription state change)
   → learning (access revoked at period end / immediately)
   → engagement (confirmation notification)
   → identity_billing (commission clawback — OD-19)
   → analytics (churn + reason, revenue correction)
```

### 5.4 Affiliate referral→payout flow
```
engagement (referral link click → sign-up → purchase attribution)
   → identity_billing (purchase payment successful)
   → identity_billing (commission event: pending)
   → identity_billing (confirmation → earned — OD-35 holding period)
   → engagement (affiliate notified; live feed updates)
   → identity_billing (payout request → Super Admin approval → paid)
   → analytics (affiliate performance rollups, funnel)
```

### 5.5 Learning activity fan-out (single event, multiple consumers)
```
learning (quiz completed)
   ├─ learning (score, mastery, XP, streak increment)
   ├─ engagement (badge unlock celebration, parent alert, streak-at-risk check)
   ├─ identity_billing (feature-limit counter: AI Q/day if AI-assisted)
   └─ analytics (queued: performance rollup, engagement score input)
```
- **OPEN DECISION (OD-36):** cross-domain event fan-out — ordering, idempotency, and failure handling for multi-consumer events (e.g., quiz completion → 5 consumers) are undefined.

### 5.6 Bulk license flow
```
identity_billing (bulk purchase paid)
   → identity_billing (licenses added to pool immediately)
   → identity_billing (assignment to student → access immediate)
   → learning (student learning activity)
   → identity_billing (release → access revoked, license back to pool)
   → analytics (license utilization, expiry alerts 30/60 days)
```

### 5.7 Notification flow
```
any domain (trigger event)
   → engagement (preference evaluation → timing rules → channel delivery)
   → engagement (delivery status: sent → delivered → read)
   → analytics (open rates, alert response time)
```

### 5.8 CSR / Sponsor funding flow
```
identity_billing (agreement + funding schedule)
   → identity_billing (disbursements: scheduled → released / failed — OD-37)
   → learning (beneficiary learning outcomes)
   → engagement (beneficiary engagement)
   → analytics (impact reporting, ROI, budget burn — privacy-masked per student)
```

---

## 6. System-of-Record Rules

Authoritative version of each important fact:

| Fact | System of record | Rule |
|---|---|---|
| Who a user is (identity, role, account state) | `identity_billing` | Sole writer; all other domains reference by plain indexed `user_id` |
| What a plan is and what it costs | `catalog` | Plan + price rules authoritative; `identity_billing` snapshots the price at purchase time |
| **Whether a user has access** | `identity_billing` (subscription status) | Docs: subscription status is "the single source of truth for access". `learning` enforces the gate but never decides it |
| Money moved (payment, invoice, refund) | `identity_billing` | Append-only transaction ledger; immutable once recorded; corrections via adjustment records, never edits |
| Commission owed / paid | `identity_billing` (commission ledger + payout ledger) | `engagement` owns the *attribution* (who referred); `identity_billing` owns the *money* (how much, when paid) |
| License pool state | `identity_billing` | Real-time on assign/release; entitlement change history immutable, append-only |
| Learning happened (progress, attempts, mastery) | `learning` | Sole writer for all learning state; resume positions, SRS state, XP ledger, streaks |
| XP balance | `learning` (point ledger) | Values applied at event time; no retroactive revaluation |
| SRS rating history | `learning` | Immutable per item |
| A notification was sent / read | `engagement` | Delivery records authoritative; notification history retained separately from the clearable center |
| Moderation outcome | `engagement` | Immutable log; overturns are new entries referencing the original |
| A referral click / attribution | `engagement` | Click + attribution events authoritative; commission derivation happens in `identity_billing` |
| Any aggregate metric (MRR, churn, DAU, engagement score, benchmarks) | `analytics` | Write-once, queue-fed; **never** a source for transactional decisions; recomputable from source domains |
| Audit trail of an admin action | the domain where the action occurred | Append-only, actor + timestamp, pervasive |
| Financial/tax records after deletion request | `identity_billing` | Anonymized, **not deleted** (legal retention) |

**General rules:**
1. Every fact has exactly one owning domain; all other access is read-only or event-driven.
2. `analytics` is never a system of record for any transactional fact — only for derived aggregates.
3. Immutables (transaction ledger, commission ledger, SRS ratings, moderation log, entitlement change history, audit logs) are append-only; corrections are new records.
4. Cross-domain identity is by plain indexed column, never FK.

---

## 7. Redis & Object Storage — Candidate Areas (CTO approval required)

**No implementation decisions are made here.** These are the areas where the documentation's requirements make each technology appropriate, flagged for CTO sign-off.

### 7.1 Redis (temporary / fast-access)
| Area | Why appropriate |
|---|---|
| Hot reads of `identity_billing.users` | Architecture rule already mandates Redis for hot user reads |
| Hot reads of `catalog` (plans, prices, content metadata) | Architecture rule already mandates Redis for hot catalog reads |
| Access/entitlement check at content play time | Every video/quiz start checks subscription status — high-frequency, low-latency need; subscription state changes are infrequent (cache-invalidate on state change) |
| License pool counts (institute) | Docs require **real-time** pool updates on assign/release — a fast counter structure fits |
| Referral click live feed (affiliate) | Docs require **real-time** "as they happen" feed — pub/sub or stream fits |
| Parent real-time activity monitor | Docs require real-time current activity — recent-event stream fits |
| Notification digest batching / queue | Non-critical notifications batched to daily digest; held notifications queued — a queue fits |
| Session / rate limiting (OTP resend cooldown, export rate limits) | Short-lived TTL state |
| Leaderboard period state | "Updated on a schedule" — sorted-set style structure fits (SoR remains `engagement`) |
| Feature-limit counters (AI Q/day, downloads/mo) | High-write, TTL-scoped counters (subject to OD-13) |

### 7.2 Object Storage (large files)
| Area | Why appropriate |
|---|---|
| Video binaries | Architecture rule: media binaries → object storage; only metadata in `catalog` |
| Podcast audio binaries | Same rule |
| Live session recordings | Retained post-session with access control; large files |
| Worksheets / resources / shared group files | File type/size limits documented; binaries don't belong in MySQL |
| Report exports (PDF/Excel/CSV) | Generated artifacts delivered by secure link; transient-to-archived lifecycle |
| Sponsor branding assets (logos, banners) | Static large files |
| Affiliate marketing assets (banners, graphics, pre-designed posts) | Static large files |
| Data portability exports (JSON/CSV) | Secure-link delivery, rate-limited |
| Backups (30/90-day retention) | Backup artifacts |

**OPEN DECISION (OD-38):** Redis deployment topology, cache-invalidation strategy, and TTL policy — CTO approval required.
**OPEN DECISION (OD-39):** Object storage provider (S3/MinIO), bucket layout, lifecycle/expiration rules, and signed-URL policy — CTO approval required.

---

## 8. OPEN DECISION Register

All unresolved architecture/business decisions identified during this analysis.

### Commercial
| ID | Decision needed |
|---|---|
| OD-10 | Grandfathering duration for price changes ("if applicable" in docs) |
| OD-11 | Do purchases via affiliate discount codes generate affiliate commission? |
| OD-12 | Installment overdue → suspension timing |
| OD-13 | Authoritative location of per-user feature-limit counters (AI Q/day, downloads/mo): `learning` (proposed) vs `identity_billing` |
| OD-14 | Bank-transfer success confirmation / reconciliation flow |
| OD-15 | Renewal notification lead time (3 days is a journey example only) |
| OD-16 | Renewal commission: number of paid cycles, renewal rate vs initial rate, lapse-then-resubscribe treatment |
| OD-17 | Dunning retry count/interval and grace-period length (docs give examples only) |
| OD-18 | Confirm asymmetry: grace on failed renewal, none on natural expiry |
| OD-19 | Refund window value + **affiliate commission clawback/reversal rule** (no `voided` commission state exists) |
| OD-20 | Downgrade credit rule (refund/credit of unused value) |
| OD-21 | Churn-reason collection mechanism (survey vs inference) |
| OD-22 | Billing currency after mid-cycle FX rate change |
| OD-35 | Commission confirmation/holding period — what makes a referral "confirmed" (trial end? first payment? return window?) |
| OD-37 | CSR disbursement "failed" state — retry/recovery flow |

### Engagement
| ID | Decision needed |
|---|---|
| OD-23 | Notification pipeline: queue technology, rate limits, dedup/coalescing, retention period |
| OD-24 | Do critical alerts bypass quiet hours? |
| OD-25 | Concrete XP values per action; point expiry policy |
| OD-26 | Streak rules: grace mechanics, "at risk" threshold, which actions count as "a study action" |
| OD-27 | Student "points" vs parent "digital tokens": same ledger or separate currencies |
| OD-28 | Badge revocation — are associated points clawed back? |
| OD-29 | Canonical "inactive user" definition (7-day / 30-day / configurable coexist) |
| OD-36 | Cross-domain event fan-out: ordering, idempotency, failure handling for multi-consumer events |

### Analytics & data
| ID | Decision needed |
|---|---|
| OD-30 | Home for support tickets/SLA data (proposed: `engagement`) |
| OD-31 | Home for infrastructure telemetry (outside the 5 domains) |
| OD-32 | Benchmark data source, population, refresh cadence |
| OD-33 | Engagement score formula weights and band cutoffs |
| OD-34 | Canonical "active user" definition (30-day / configurable / 30-day coexist) |
| OD-40 | Retention periods: nearly all are "platform-defined" with no numbers (notifications, activity logs, audit logs, report history, recordings, AI conversations, mood/burnout data) |
| OD-41 | Real-time mechanism for affiliate live feed and parent monitor (WebSocket vs polling) + latency SLA |
| OD-42 | Anonymization standard for "anonymized industry averages" and deletion-time anonymization |
| OD-43 | Attribution model for referrals: cookie/tracking window, first/last click, self-referral and duplicate-attribution rules |
| OD-44 | Payout mechanics: currency, methods, tax withholding, fee responsibility, auto-payout vs request-only interaction |
| OD-45 | Rate precedence: how base rate vs level rate vs tier rate vs per-course scope combine into an effective commission rate |
| OD-46 | Multi-tier depth: what happens at Tier 3 (sub-affiliate recruits) — presumably none, but unstated |
| OD-47 | Termination/suspension settlement: timing, treatment of pending commissions, downline transfer |
| OD-48 | Video completion threshold % ("watched to end or past a completion threshold") |
| OD-49 | SRS rating scale conflict: student docs (Again/Good/Easy) vs admin config (Too Easy/Good/Hard) |
| OD-50 | Forum access gating by subscription tier (which tier gets forums) |
| OD-51 | Live session attendance SoR: self-marked (group sessions) vs system join/leave timestamps (live classes) |
| OD-52 | AI companion conversation retention period and PII handling; mood/burnout data retention and parent visibility |
| OD-53 | Family plan sibling discount tier values (2/3/4+ children) |
| OD-54 | Trial re-trial maximum count |
| OD-55 | Sponsorship wind-down: sponsored content access/branding behaviour after end date beyond "placement removal" |
| OD-56 | Corporate committed-spend interaction with mid-year tier changes |
| OD-57 | Corporate cost-center allocation timing (at invoice vs at seat assignment) |
| OD-58 | Report delivery failure handling (retry/escalation for failed email deliveries) |
| OD-59 | Cross-audience data boundaries: can super admin see individual student PII in analytics (FERPA mapping to screens) |
| OD-60 | Sponsor "brand value metrics" formula; impression tracking mechanism for brand exposure |

### Infrastructure (CTO approval required)
| ID | Decision needed |
|---|---|
| OD-38 | Redis deployment topology, cache-invalidation strategy, TTL policy |
| OD-39 | Object storage provider, bucket layout, lifecycle rules, signed-URL policy |

---

## 9. Approval

This document constitutes the approved **MDA Commercial, Engagement, Analytics & Data Ownership Model** (v1.0). It defines process maps, event maps, analytics inputs, ownership, cross-domain flows, and system-of-record rules across the five approved data domains, and registers 50+ OPEN DECISION items for resolution before database design begins.

**Next step (blocked on OPEN DECISIONS + CTO approval of §7):** database table design per domain.
