# 3. Verifying Child Relationships — Test Cases

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: verifying_relationships.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.1 Relationship Verification | Relationship verification before full link activation | TC-PT-2-03-001 |
| 3.1 Relationship Verification | Verification via school/institute records (where available) | TC-PT-2-03-002 |
| 3.1 Relationship Verification | Verification step for the Parent | TC-PT-2-03-003 |
| 3.1 Relationship Verification | Verification status (verified, pending, failed) | TC-PT-2-03-004 |
| 3.1 Relationship Verification | Child data limited until verified | TC-PT-2-03-005 |
| 3.1 Relationship Verification | Verification event logging (verified, failed) | TC-PT-2-03-006 |
| 3.1 Relationship Verification | Audit logging of the relationship verification | TC-PT-2-03-007 |
| 3.1 Relationship Verification | Rule: The relationship is verified before full link activation. | TC-PT-2-03-001 |
| 3.1 Relationship Verification | Rule: The child's data is limited until verified. | TC-PT-2-03-002 |
| 3.1 Relationship Verification | Rule: A failed verification does not activate the link. | TC-PT-2-03-003 |
| 3.1 Relationship Verification | Rule: Verification events (verified, failed) are logged with the account and the timestamp. | TC-PT-2-03-004 |
| 3.1 Relationship Verification | Rule: The relationship verification is audit-logged with the account and the timestamp. | TC-PT-2-03-005 |
| 3.2 Consent and Permission | Child consent for the Parent's monitoring | TC-PT-2-03-008 |
| 3.2 Consent and Permission | Scope of Parent access defined | TC-PT-2-03-009 |
| 3.2 Consent and Permission | Consent status (granted, withdrawn) | TC-PT-2-03-010 |
| 3.2 Consent and Permission | Parent can see the permitted data scope | TC-PT-2-03-011 |
| 3.2 Consent and Permission | Consent can be withdrawn | TC-PT-2-03-012 |
| 3.2 Consent and Permission | Consent event logging (granted, withdrawn) | TC-PT-2-03-013 |
| 3.2 Consent and Permission | Audit logging of the consent and permission | TC-PT-2-03-014 |
| 3.2 Consent and Permission | Rule: The child's consent is required for the Parent's monitoring. | TC-PT-2-03-008 |
| 3.2 Consent and Permission | Rule: The scope of access is defined by the consent. | TC-PT-2-03-009 |
| 3.2 Consent and Permission | Rule: The consent can be withdrawn. | TC-PT-2-03-010 |
| 3.2 Consent and Permission | Rule: Consent events (granted, withdrawn) are logged with the account and the timestamp. | TC-PT-2-03-011 |
| 3.2 Consent and Permission | Rule: The consent and permission is audit-logged with the account and the timestamp. | TC-PT-2-03-012 |
| 3.3 Link Security | Link bound to the verified Parent account | TC-PT-2-03-015 |
| 3.3 Link Security | Authentication required to view the child's data | TC-PT-2-03-016 |
| 3.3 Link Security | Suspicious access attempts flagged | TC-PT-2-03-017 |
| 3.3 Link Security | Link can be revoked | TC-PT-2-03-018 |
| 3.3 Link Security | Link security event logging (flagged, revoked) | TC-PT-2-03-019 |
| 3.3 Link Security | Audit logging of the link security | TC-PT-2-03-020 |
| 3.3 Link Security | Rule: The link is bound to the verified Parent account. | TC-PT-2-03-015 |
| 3.3 Link Security | Rule: Authentication is required to view the child's data. | TC-PT-2-03-016 |
| 3.3 Link Security | Rule: Suspicious access attempts are flagged. | TC-PT-2-03-017 |
| 3.3 Link Security | Rule: Link security events (flagged, revoked) are logged with the account and the timestamp. | TC-PT-2-03-018 |
| 3.3 Link Security | Rule: The link security is audit-logged with the account and the timestamp. | TC-PT-2-03-019 |

## 3.1 Relationship Verification

### TC-PT-2-03-001 — Relationship verification before full link activation
**Type:** Positive
**Covers:** 3.1 → Relationship verification before full link activation; Rule: The relationship is verified before full link activation.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Relationship verification before full link activation.
2. Observe the result and verify the full behavior: Relationship verification before full link activation.
**Expected Result:** Relationship verification before full link activation — delivered exactly as documented.
**Priority:** Critical

### TC-PT-2-03-002 — Verification via school/institute records (where available)
**Type:** Positive
**Covers:** 3.1 → Verification via school/institute records (where available); Rule: The child's data is limited until verified.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Verification via school/institute records (where available).
2. Observe the result and verify the full behavior: Verification via school/institute records (where available).
**Expected Result:** Verification via school/institute records (where available) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-003 — Verification step for the Parent
**Type:** Positive
**Covers:** 3.1 → Verification step for the Parent; Rule: A failed verification does not activate the link.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Verification step for the Parent.
2. Observe the result and verify the full behavior: Verification step for the Parent.
**Expected Result:** Verification step for the Parent — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-004 — Verification status (verified, pending, failed)
**Type:** Positive
**Covers:** 3.1 → Verification status (verified, pending, failed); Rule: Verification events (verified, failed) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Verification status (verified.
2. Observe the result and verify the full behavior: Verification status (verified, pending, failed).
**Expected Result:** Verification status (verified, pending, failed) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-005 — Child data limited until verified
**Type:** Edge
**Covers:** 3.1 → Child data limited until verified; Rule: The relationship verification is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Child data limited until verified.
2. Observe the result and verify the full behavior: Child data limited until verified.
**Expected Result:** Child data limited until verified — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-006 — Verification event logging (verified, failed)
**Type:** Positive
**Covers:** 3.1 → Verification event logging (verified, failed)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Verification event logging (verified.
2. Observe the result and verify the full behavior: Verification event logging (verified, failed).
**Expected Result:** Verification event logging (verified, failed) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-007 — Audit logging of the relationship verification
**Type:** Positive
**Covers:** 3.1 → Audit logging of the relationship verification
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the relationship verification.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 3.2 Consent and Permission

### TC-PT-2-03-008 — Child consent for the Parent's monitoring
**Type:** Positive
**Covers:** 3.2 → Child consent for the Parent's monitoring; Rule: The child's consent is required for the Parent's monitoring.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Child consent for the Parent's monitoring.
2. Observe the result and verify the full behavior: Child consent for the Parent's monitoring.
**Expected Result:** Child consent for the Parent's monitoring — delivered exactly as documented.
**Priority:** Critical

### TC-PT-2-03-009 — Scope of Parent access defined
**Type:** Positive
**Covers:** 3.2 → Scope of Parent access defined; Rule: The scope of access is defined by the consent.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Scope of Parent access defined.
2. Observe the result and verify the full behavior: Scope of Parent access defined.
**Expected Result:** Scope of Parent access defined — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-010 — Consent status (granted, withdrawn)
**Type:** Positive
**Covers:** 3.2 → Consent status (granted, withdrawn); Rule: The consent can be withdrawn.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Consent status (granted.
2. Observe the result and verify the full behavior: Consent status (granted, withdrawn).
**Expected Result:** Consent status (granted, withdrawn) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-011 — Parent can see the permitted data scope
**Type:** Positive
**Covers:** 3.2 → Parent can see the permitted data scope; Rule: Consent events (granted, withdrawn) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Parent can see the permitted data scope.
2. Observe the result and verify the full behavior: Parent can see the permitted data scope.
**Expected Result:** Parent can see the permitted data scope — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-012 — Consent can be withdrawn
**Type:** Positive
**Covers:** 3.2 → Consent can be withdrawn; Rule: The consent and permission is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Consent can be withdrawn.
2. Observe the result and verify the full behavior: Consent can be withdrawn.
**Expected Result:** Consent can be withdrawn — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-013 — Consent event logging (granted, withdrawn)
**Type:** Positive
**Covers:** 3.2 → Consent event logging (granted, withdrawn)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Consent event logging (granted.
2. Observe the result and verify the full behavior: Consent event logging (granted, withdrawn).
**Expected Result:** Consent event logging (granted, withdrawn) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-014 — Audit logging of the consent and permission
**Type:** Positive
**Covers:** 3.2 → Audit logging of the consent and permission
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the consent and permission.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 3.3 Link Security

### TC-PT-2-03-015 — Link bound to the verified Parent account
**Type:** Positive
**Covers:** 3.3 → Link bound to the verified Parent account; Rule: The link is bound to the verified Parent account.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Link bound to the verified Parent account.
2. Observe the result and verify the full behavior: Link bound to the verified Parent account.
**Expected Result:** Link bound to the verified Parent account — delivered exactly as documented.
**Priority:** Critical

### TC-PT-2-03-016 — Authentication required to view the child's data
**Type:** Edge
**Covers:** 3.3 → Authentication required to view the child's data; Rule: Authentication is required to view the child's data.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Authentication required to view the child's data.
2. Observe the result and verify the full behavior: Authentication required to view the child's data.
**Expected Result:** Authentication required to view the child's data — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-017 — Suspicious access attempts flagged
**Type:** Positive
**Covers:** 3.3 → Suspicious access attempts flagged; Rule: Suspicious access attempts are flagged.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Suspicious access attempts flagged.
2. Observe the result and verify the full behavior: Suspicious access attempts flagged.
**Expected Result:** Suspicious access attempts flagged — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-018 — Link can be revoked
**Type:** Positive
**Covers:** 3.3 → Link can be revoked; Rule: Link security events (flagged, revoked) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Link can be revoked.
2. Observe the result and verify the full behavior: Link can be revoked.
**Expected Result:** Link can be revoked — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-019 — Link security event logging (flagged, revoked)
**Type:** Positive
**Covers:** 3.3 → Link security event logging (flagged, revoked); Rule: The link security is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Link security event logging (flagged.
2. Observe the result and verify the full behavior: Link security event logging (flagged, revoked).
**Expected Result:** Link security event logging (flagged, revoked) — delivered exactly as documented.
**Priority:** High

### TC-PT-2-03-020 — Audit logging of the link security
**Type:** Positive
**Covers:** 3.3 → Audit logging of the link security
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the link security.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
