# 4. App Management & Security

User Type: **Student**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 4. App Management & Security

### 4.1 App Availability and Updates
**What it does:** Provides the mobile app on iOS and Android, with updates delivered through the app stores. The Student is informed of new versions and can update the app. The app supports the platform's minimum OS versions, and the Student is guided to update the OS where required.

**Sub-features:**
- Mobile app on iOS and Android
- App updates through the app stores
- New version notification
- Minimum OS version support
- Update guidance for the OS
- App version shown in the app
- Update event logging (notified, updated)
- Audit logging of the app availability and updates

**Student User Journey:**
1. Student installs the app from the App Store / Play Store.
2. A new version is released; a notification is shown.
3. Student updates the app through the app store.
4. The app version is shown in the app settings.
5. Where the OS is below the minimum, update guidance is shown.
6. The app works on the supported OS versions.
7. Student opens Profile → "Activity" and confirms the update events are recorded.

**Rules & Edge Cases:**
- The app is available on iOS and Android.
- Updates are delivered through the app stores.
- A new version notification is shown.
- The app supports the platform's minimum OS versions.
- Update events (notified, updated) are logged with the account and the timestamp.
- The app availability and updates is audit-logged with the account and the timestamp.

### 4.2 Push Notifications
**What it does:** Delivers push notifications to the Student's device: study reminders, session alerts, achievement notifications, and report-ready alerts. The Student can enable or disable push notifications and customize the categories. Push notifications keep the Student engaged between app sessions.

**Sub-features:**
- Push notifications on the device
- Study reminder push notifications
- Session alert push notifications
- Achievement push notifications
- Report-ready push notifications
- Enable/disable push notifications
- Customize notification categories
- Push event logging (sent, opened, disabled)
- Audit logging of the push notifications

**Student User Journey:**
1. Student enables push notifications on the device.
2. A study reminder push notification is delivered.
3. A session alert is delivered before a live session.
4. An achievement push notification is delivered for a new badge.
5. Student customizes the notification categories.
6. Student disables push notifications.
7. Student opens Profile → "Activity" and confirms the push events are recorded.

**Rules & Edge Cases:**
- Push notifications require the device permission.
- The Student can enable/disable push notifications.
- Notification categories can be customized.
- Push events (sent, opened, disabled) are logged with the account and the timestamp.
- The push notifications is audit-logged with the account and the timestamp.

### 4.3 App Security
**What it does:** Protects the Student's account on the mobile app. The app supports biometric or PIN lock, session timeout, and secure storage of the session token. The Student can lock the app and sign out from the device. This protects the Student's content and account on a mobile device.

**Sub-features:**
- Biometric or PIN app lock
- Session timeout on the app
- Secure storage of the session token
- Lock the app
- Sign out from the device
- App security settings on the mobile app
- Security event logging (locked, signed out)
- Audit logging of the app security

**Student User Journey:**
1. Student enables the biometric app lock.
2. The app locks after the session timeout.
3. Student unlocks the app with biometrics.
4. The session token is stored securely.
5. Student signs out from the device.
6. The app security settings are on the mobile app.
7. Student opens Profile → "Activity" and confirms the security events are recorded.

**Rules & Edge Cases:**
- The app lock uses biometrics or a PIN.
- The session times out after the platform's idle period.
- The session token is stored securely on the device.
- Signing out from the device revokes the app session.
- Security events (locked, signed out) are logged with the account and the timestamp.
- The app security is audit-logged with the account and the timestamp.
