# 7. Access & API

User Type: **Organization**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 7. Access & API

### 7.1 Single Sign-On (SSO)
**What it does:** Lets the organization enable SSO so its users sign in with the organization's identity provider (SAML/OIDC), with just-in-time provisioning.

**Sub-features:**
- SSO setup (SAML/OIDC)
- Identity provider configuration
- Just-in-time user provisioning
- SSO login flow
- SSO status and troubleshooting
- Single Sign-On (SSO) available on web and mobile
- single sign-on (sso) event logging (viewed)
- Audit logging of single sign-on (sso)

**Organization User Journey:**
1. Organization navigates to Single Sign-On (SSO).
2. Organization reviews the single sign-on (sso) details shown.
3. Organization performs the primary action for single sign-on (sso).
4. Organization confirms the result matches the documented behavior.
5. Organization opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- SSO setup (SAML/OIDC).
- Identity provider configuration.
- Just-in-time user provisioning.
- SSO login flow.
- SSO status and troubleshooting.

### 7.2 API Access
**What it does:** Provides the organization with API access to the platform: API keys, rate limits, and documented endpoints for users, programs, and progress.

**Sub-features:**
- API key generation and management
- Rate limit information
- Documented endpoints (users, programs, progress)
- API usage monitoring
- API key revocation
- API Access available on web and mobile
- api access event logging (viewed)
- Audit logging of api access

**Organization User Journey:**
1. Organization navigates to API Access.
2. Organization reviews the api access details shown.
3. Organization performs the primary action for api access.
4. Organization confirms the result matches the documented behavior.
5. Organization opens Profile → "Activity" and confirms the events are recorded.

**Rules & Edge Cases:**
- API key generation and management.
- Rate limit information.
- Documented endpoints (users, programs, progress).
- API usage monitoring.
- API key revocation.
