Skip to main content

RBAC Tests

IDTest CaseTypePriorityExpected ResultEvidence RequiredStatus
TC-RBAC-001Admin accesses admin-only featurePositiveCriticalAccess allowedScreenshotNot Run
TC-RBAC-002School Manager attempts admin-only cancellationNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-RBAC-003Supplier attempts school manager featureNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-RBAC-004Operator attempts supplier featureNegativeHighAccess deniedScreenshot or API 403 responseNot Run
TC-RBAC-005Parent accesses own student flowPositiveHighAccess allowed within own scopeScreenshotNot Run
TC-RBAC-006Student accesses own allowed flowPositiveMediumAccess allowed within own scopeScreenshotNot Run