bcgov / bcgov/entity

Phase 2 - Invite someone to get a Digital Business Card

Open
#16,496 0 comments 0 reactions 0 assignees View on GitHub
Epic
Dominant language
JavaScript
Stars
23
Forks
62
Avg merge
24m
Merged PRs (30d)
1

Description

## Description (Hypothesis):
- Short Description of the needed Epic in the below format

As an authenticated Registries Account holder that manages a business
I want to give another person a Digital Business Card
so they can apply for services on the business's behalf

or
* What are the most critical features being built as part of this Epic
- [ ] An invitation can be sent to someone
- [ ] they authenticate and can download the Digital Business Card
- [ ] Registries know who they are
- [ ] Digital Business Card can be revoked

* Expected Outcome – Justification why this Feature must be built, what is expected value and justification for priority.
Companies may want their employees or other professionals to apply for services on their behalf. These people may not be attached to a Registries Account as they don't process transactions on the Registry applications.

----
## Acceptance Criteria
* Used to determine whether the implementation is correct and delivers the business benefits
### Scenario 1 - issue invitation
**GIVEN** I have a Registries Account
**AND** I authenticated with my BC Services App (card, non-card, or token) **AND** I have any role type (Account Administration, Account Coordinator, User)
**OR** I authenticated with a BCeID, 2FA and affidavit **AND** I have the Account Administrator role type
**WHEN** I am logged into my Registries Account
**THEN** I can send an email invitation to someone not attached to my account and offer them a Digital Business Card

### Scenario 2A - receive invitation and authenticate using existing Registries account
**GIVEN** I have received an invitation to get a Digital Business Card
**AND** currently have a Registries Account (but not associated to the business)
**WHEN** I open the invitation
**THEN** I will sign into my Registries Account
**AND** I will wait for the invitee to approve and issue my credential

### Scenario 2B - receive invitation and don't have a Registries account
**GIVEN** I have received an invitation to get a Digital Business Card
**AND** DO NOT have a Registries Account
**WHEN** I open the invitation
**THEN** I will create a Registries Account _*TBC_
**AND** authenticate with the BCSC
**AND** I will wait for the invitee to approve and issue my credential

### Scenario 3 - Invitee authorizes person to access the Digital Banking Card
**GIVEN** I previously invited someone to get a digital credential
**AND** am logged into my Registries Account
**WHEN** I see the invitee has authenticated and accepted the invitation
**THEN** I can approve the release of the credential

### Scenario 4 - The invited person downloads the Digital Banking Card to their wallet
**GIVEN** I previously accepted an invitation for a credential and authenticated
**WHEN** the person who invited me approved the release of my credential
**THEN** I will see the credential in my wallet
_Questions: what interim steps do they need? When do they us the QR code?_

----
## Additional Information
* Start date when team will start to work on: This is visible in ZenHub under "Roadmap"
* End date Epic will be delivered: This is visible in ZenHub under "Roadmap"
* T-shirt size: X (S, M, L, or XL) (S=1-2 Sprints, M=2-3 Sprints, L=4-5 Sprints, XL=not sure, probably more than 5 Sprints). Story points needs to be updated in Epic. This can be decided by team.
* Process Flow (if applicable)
* CM considerations?
* Possible dependencies or blockers foreseen right now? - Please create a story and block this epic by the dependency story.

----
Enabler Epics:
* action
* result
* object

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by decomposing the four acceptance scenarios and resolving the open questions about account creation, interim steps, QR-code use, and credential approval; done means the invitation, authentication, authorization, issuance, download, and revocation flows are specified and verified.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.