{
  "$comment": "Contract A4 PRACTICE items for the ashr-partner-l2 track, domain tenant-setup-and-roles. Published, for lesson quizzes and lab preparation. The secured theory exam is NOT drawn from this file. Every item cites the ASHR.work pages it is grounded in (`cites`) and the repo files the facts were read from (`sources`). No item quotes a price and no item carries customer data.",
  "track": "ashr-partner-l2",
  "domain": "tenant-setup-and-roles",
  "items": [
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.01",
      "kind": "mcq",
      "domain": "tenant-setup-and-roles",
      "stem": "During rollout, an employee tries to sign up with their work email before anyone has invited them. What happens?",
      "options": [
        {
          "key": "a",
          "text": "They join the organisation as an employee automatically because the email domain matches"
        },
        {
          "key": "b",
          "text": "The sign-up is rejected: a person becomes a user of an organisation only if that organisation invited them first, and the role in the invitation is the role they get"
        },
        {
          "key": "c",
          "text": "They get a pending account an admin approves later"
        },
        {
          "key": "d",
          "text": "They create a second organisation with the same name"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Tenant and role come from the invitation, never from anything the person types. Plan invitations before go-live.",
      "cites": [
        "https://ashr.work/docs/explanation/tenancy-and-roles"
      ],
      "sources": [
        "content/docs/explanation/tenancy-and-roles.mdx",
        "lib/tenant.ts"
      ]
    },
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.02",
      "kind": "mcq",
      "domain": "tenant-setup-and-roles",
      "stem": "The customer's external accountant must run payroll and must not get general HR-admin access. How do you set them up?",
      "options": [
        {
          "key": "a",
          "text": "Give them the admin role"
        },
        {
          "key": "b",
          "text": "Give them a base role of employee plus the finance grant"
        },
        {
          "key": "c",
          "text": "Give them the manager role over everyone"
        },
        {
          "key": "d",
          "text": "Create a new custom 'accountant' role"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "The base role is one of admin, manager or employee; finance, recruiter, hiring-manager and delegated admin access are additive grants on top.",
      "cites": [
        "https://ashr.work/docs/explanation/tenancy-and-roles"
      ],
      "sources": [
        "content/docs/explanation/tenancy-and-roles.mdx",
        "lib/tenant.ts"
      ]
    },
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.03",
      "kind": "mcq",
      "domain": "tenant-setup-and-roles",
      "stem": "The customer wants HR admins kept out of payroll. What does turning on the finance-only payroll restriction do?",
      "options": [
        {
          "key": "a",
          "text": "It hides payroll from employees only"
        },
        {
          "key": "b",
          "text": "Payroll pages and actions are limited to people holding the finance grant, so HR admins lose their route in; only an org admin can change the switch, and it refuses to turn on if it would lock everybody out"
        },
        {
          "key": "c",
          "text": "It deletes HR admins' past payroll access logs"
        },
        {
          "key": "d",
          "text": "It moves payroll to a separate workspace"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Make sure someone holds the finance grant before you turn it on.",
      "cites": [
        "https://ashr.work/docs/explanation/tenancy-and-roles"
      ],
      "sources": [
        "content/docs/explanation/tenancy-and-roles.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.04",
      "kind": "mcq",
      "domain": "tenant-setup-and-roles",
      "stem": "A team lead should run hiring for the openings they own without seeing every employee's salary. Which grant fits?",
      "options": [
        {
          "key": "a",
          "text": "The admin role"
        },
        {
          "key": "b",
          "text": "The hiring-manager grant"
        },
        {
          "key": "c",
          "text": "The finance grant"
        },
        {
          "key": "d",
          "text": "Delegated admin access"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "A hiring manager sees only the openings they own and those candidates; the recruiter grant gives the whole recruitment module.",
      "cites": [
        "https://ashr.work/docs/explanation/tenancy-and-roles"
      ],
      "sources": [
        "content/docs/explanation/tenancy-and-roles.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.05",
      "kind": "mcq",
      "domain": "tenant-setup-and-roles",
      "stem": "The customer does not want the Expenses module visible during the first month of rollout. What happens when you switch it off?",
      "options": [
        {
          "key": "a",
          "text": "Its data is deleted"
        },
        {
          "key": "b",
          "text": "It is hidden from everyone in the organisation and the navigation updates for the whole org; switching it back on brings it back"
        },
        {
          "key": "c",
          "text": "It is hidden only from employees"
        },
        {
          "key": "d",
          "text": "It needs a support ticket to switch off"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Module visibility is per organisation. Switching a module off does not delete what it held.",
      "cites": [
        "https://ashr.work/help/admin/module-visibility"
      ],
      "sources": [
        "content/help/admin/module-visibility.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.tenant-setup-and-roles.06",
      "kind": "multi",
      "domain": "tenant-setup-and-roles",
      "stem": "Which of these do you configure in the Admin console during week-one tenant setup? Select all that apply.",
      "options": [
        {
          "key": "a",
          "text": "Workforce types (full-time, interns, contractors and so on)"
        },
        {
          "key": "b",
          "text": "The employee-ID format"
        },
        {
          "key": "c",
          "text": "The leave-escalation window"
        },
        {
          "key": "d",
          "text": "The database hosting region"
        },
        {
          "key": "e",
          "text": "Income-tax slabs"
        }
      ],
      "answer_key": {
        "correct": [
          "a",
          "b",
          "c"
        ]
      },
      "max_points": 2,
      "rationale": "There is no per-customer hosting region, and tax slabs live under Payroll → Income tax, not the Admin console.",
      "cites": [
        "https://ashr.work/docs/tutorials/admin-first-90-days",
        "https://ashr.work/help/admin/configuring-workforce-types",
        "https://ashr.work/help/admin/employee-id-formats",
        "https://ashr.work/help/admin/leave-escalation-configuration"
      ],
      "sources": [
        "content/docs/tutorials/admin-first-90-days.mdx",
        "content/help/admin/configuring-workforce-types.mdx",
        "content/help/admin/employee-id-formats.mdx",
        "content/help/admin/leave-escalation-configuration.mdx"
      ]
    }
  ]
}
