# TELSPAY Education v2026.9.5.2 — Last Mile Release

This release is based on the validated v2026.9.5.1 full release and includes all prior Education hotfixes plus the final School/Member school-fees wiring.

## Added / completed in v2026.9.5.2

### School Portal
- Student listing with search and pagination.
- Student profile for full bio/KYC review and updates.
- School-side KYC edits return KYC to PENDING; school staff cannot self-verify sensitive KYC.
- Student payment number display and reconciliation history.
- Mobile Money school-fees checkout.
- Bank and Cash school-fee submission; Bank evidence is mandatory and stored privately.
- Bank/Cash submissions remain pending until SACCO Admin approval.
- Complete operational navigation for Admissions, Admission Forms, Academic Setup, Students & KYC, Fees, Payments/Reconciliation, Loans, Documents, Student Wallets, Student Loans, Store, Compliance, School Profile and Subscription.

### Member App / Education Invest
- Savings -> Education Invest retained.
- Mobile Money Education Invest top-up retained and verified server-to-server.
- Member Savings -> linked Student Wallet transfer.
- Savings-based Student Wallet transfers require both OTP and Transaction PIN.
- Savings-based school-fees payments require both OTP and Transaction PIN.
- Member service fees are read from SACCO Education Finance Settings and posted separately.
- Shares are never used as a payment source.
- Parent/member can view linked students and school-fee reconciliation history.

### SACCO Admin
- Bank/Cash school-fee reconciliation queue with Approve/Reject workflow.
- Secure private evidence preview for PDF/JPG/PNG evidence.
- Finance Settings include member Savings school-fees fee and Savings -> Student Wallet transfer fee.
- Education Control Center links to Fee Reconciliation.
- Global Education transaction controls from earlier v2026.9.5 remain included.

## Database migration
For an existing v2026.9.5.1 installation, import:

`database/TELSPAY_EDUCATION_LAST_MILE_V2026_9_5_2.sql`

The migration is additive and creates OTP/fee/evidence controls and extends school-fee payment metadata.

## Production configuration
Preserve the production private configuration:

`/home/CPANEL_USER/telspay_secure/education/local.php`

Do not replace it with `local.example.php`.

A strong `token_pepper` (at least 32 characters) is required for Education action OTP hashing.

Flutterwave, SMTP and Africa's Talking live credentials are not bundled. Live provider flows must be verified on staging/cPanel using the production/test provider accounts.
