CodamAIDocs
Module

CIAS – Identity and access

The bridge between a CodamAI application and the identity provider (Keycloak). CIAS knows who a person is, which tenant they belong to, which roles exist, and who may grant them. Keycloak handles the sign-in itself.

CIAS stands for CodamAI Identity & Access System. The most important sentence first:

Who does what?
Keycloak
Identity provider
  • checks passwords and MFA
  • shows the login page
  • issues tokens
  • keeps sessions
CIAS
Meaning and management
  • users, tenants, roles, groups
  • registration and invitations
  • writes roles and attributes into Keycloak
  • checks token and tenant on every request
The application (e.g. CDMS)
Enforcement
  • reads roles from the token
  • decides what a role may do
  • filters rows by attributes

The direction is always the same: application → CIAS → Keycloak. Only CIAS writes permissions into Keycloak.

Subject areas

Basics: what CIAS is and what it is not

The terms and the split you need to understand any CIAS flow: the objects and their owners, tenant and group, the two permission matrices, the write direction, and the ceiling.

CIAS as a bridge to the identity providerThe objects and who owns themTenant, organization, groupThe two permission matricesThe ceiling: nobody grants more than they have
Login and token

How a person or a service gets a token, how it is renewed and ended, and what happens with the token on every request.

Sign in in the browserSign in as a service (client credentials)Session in the BFF and cookiesRenew the tokenSign outWhat happens with the token on every requestToken exchangeWhat is read from the tokenEffective roles: global or in the tenantWhy revoking permissions takes effect with a delay
Registration

How a person becomes a user: one flow with four variants, email verification, password at Keycloak, approval, tenant assignment, initial roles, hooks and emails.

One flow, four variantsThe states of a registrationSelf-registrationCreation by the platform administratorInvitation by the tenant administratorRedeem an invitationThe email is the accountVerify the emailSet the passwordApproval by an administratorWhere the tenant comes fromWhat happens on completionInitial roles as a rule setYour own logic: hooks and eventsProtecting the public endpointsClean up abandoned registrations
User management

The user record in CIAS from the subject area view: status, suspend, close, move, maintain attributes, and why the order of the write operations decides security.

The user recordThe lifecycle of a userThe write orderSuspend, reactivate, closeImport existing accountsRename and change the home tenantMaintain a person's attributesResend the password setup linkSelf-service: own tenant and language
Tenants

The tenant as the isolation boundary: static or dynamic, its business status, its technical rollout, how it is resolved and admitted on every request, and how you switch between tenants.

Static and dynamic tenantsThe lifecycle of a tenantCreate and provision a tenantThe tenant keySuspend and close tenants, validityDetermine the tenant of a requestAdmit the tenant (tenant gate)Switch between tenantsIn SINGLE the tenant in the token does not countWorking for a tenant without a request
Grant roles and permissions

The role catalog, the levels of a role, how modules register their roles, who may grant roles, time-limited grants, and how a role gets into the token.

The role catalogRealm role, client role, organization roleModules register their rolesReconciliation with KeycloakHow a role gets from the code into the tokenGrant a roleTime-limited rolesRevoke a roleThe platform's realm roles
Groups

Groups as role bundles with members: create them, maintain members, the default group, reconciliation with Keycloak and how groups interact with dynamic tenants.

What a group isManage groups and membersThe default groupReconciliation with KeycloakGroup roles under dynamic tenants
User attributes

Details on the account that become claims in the token and filter rows in CDMS: where they come from, how modules declare them, who may write them and which tenants a value applies to.

Two origins of attributesRegistering attributesThe path into the tokenWho may write an attributeOne value per person or per tenantHow an attribute goes away again
Notifications

Which emails CIAS sends, how the right template is found, and who may change templates.

Which emails existHow the right template is foundEdit templatesSending and branding
Audit in CIAS

One audit trail for the whole platform: which events go into it, what is missing, and who may read them.

One trail for everythingWhich events are loggedRead the auditCIAS audit and CDMS history
Connection to the identity provider

How CIAS talks to Keycloak without the business modules knowing Keycloak: ports and adapters, the Keycloak adapter, the in-memory adapter for tests, and the Keycloak extension.

Ports and adaptersThe Keycloak adapterThe in-memory adapter for tests and developmentThe Keycloak extension for the password link
Security principles

The principles behind every CIAS process, in one place: refuse when in doubt, indistinguishable refusals, no defaults for permissions, and behavior during outages.

Reject when in doubtRejections that reveal nothingWhen CIAS or Keycloak fails
User interfaces

Which user interfaces exist for sign-in, registration and administration, and which flows start there.

The login pages (Keycloak theme)The admin interfaceRegister and verifyThe CIAS portal
Search