What this is about
In CodamAI there are two records, and they answer different questions:
- The CIAS audit records what happened to people, tenants and permissions: who gave whom which role and when? When was the tenant suspended?
- The CDMS history records what data looked like: what state did this order have yesterday, and who changed it? See Audit, history, rollback.
Side by side
CIAS audit
what happened to people and permissions
- one entry per event, such as
AuthorizationEvent.Granted - one table
cias_audit_entryin the system database, for the whole platform - actor:
suband tenant from the token - append only, no rollback
- read only by a platform administrator, via
AuditQueryUseCase
CDMS history
what data looked like
- one revision per change, with the whole state of the object
- a separate revision log per database, so per tenant
- actor: name, IP address, browser; in the database also the user ID (
sub) - an old state can be brought back (rollback)
- read by whoever has the model's history role, via
POST /{id}/history
Where to look?
| What is it about? | Look in |
|---|---|
| Who gave this person the role, and when? | CIAS audit, AuthorizationEvent.Granted |
| Since when has the tenant been suspended, and who did it? | CIAS audit, TenantEvent.Suspended |
| When did this person register? | CIAS audit, RegistrationEvent.Initiated and Completed |
| Who changed the price of this order, and what was in it before? | CDMS history of the order |
| What did the customer look like a week ago? | CDMS history, possibly rollback |
| Was the person who changed the order allowed to do so back then? | both: time and name from the CDMS history, then in the CIAS audit this person's role grants up to that time |
Connecting both
-
1Admin→CDMSreads the history of the order: revision 57 on 22.09. at 10:02,
usernameBen Beispiel -
2Admin→CIASlooks up Ben's user record and reads the audit: entries
AuthorizationEvent.Granted,Revoked,Expiredwith Ben'suserIdup to 10:02 -
3Admin
order-editwas granted on 20.09. and only revoked on 25.09.Result: Ben had the permission at the time of the change
Watch the names and IDs: the CDMS history returns the name from the token (username); the user ID (sub) is only in the table revinfo of the database. After a user switch, username is the person acted on behalf of, and actingUsername the person who actually acted. As actor in the CIAS audit there is the Keycloak ID (sub). In the role events, userId is the ID of the user record in CIAS. You find the link in the user record, which holds Keycloak ID, name and CIAS ID, see The user record.