What this is about
A platform administrator can take access away from a person and give it back. There are three calls for this:
| Call | Effect | reversible |
|---|---|---|
POST /cias/admin/users/{id}/suspend | suspend | yes |
POST /cias/admin/users/{id}/reactivate | reactivate | – |
POST /cias/admin/users/{id}/close | close | no |
The three calls
When: Suspicion of misuse, open clarification, temporary pause.
-
1Admin→CIAS
POST /cias/admin/users/{id}/suspendwith{ "reason": "…" } -
2CIASPlatform administrator? Reason given?otherwise 403 or 400
-
3CIAS→Keycloakdisables the account
-
4CIASStatus →
SUSPENDED, eventSuspendedwith reasonResult: 200 with the record
Result: From CLOSED: 409 cias.user.invalid-state.
When: The clarification is complete.
-
1Admin→CIAS
POST /cias/admin/users/{id}/reactivate, without a body -
2CIASStatus →
ACTIVE -
3CIAS→Keycloakenables the accountResult: 200 with the record, event
Activated
Result: From CLOSED: 409.
When: The person leaves the company, the account should end permanently.
-
1Admin→CIAS
POST /cias/admin/users/{id}/closewith{ "reason": "…" } -
2CIAS→Keycloakdisables the account
-
3CIASStatus →
CLOSED, eventClosedwith reasonResult: 200 with the record
Result: Final. A second call changes nothing.
Why not delete?
- In CDMS, data is attached to the person: rows in user models belong to them, and the history names them. A deleted account would leave these references pointing to nothing.
- The audit should still be able to say later who did what and when.
What takes effect immediately and what does not
Suspending and closing disable the account in Keycloak. This means:
| Effect | |
|---|---|
| new sign-in | impossible immediately |
| renew token | fails at the next refresh |
| access token the person already has | stays valid until it expires |
CIAS does not end running sessions separately. How long an existing token keeps working is described in Why revoking permissions takes effect with a delay.
Errors
| Case | Response |
|---|---|
| not a platform administrator | 403 cias.user.administration-denied |
| person unknown | 404 cias.user.not-found |
| reason missing | 400 cias.user.invalid-request |
| person is closed (suspend, reactivate) | 409 cias.user.invalid-state |
| Keycloak unreachable | 503 cias.iam.unavailable |