CodamAIDocs
Topicdone

Suspend, reactivate, close

The three status operations step by step, and the fact that closing disables the account but does not delete it.

Variants
suspendunsuspend (reactivate)closeno deletion

What this is about

A platform administrator can take access away from a person and give it back. There are three calls for this:

CallEffectreversible
POST /cias/admin/users/{id}/suspendsuspendyes
POST /cias/admin/users/{id}/reactivatereactivate–
POST /cias/admin/users/{id}/closecloseno

The three calls

Suspend, reactivate, close

When: Suspicion of misuse, open clarification, temporary pause.

  1. 1
    Admin→CIAS
    POST /cias/admin/users/{id}/suspend with { "reason": "…" }
  2. 2
    CIAS
    Platform administrator? Reason given?
    otherwise 403 or 400
  3. 3
    CIAS→Keycloak
    disables the account
  4. 4
    CIAS
    Status → SUSPENDED, event Suspended with reason
    Result: 200 with the record

Result: From CLOSED: 409 cias.user.invalid-state.

When: The clarification is complete.

  1. 1
    Admin→CIAS
    POST /cias/admin/users/{id}/reactivate, without a body
  2. 2
    CIAS
    Status → ACTIVE
  3. 3
    CIAS→Keycloak
    enables the account
    Result: 200 with the record, event Activated

Result: From CLOSED: 409.

When: The person leaves the company, the account should end permanently.

  1. 1
    Admin→CIAS
    POST /cias/admin/users/{id}/close with { "reason": "…" }
  2. 2
    CIAS→Keycloak
    disables the account
  3. 3
    CIAS
    Status → CLOSED, event Closed with reason
    Result: 200 with the record

Result: Final. A second call changes nothing.

Why not delete?

  • In CDMS, data is attached to the person: rows in user models belong to them, and the history names them. A deleted account would leave these references pointing to nothing.
  • The audit should still be able to say later who did what and when.

What takes effect immediately and what does not

Suspending and closing disable the account in Keycloak. This means:

Effect
new sign-inimpossible immediately
renew tokenfails at the next refresh
access token the person already hasstays valid until it expires

CIAS does not end running sessions separately. How long an existing token keeps working is described in Why revoking permissions takes effect with a delay.

Errors

CaseResponse
not a platform administrator403 cias.user.administration-denied
person unknown404 cias.user.not-found
reason missing400 cias.user.invalid-request
person is closed (suspend, reactivate)409 cias.user.invalid-state
Keycloak unreachable503 cias.iam.unavailable

Next

Sources in the code and the knowledge base
  • CIAS/cias-user – UserAdminController (suspend, reactivate, close), UserRestDtos, UserService, UserExceptionHandler
  • CIAS/cias-iam-keycloak – KeycloakIdentityAdapter (enable, disable)
  • CIAS/cias-user/docs/adr – ADR-017 §5
Search