What this is about
Every user record has a status. It says whether the person may use the application. Keycloak only has “enabled” or “disabled” for this. CIAS distinguishes four states, because “suspended” and “closed” mean different things in business terms.
The state diagram
stateDiagram-v2
direction LR
[*] --> PENDING: record created
PENDING --> ACTIVE: activate
PENDING --> SUSPENDED: suspend
ACTIVE --> SUSPENDED: suspend
SUSPENDED --> ACTIVE: reactivate
PENDING --> CLOSED: close
ACTIVE --> CLOSED: close
SUSPENDED --> CLOSED: close
CLOSED --> [*]
The four states
| Status | Meaning | In Keycloak | Can sign in |
|---|---|---|---|
PENDING | record created, not yet activated. Usually only occurs briefly while a registration is being completed, or after the import of an account that was not active in Keycloak | unchanged | no |
ACTIVE | active | enabled | yes |
SUSPENDED | suspended, for example on suspicion of misuse or while something is being clarified | disabled | no |
CLOSED | closed, the account has ended permanently | disabled | no |
The transitions
When: at the end of a registration, on import of an active account, or via POST /cias/admin/users/{id}/reactivate
From any state except CLOSED. If the person is already active, nothing changes. CIAS enables the account in Keycloak.
Result: ACTIVE, event Activated
When: POST /cias/admin/users/{id}/suspend with a reason
From PENDING or ACTIVE. CIAS disables the account in Keycloak.
Result: SUSPENDED, event Suspended with the reason
When: POST /cias/admin/users/{id}/close with a reason
From any state. CIAS disables the account in Keycloak, nothing is deleted. Closing is final.
Result: CLOSED, event Closed with the reason
Why CLOSED is final
A closed account cannot be reactivated, suspended, or moved to another tenant. Such an attempt ends with 409 cias.user.invalid-state.
The reason: closing should be a clear final step, for example when someone leaves the company. If you could reopen a closed account, “closed” would just be another word for “suspended”.