What this is about
A platform administrator can change two values on the user record: the display name and the home tenant. Both are values in CIAS. Keycloak does not notice any of it.
The two calls
When: The person has a different name, or the name was misspelled.
POST /cias/admin/users/{id}/rename with { "displayName": "Anna Berg-Schulz" }. An empty name resets the display name to the address. First and last name in Keycloak stay unchanged.
Result: 200 with the record.
When: In terms of the subject area, the person belongs to a different tenant.
POST /cias/admin/users/{id}/tenant with { "tenantKey": "suedlogistik" }. If the value changes, CIAS sends the event Moved with the old and the new tenant.
Result: 200 with the record.
When: The person should no longer be assigned to any tenant.
The same call with { "tenantKey": null } or an empty value.
Result: The person appears in the list of persons without a tenant.
When: The person has the status CLOSED.
CIAS rejects a move.
Result: 409 cias.user.invalid-state
What changes and what stays
homeTenantKeyin the record- Lists
GET /cias/admin/users?tenantKey=… - Event
Movedin the audit
- Membership in the organization
nordbau - Attributes
tenantandallowedTenantson the account - the tenant in which the requests run
- Roles in the tenant
The tenant of a request always comes from the token, not from the record. As long as Keycloak keeps the person in nordbau, they work in nordbau. See Determine the tenant of a request.