CodamAIDocs
Subject area

Basics: what CIAS is and what it is not

The terms and the split you need to understand any CIAS flow: the objects and their owners, tenant and group, the two permission matrices, the write direction, and the ceiling.

Topics in this subject area

  1. 1.CIAS as a bridge to the identity provider

    What CIAS does and what it explicitly does not do: no login, no passwords, no checking of permissions on data. With the table “CIAS does / CIAS does not”.

  2. 2.The objects and who owns them

    User, tenant, role, role grant, group, attribute, module: what each object is, who owns it, and what Keycloak keeps of it as a copy.

  3. 3.Tenant, organization, group

    Two structural terms, not three. The tenant separates data, the group bundles roles, “organization” is only Keycloak's name for a dynamic tenant. With the one question that decides, and a scenario played through.

  4. 4.The two permission matrices

    How a permission is carried (realm role, client role, organization role, group, attribute) is CIAS. What a permission allows (model, operation, field) is CDMS. Why CIAS does not keep a model-operation matrix.

  5. 5.The ceiling: nobody grants more than they have

    The rule above every write path: a grant never exceeds the granter. What it means for roles, groups and attributes, and how it differs from delegation.

Search