Basics: what CIAS is and what it is not
The terms and the split you need to understand any CIAS flow: the objects and their owners, tenant and group, the two permission matrices, the write direction, and the ceiling.
Topics in this subject area
- 1.CIAS as a bridge to the identity provider
What CIAS does and what it explicitly does not do: no login, no passwords, no checking of permissions on data. With the table “CIAS does / CIAS does not”.
- 2.The objects and who owns them
User, tenant, role, role grant, group, attribute, module: what each object is, who owns it, and what Keycloak keeps of it as a copy.
- 3.Tenant, organization, group
Two structural terms, not three. The tenant separates data, the group bundles roles, “organization” is only Keycloak's name for a dynamic tenant. With the one question that decides, and a scenario played through.
- 4.The two permission matrices
How a permission is carried (realm role, client role, organization role, group, attribute) is CIAS. What a permission allows (model, operation, field) is CDMS. Why CIAS does not keep a model-operation matrix.
- 5.The ceiling: nobody grants more than they have
The rule above every write path: a grant never exceeds the granter. What it means for roles, groups and attributes, and how it differs from delegation.