CodamAIDocs
Topicdone

Tenant, organization, group

Two structural terms, not three. The tenant separates data, the group bundles roles, “organization” is only Keycloak's name for a dynamic tenant. With the one question that decides, and a scenario played through.

Variants
TenantOrganization (Keycloak only)GroupParent/child structure (deliberately not)

What this is about

Three words come up again and again when talking about the structure of customers: tenant, organization and group. They sound like three things. In CIAS there are only two:

  • The tenant separates data. What is in tenant A, nobody from tenant B can see.
  • The group bundles roles. Whoever is a member gets all roles of the group.
  • The organization is not a thing of its own. It is Keycloak’s name for a dynamic tenant.

The one question that decides

When someone says “we need an organization for X”, a single question helps:

flowchart TB
    Q{"Should these people be unable<br/>to see the others' data?"}
    Q -- "yes" --> T["Own tenant<br/>data separated"]
    Q -- "no" --> Q2{"Should they get<br/>the same roles together?"}
    Q2 -- "yes" --> G["Group<br/>a bundle of roles"]
    Q2 -- "no" --> N["individual<br/>role grants"]

Only a “yes” to the first question costs a tenant. A tenant is heavy: it gets its own data, often its own database, and every request runs under exactly one tenant. A group is light: it is only a list of roles and members.

The three terms side by side

What each term means in CIAS
TenantOrganizationGroup
Jobseparates datanone of its ownbundles roles
Who keeps it?CIASnobody, it follows the tenantCIAS
Record in CIASyes, with key, type, statusno, only the ID as a reference on the tenantyes, with roles and members
In Keycloakdynamic: organization. Static: nothingorganizationgroup in the realm
Shows up in the token asactive tenant of the requestorganization claim with membership and rolesthe roles it contains
Parents and childrennonono

The tenant

A tenant is a customer unit with its own, separated data. CIAS keeps it as its own record and is the only system that creates tenants. There are two types:

TypeHow Keycloak knows itHow a person is assigned to it
DYNAMICas an organizationmembership in the organization
STATICnot at allthrough the attribute tenant (and allowedTenants) on the account

The type is set on the tenant, not on the installation. More under Static and dynamic tenants.

The organization

Keycloak has its own feature called “Organizations”. CIAS uses it to represent a dynamic tenant in Keycloak. That means:

  • An organization is created when a company registers itself: CIAS then creates the organization and the dynamic tenant together. When a dynamic tenant is created through the admin API, the call names an organization that already exists. It has no life cycle of its own; it follows the tenant.
  • There is no organization administration in CIAS, no table of its own and no endpoint of its own for organizations.
  • In CIAS screens and APIs it is always called tenant. You only see the word “organization” in the Keycloak console, in the adapter and in the token, there as the claim organization.

The group

A group is a bundle of roles. Instead of giving every new colleague in support ten roles one by one, you create the group support once and make the colleague a member.

  • A group may carry roles of several modules at once, such as CDMS and CRMS roles.
  • A group applies platform wide. It is not assigned to a tenant.
  • A group can be the default group: every new account joins it.
  • Being a member means: you get the roles. It does not mean that you see the data of other members.

More under What a group is. How client roles from a group behave under a dynamic tenant is described under Group roles under dynamic tenants.

No parents and children

A tenant has no parent tenant, and an organization has no sub-organization. This is on purpose. A tenant is a line of separation. If it had children, each of these three questions would need a fixed answer:

  1. If the parent tenant is suspended, are the children suspended too?
  2. Do the roles from the parent tenant also apply in the children?
  3. Does the parent tenant see the children’s data?

Every answer would be a security decision. That is why there is no tenant hierarchy. Every tenant stands on its own.

Customer wants a “holding with subsidiaries”
Should the subsidiaries see each other's data?Shared roles?Solution in CIAS
no–one tenant per subsidiary
yesyesone tenant, plus groups for the shared role bundles
yesnoone tenant, roles granted one by one

Scenario: two companies, one application

Two customers use the same application: Nordbau GmbH and Südlogistik AG. Neither may see the other’s data.

How the structure is created
  1. 1
    Admin→Keycloak
    creates the organizations nordbau and suedlogistik and makes Anna and Ben members of them
  2. 2
    Admin→CIAS
    creates the tenant nordbau, type DYNAMIC, with the ID of the organization nordbau
  3. 3
    Admin→CIAS
    creates the tenant suedlogistik, type DYNAMIC, with the ID of the organization suedlogistik
  4. 4
    Admin→CIAS
    creates the group sachbearbeitung with the roles customer-read and order-edit
  5. 5
    CIAS→Keycloak
    creates the group in the realm, marked with cias-managed=true
  6. 6
    Admin→CIAS
    makes Anna (Nordbau) and Ben (Südlogistik) members of the group
    Result: Both have the same roles, but each only on their own tenant's data

What applies now:

AnnaBen
Tenantnordbausuedlogistik
Roles from the groupcustomer-read, order-editcustomer-read, order-edit
sees customers of Nordbauyesno
sees customers of Südlogistiknoyes

The group gave Anna and Ben the same permissions. The tenant makes sure they use these permissions on different data. The shared group does not connect the two.

Sources in the code and the knowledge base
  • CIAS/CLAUDE.md – §9 tenant and organization model, §10 tenant types
  • CIAS/cias-tenancy/docs/adr – ADR-006, ADR-020, ADR-037
  • CIAS/cias-authorization/docs/adr – ADR-034
  • CIAS/cias-tenancy – V1__cias_tenant.sql (no parent field)
  • CIAS/cias-authorization – V4__cias_group.sql, V5__cias_group_default.sql
  • CIAS/cias-iam-keycloak – KeycloakOrganizationAdapter, KeycloakRoleAdapter
Search