Skip to content
Proud to collaborate with Microsoft for Startups

identity.end-user.assign-group ​

Assign an end-user to a single access group within an app

Assign an end-user to a single access group within an app.

Inputs:

  • actor: Cognito sub or user UUID (required)
  • organization_uuid: owning organization — tenant check (required)
  • identity_app_uuid: the app's identity tenant (required)
  • end_user_uuid: the target end-user (the wire identity) (required)
  • group_slug: the access group to assign — must be a defined group (required)
  • force: accepted and ignored. Kept so callers written against the old last-owner guard keep working; there is no longer anything to force.

Outputs (terminal state_data):

  • end_user_uuid, previous_group, new_group, updated_at

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes——
organization_uuiduuidYes——
identity_app_uuiduuidYes——
end_user_uuiduuidYes——
group_slugstringYes——
forcebooleanNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
end_user_uuidstringYes——
previous_groupstringNo——
new_groupstringYes——
updated_atstringNo——
organization_uuiduuidNo——
identity_app_uuiduuidNo——
group_slugstringNo——
actorstringNo——
forcebooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
reasonstringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.end-user.assign-group",
  "initial_data": {
    "actor": "value",
    "organization_uuid": "value",
    "identity_app_uuid": "value",
    "end_user_uuid": "value"
  }
}