Block User
Objects used
Allowed roles
SUPER_ADMINORGANIZATION_ADMIN
Constraints
- The user concerned cannot access the application anymore.
PROJECT_ADMINs andORGANIZATION_ADMINs still see the user, but it is markedBLOCKED.- The user cannot be blocked if they are:
- The last permanent
PROJECT_ADMINprofile with typeDEFAULTin a project - The last
ORGANIZATION_ADMINin an organization
- The last permanent
Session impact
Access revocation is stateless and takes effect at the affected user's next token refresh, not immediately. The UI must clearly indicate this delay to avoid confusion.