delete-user-geographic-access-scope
dci delete-user-geographic-access-scope
Clears the geographic scope assigned to a user who belongs to the target customer, leaving it unassigned. The authenticated tenant must be the hierarchy root, and the target must be that root customer or one of its child customers. Repeating the request is idempotent. Requires the UsersManager permission.
Examples
# Preview clearing a user's geographic scope without sending a request.
dci delete-user-geographic-access-scope <target-customer-id> <user-id> --dry-run
A local preview of the operation; the scope is unchanged.
# Clear the scope without the confirmation prompt, for scripts.
dci delete-user-geographic-access-scope <target-customer-id> <user-id> --yes
Exit code 0 and no output; `dci get-user-geographic-access-scope <target-customer-id> <user-id>` now reports `type: unassigned`.
Output
On success, this command produces no response data.
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 409 | 21 | RESOURCE_CONFLICT | The operation conflicts with the resource's current state. |
| 429 | 50 | RATE_LIMITED | Too many requests. Retryable — the CLI reports the server-provided delay. |
| 500, 503 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- get-user-geographic-access-scope — Get a user's geographic scope
- update-user-geographic-access-scope — Replace a user's geographic scope
- delete-customer-geographic-access-scope — Clear a customer's geographic scope
- API reference: DELETE /rbac/v1/customers/{targetCustomerId}/users/{userId}/geographic-scope
Aliases: deleteusergeographicaccessscope