identities-api
Manages user identities within tenant organisations. Stores profile details, team associations, and lifecycle state. Other services resolve user identity via JWT claims (PrincipalId, email) and call this service to retrieve enriched profile data. Identities follow a state lifecycle: Pending → Active → Disabled or Superseded. Changing a PrincipalId creates a new record and supersedes the old one.