Sets which of the nine declarable key-protection backends a licensed tier uses. The tier transitions through BINDING and lands in DECLARED_PENDING_BIND — selecting a type declares an intent, it does not bind a backend, so the tier does NOT become ACTIVE here. A mechanism this deployment does not OFFER right now is refused 422 before anything else is evaluated (see the 422 below), and the tier listing reports that same verdict per token as offered, from the same composition, so a picker cannot present an option this operation refuses. When the selected backend provides LOWER custody assurance than the tier's name implies (for example ENTERPRISE on softhsm), the change is refused 422 unless assuranceDowngradeConfirmed is set; a same-or-higher-assurance selection needs no confirmation. A selection that would MOVE the tier's resolved key-encryption key is refused 409 while any tenant on that tier holds key material; a selection that provably does not move it — re-selecting the type the tier already holds — is permitted even then. blastRadiusAcknowledged records that the operator was shown, and accepted, how many tenants the change actually moves — that is assignedTenantCount, not the edition's total; it is recorded on the audit row and is not itself a gate, so omitting it is recorded as false and refuses nothing. Every accepted change emits a signed admin audit event carrying who, when, the tier, the from-to transition and both acknowledgements. This request carries no credential and no PIN. Required scope: admin.platform.key-backend.tier.manage.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||