# updateUserRoles

## Overview

Reconciles a user's role assignments to match the desired set. Assigns new roles and revokes removed roles.

## Modules Commands Used

- [user-management] AssignRoleToUser
- [user-management] RevokeRoleFromUser

## Exception Handling

| Error Code | Description |
| --- | --- |
| USER_MANAGEMENT_USER_NOT_FOUND | The specified user does not exist |
| USER_MANAGEMENT_USER_NOT_ACTIVE | The user is not in active status (assign path only) |
| USER_MANAGEMENT_ROLE_NOT_FOUND | A specified role does not exist |
| USER_MANAGEMENT_ROLE_NOT_ACTIVE | A specified role is not in active status (assign path only; not yet in revokeRoleFromUser error union) |
| USER_MANAGEMENT_ASSIGNMENT_NOT_FOUND | Role assignment not found during revoke (silently ignored) |
