if a user authority gets removed, we need to call a token endpoint to remove user token for said user and force logout of their session