# Bundle remove calculation in provisioning plan

**URL:** <https://developer.sailpoint.com/discuss/t/bundle-remove-calculation-in-provisioning-plan/100023>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, provisioning\
**Created:** [February 6, 2025, 3:49am UTC](https://developer.sailpoint.com/discuss/t/bundle-remove-calculation-in-provisioning-plan/100023 "2025-02-06T03:49:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shivakarasani199](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@shivakarasani199](https://developer.sailpoint.com/discuss/u/shivakarasani199)\
**Post date:** [February 6, 2025, 3:49am UTC](https://developer.sailpoint.com/discuss/t/bundle-remove-calculation-in-provisioning-plan/100023/1 "2025-02-06T03:49:41Z")

</div>

## Which IIQ version are you inquiring about?

8.2P7

Hello Community , I have a use case where i can have only one entitlement (assigned via IT Role) at any given point of time.  
So we are trying to revoke the existing IT role Bundle of that application before adding the requested IT Roles.

Is there a way we can modify the provisioning plan to achieve this ? I tried multiple ways but not able to progress on revoking the existing IT roles and adding newly requested role from current provisioning plan

I am using Add Entitlement Operation , WebserviceBeforeOperationRule

```auto
ProvisioningPlan plan = new ProvisioningPlan();
  Identity identity = plan.getIdentity();
  String identityName = identity.getName();
  AccountRequest accReq = provisioningPlan.getAccountRequest("ApplicationName");
  if (accReq != null) {
    String nativeIdentity = accReq.getNativeIdentity();
    Identity identity = context.getObjectByName(Identity.class,identityName);
    if (identity != null) {
      List<Bundle> roles = identity.getAssignedRoles();
	  List accReqList = new ArrayList();

       if (roles != null) {
       for (int i = 0; i &lt; roles.size(); i++) {            
          	Bundle roleBundle = roles.get(i);
            if (roleBundle != null) {
            	String name = roleBundle.getDisplayName();
              if (name.startsWith("ITRole_Appx")) {
                log.error("role name starts with ITRole_Appx >> "+name);
                AccountRequest accountReq = new AccountRequest();
                accountReq.add(new AttributeRequest("assignedRoles", ProvisioningPlan.Operation.Remove, name));
                accReqList.add(accountReq);
              }
            }
          }
          ProvisioningPlan newPlan = new ProvisioningPlan();
          newPlan.setNativeIdentity(identityName);
          newPlan.setAccountRequests(accReqList);
          Provisioner provisioner = new Provisioner(context);
          provisioner.execute(newPlan);
        }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![pszupiluk](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pszupiluk/32/22071_2.png) [@pszupiluk](https://developer.sailpoint.com/discuss/u/pszupiluk)\
**Post date:** [February 12, 2025, 2:51pm UTC](https://developer.sailpoint.com/discuss/t/bundle-remove-calculation-in-provisioning-plan/100023/2 "2025-02-12T14:51:55Z")

</div>

Hi Shiva,

Since you need a change on IT role level, I would recommend to detect this situation in LCM Provisoning workflow and adding remove IT role operation to the request. Then connector would get at the same time two operations - one to add entitlement and other to remove.

As for your approach, code looks more or less fine. Do you get any error when executing this?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [April 13, 2025, 2:52pm UTC](https://developer.sailpoint.com/discuss/t/bundle-remove-calculation-in-provisioning-plan/100023/3 "2025-04-13T14:52:05Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
