In my experience that I documented in my linked topic, if you run an access item campaign against a specific access profile, identities that were assigned that access profile automatically via a role are not included. Hope this helps