# Deprovisioning business roles

**URL:** <https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, roles\
**Created:** [March 26, 2025, 6:27pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482 "2025-03-26T18:27:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramthetribo](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@ramthetribo](https://developer.sailpoint.com/discuss/u/ramthetribo)\
**Post date:** [March 26, 2025, 6:27pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/1 "2025-03-26T18:27:18Z")

</div>

Hello,

We have IIQ 8.4 p1.  
For some old terminated users, entitlements section don’t have roles or entitlements.  
However when i search for the user via identity warehouse, seeing some roles in the ‘Assigned Role Summary’. Can you please let me know how can we get these roles cleanup done? Should i be using provisioning plan/ Account request / Attribute request and execute the plan ? If you have done something similar for business role, can you share your inputs ?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![SanjeevIAM](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sanjeeviam/32/21695_2.png) [@SanjeevIAM](https://developer.sailpoint.com/discuss/u/SanjeevIAM)\
**Post date:** [March 26, 2025, 7:51pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/2 "2025-03-26T19:51:22Z")

</div>

Have you tried to remove the roles using APIs (method available on Identity object) that may have caused the issue? You should use provisioning plan to add or remove roles.  
You can try to executing the plan for a particular user and refresh user identity to see if it resolves the issue.

---

<div class="post-metadata">

**Author:** ![ramthetribo](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@ramthetribo](https://developer.sailpoint.com/discuss/u/ramthetribo)\
**Post date:** [March 26, 2025, 8:24pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/3 "2025-03-26T20:24:53Z")

</div>

Thanks, Sanjeev. Since this is not an account on the application, can you show me how to build the plan to remove roles from the identity ? I was thinking remove(Bundle bundle) method in identity will do that but it didn’t ☹

---

<div class="post-metadata">

**Author:** ![SanjeevIAM](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sanjeeviam/32/21695_2.png) [@SanjeevIAM](https://developer.sailpoint.com/discuss/u/SanjeevIAM)\
**Post date:** [March 26, 2025, 11:04pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/4 "2025-03-26T23:04:05Z")

</div>

Here is an example code to remove role using a plan

```auto
ProvisioningPlan plan = new ProvisioningPlan();
  plan.setIdentity(identityObj);
  ProvisioningPlan.AccountRequest accReq = new ProvisioningPlan.AccountRequest();
  accReq.setApplication("IIQ");
  accReq.setNativeIdentity(identityName);
  accReq.setOperation(ProvisioningPlan.AccountRequest.Operation.Modify);

  accReq.add(new ProvisioningPlan.AttributeRequest("assignedRoles",ProvisioningPlan.Operation.Remove,"<YOUR ROLE NAME>"));
  plan.add(accReq);

```

But I assume you would not want to remove role one by one using name and the following code gets the role list present in Assigned Role Summary to create a plan to remove role

```auto
Identity identityObj =context.getObjectByName(Identity.class,identityName); 
  String roleSummaryCSV = identityObj.getAssignedRoleSummary();
  if(roleSummaryCSV != null){
  List roleList = Util.csvToList(roleSummaryCSV);
  ProvisioningPlan plan = new ProvisioningPlan();
  plan.setIdentity(identityObj);
  ProvisioningPlan.AccountRequest accReq = new ProvisioningPlan.AccountRequest();
  accReq.setApplication("IIQ");
  accReq.setNativeIdentity(identityName);
  accReq.setOperation(ProvisioningPlan.AccountRequest.Operation.Modify);

  accReq.add(new ProvisioningPlan.AttributeRequest("assignedRoles",ProvisioningPlan.Operation.Remove,roleList));
  plan.add(accReq);
}

```

---

<div class="post-metadata">

**Author:** ![ramthetribo](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@ramthetribo](https://developer.sailpoint.com/discuss/u/ramthetribo)\
**Post date:** [March 27, 2025, 6:15pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/5 "2025-03-27T18:15:40Z")

</div>

Hi Sanjeev,  
Thanks for the detailed code snippet. I have tried using it for removing just one role but its’ not removing the role. Can you review below one and let me know your thoughts. Am i missing anything?

Identity identity = (Identity) it.next();

Provisioner p = new Provisioner(context);  
ProvisioningProject project = new ProvisioningProject();  
ProvisioningPlan plan = new ProvisioningPlan();

p.setArgument(“noFiltering”, true);

plan.setIdentity(identity);  
ProvisioningPlan.AccountRequest accReq = new ProvisioningPlan.AccountRequest();  
accReq.setApplication(“IIQ”);  
accReq.setNativeIdentity(identity.getName());  
accReq.setOperation(ProvisioningPlan.AccountRequest.Operation.Modify);

accReq.add(new ProvisioningPlan.AttributeRequest(“assignedRoles”,ProvisioningPlan.Operation.Remove,“SAP - ReadOnly”));  
plan.add(accReq);

project = p.compile(plan);  
p.execute(plan);

---

<div class="post-metadata">

**Author:** ![SanjeevIAM](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sanjeeviam/32/21695_2.png) [@SanjeevIAM](https://developer.sailpoint.com/discuss/u/SanjeevIAM)\
**Post date:** [March 27, 2025, 7:00pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/6 "2025-03-27T19:00:26Z")

</div>

Can you print/log the project before executing it and see what you see in the project. Also in your case try getting list of assigned roles from identity object and log/print it to check if you see this role in the list or not.

---

<div class="post-metadata">

**Author:** ![pravin\_ranjan](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pravin_ranjan/32/6771_2.png) [@pravin\_ranjan](https://developer.sailpoint.com/discuss/u/pravin_ranjan)\
**Post date:** [March 27, 2025, 7:48pm UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/7 "2025-03-27T19:48:40Z")

</div>

@ramthetribo did you tried with refreshing those identity with this checked “refresh role metadata for each identity” ?

---

<div class="post-metadata">

**Author:** ![ramthetribo](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@ramthetribo](https://developer.sailpoint.com/discuss/u/ramthetribo)\
**Post date:** [March 28, 2025, 3:55am UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/8 "2025-03-28T03:55:58Z")

</div>

Hello @SanjeevIAM It worked with when i got roles via Assigned role summary and passed it to the code. Thank you very much for your help!

---

<div class="post-metadata">

**Author:** ![ramthetribo](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@ramthetribo](https://developer.sailpoint.com/discuss/u/ramthetribo)\
**Post date:** [March 28, 2025, 3:57am UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/9 "2025-03-28T03:57:59Z")

</div>

@pravin_ranjan Thanks for the suggestion. Just FYI: Just the refresh didn’t work. Please see my other post. When i fetched assigned role summary to passed it to the Attribute request and it worked as Sanjeev said.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [May 27, 2025, 3:58am UTC](https://developer.sailpoint.com/discuss/t/deprovisioning-business-roles/105482/10 "2025-05-27T03:58:55Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
