Entitlemnet catalog not show all groups available

Hi CoSailors.

I am having troubles to understand how entitlement aggregation works due to the following scenario that I am facing:

Connector: Google Workspace SaaS connector

1.- I ran the entitlement aggregation without delta aggregation enabled and got 72 groups
2.- I ran account aggregation without delta aggregation enabled and got 109 accounts

Before performing the following steps I already have all the accounts and the group catalog from Google.

3.- I enabled delta aggregation
4.- I ran entitlement aggregation and I got 0 because the owner didn’t create any new group or performed any modification to the groups, so in my mind the expected result is to see in SailPoint the 72 groups that I got before, however, when I go the entitlement tab in SailPoint where the 72 groups used to be, The interface now shows 0 entitlements. So I disabled delta aggregation and performed entitlement aggregation again and i got again the 72.

I think is wrong that SailPoint deletes all the entitlements when nothing changed with the groups.

Could anybody, please, help me to understand?

Kind regards.

Hi @JaimeIvanHuertaMontes While I am definitely not an expert on Google stuff - have you double checked the scopes associated with the Service Account? FWIK, different permissions are required to query audit events (used in delta agg). Admittedly, ISC shouldn’t (IMHO) delete groups if there is a prob with permissions, but just worth checking.