How to trigger a powershell script in a Certification revoke action?

Hello,
I have an use case involving these components: Identity Now, Active Directory (AD), IQService configured in the AD source and OneIdentity active-roles.

The Client required a certification campaign in which the revoke should trigger a powershell script to change the group membership.

Has anyone ever made a similar script? And which IdN rule should I use to call this script?
Thanks, Andrea.