Hi @venus
The best approach will be to use Identity IQ Reports. The Datasource object can be IdentityEntitlements and filter with grantedByRole equals to false to get the users and their entitlements which are not assigned by Role.
Refer this solution which will help to filter on IdentityEntitlements. : Active employees of a department with their applications and related entitlements - IdentityIQ (IIQ) / Discussion and Questions - SailPoint Developer Community Forum