I put this on Compass and opened a ticket for a client but haven’t received a response yet, so trying here as well.
We have the RapidSetup Leaver configured to remove all assigned roles upon termination. This sets the negative="true"
flag on all RoleAssignments associated with an identity (RapidSetup and Business role types).
The issue I am running in to is upon rehire (which is a non-rapidsetup workflow we developed since rapidsetup doesn’t have it’s own rehire event), the negative flag is sticking around on RoleAssignments which are tied to Business roles. RapidSetup Birthright roles that are to be re-assigned back during that rehire event are successfully given back to the identity with no negative flag, but the Business roles that someone should have re-assigned via an identity refresh with refresh roles/provision assignments is not happening because the negative flag is not removed.
Is this expected behavior? Is there something specific that we should be doing during rehire to make sure the negative flag is not retained on these business RoleAssignments? Ideally, the RapidSetup leaver would just remove the RoleAssignments rather than setting the negative flag and we would not be in this situation at all.
This is on 8.1p1.