Hi @mcheek
Regarding this statement : “Similarly if you remove an entitlement from a role, I remember it not removing that from the identities assigned the role“
==> This is now supported as described here : New Capability: Role change Propagation - Announcements / Product News - SailPoint Developer Community