Update on Role Change Propagation General Availability
- We’re getting ready to move this capability to General Availability. As part of that preparation, we’ll be closing this announcement thread and posting a new, updated announcement with the final rollout plan.
This enhancement is brought to you by
Idea AI-I-51
Description
This release introduces a key improvement to ISC Role Management. Now, when access is removed from a Role definition, the corresponding access can also be automatically removed from users assigned to that Role—helping reduce the risk of over-provisioning and keeping access aligned with intended Role design.
With this release, you can now configure ISC to automatically de-provision access from users when it’s removed from the Role they are a member of. Access that is added to a Role definition will continue to be propagated automatically and will operate in the same manner as it does today.
New Capabilities
Role Change Propagation allows you to configure ISC to automatically remove access assignments from users when access rights are removed from their associated Role definitions.
- A Global Setting is now available to enable/disable the role change propagation feature.
- The following access changes are now propagated by ISC:
- Removal of an Entitlement from a Role
- Removal of an Access Profile from a Role
- Removal of an entitlement from an Access Profile included in a Role
- Removal of a Role’s dimension or removing an entitlement or access profile from a Role’s dimension.
Problem
Currently in ISC, removing access rights from a Role doesn’t automatically remove that access from users assigned to it—leading to potential over-provisioning and increased risk.
Solution
Role Change Propagation provides the ability to configure ISC so that when access rights are removed from a Role definition, the corresponding access assignments are removed from users who have the Role assigned.
Note: This is an optional capability. A Global Setting is available to enable/disable the Role Change Propagation feature.
When the following access rights are removed from Role’s definition, the corresponding access assignments will be removed from users who have the Role assigned:
- Removal of an Entitlement from a Role
- Removal of an Access Profile from a Role
- Removal of an entitlement from an Access Profile included in a Role
- Removal of a Role’s dimension or removing an entitlement or access profile from a Role’s dimension.
Who is affected?
Role Change Propagation is available for all customers.
Action Required
Role Change Propagation is a configurable capability which is disabled by default. Customers who opt to use this capability must enable the Role Propagation system feature in ISC Global Settings.
Important Dates
Last updated on July 22, 2025
Prior to the enablement of this new capability, our testing team uncovered an issue which had the potential to result in inaccurate de-provisioning. After careful review, the Engineering team determined that a design change was necessary to effectively address the issue. As a result, Role Change Propagation general availability is now planned for Q4 2025. Enablement will begin mid-Q4 and is expected to be fully complete by the end of December.
While our decision to delay the release was made in the best interest of all our customers, we fully understand that unexpected changes in feature delivery dates can have significant impact, and we sincerely apologize for any disruption caused by this delay.


