During testing of this connector, I observed that the Add Entitlement operation performs a full replacement of the existing entitlement in spite of the schema attribute being marked as multi-valued. This means:
A user must always have exactly one entitlement assigned.
Multiple entitlements cannot coexist on a single user account within this DigiCert connector-based application.
Given this limitation, the claim that access certifications are supported raises questions. If a user can only ever hold one entitlement, and that entitlement must remain active at all times, the certification process seems impractical and lacks meaningful application.
Additionally, the Delete Account operation does not function as expected. I tested it using the UI-based LCS trigger for account deletion, the approach did not succeed but it is mentioned as a supported feature on the connector document.
Can someone please re-validate this documentation and let me know?