How to Automatically Remove Manually Assigned Permissions

While permissions assigned by automated rules are removed when the conditions are no longer met, manually assigned permissions often require separate handling. This guide outlines two methods for automatically removing manually assigned permissions: when an employee leaves the organization and when they change departments.



When an employee leaves the organization

You can configure the system to automatically remove all manually assigned permissions when a user's account is deactivated.

This process is handled by a feature called Purge manual roles on delete. When this setting is enabled, all manually granted permissions are removed from a user account as soon as it is registered as deactivated.

To enable this feature please contact Identum support and request to activate Purge manual roles on delete for your organization.


Warning: This feature has a retroactive effect. Once enabled, it will apply to all deactivations.



When an employee changes department

You can configure the system to automatically remove specific manually assigned permissions when an employee moves to a new department.

  1. On the relevant Collection, enable Remove manually assigned department permissions on the Information tab.

  2. On the Permissions tab, enable both Department-specific permission and Remove manually assigned department permissions for each permission that should be removed on department change.

See Collections and Permissions: Settings for a full explanation of these settings.

Note: This feature is not retroactive. It will only apply to department changes that occur after the configuration is complete, unless the Department-specific permission setting was already enabled.

Last updated: