Revoke roles

Last update:
Aug 21, 2026
Scenario
An administrator needs to revoke roles from a user in AIC to remove unnecessary access, remediate over-permissioning, or support offboarding and compliance reviews. Revocation may be performed directly (policy-off) or indirectly by updating group membership (policy-on), depending on inheritance behavior.
Prerequisites
  • Administrator has access to the Users page with role-based permissions.
  • The user is registered and searchable in AIC.
  • The admin knows whether the access is direct or inherited (Policy-on vs Policy-off).
Steps
  1. Sign in to Aikyam Identity Console.
  2. Navigate to Users and open the user profile.
  3. Go to the Roles tab and select the relevant application from the Application dropdown.
  4. Determine the revocation path :
    • Policy-off (direct roles): revoke the role directly from the Roles tab.
    • Policy-on (inherited roles): roles cannot be revoked individually; proceed by removing the user from the group that grants the role.
  5. Validate access after revocation by re-checking the user’s Roles tab for the same application.
Note:
  • Policy-on: revoke inherited access by removing group membership, not by revoking the role.
  • Policy-off: roles are manually managed and can be revoked individually.
  • Roles and groups are supported for OHID tenants only.

On this page

Powered by Aikyam @2025 All rights reserved