Scenario
An administrator needs to remove a registered user from an application group in AIC to revoke
group-scoped access or correct an incorrect membership. This is commonly required during role/team changes, offboarding, or remediation after an access review. For
Policy-on applications, removing the user from the group is the required way to revoke inherited roles that cannot be revoked individually.