Have a strange behavior. When a request (new or change) goes thru the approval workflow and is approved at every step with the exception of the last step, which rejects the request, the rejected request (still has roles) gets auto provisioned in the back end R3. In the Workflow->Auto Provisioning->Auto-Provisioning Type is set to "Auto-Provision at end of request". It was my belief that meant approved requests, not all requests. Is there a workaround for this? GRC 5.3 SP9
You can change it to request level and still security can make changes to the role assignment. There is no need to add additional stage.