Rejected Fulfillment Request Leaves Automatically Created Revocation Request Active in RSA Governance & Lifecycle
2 months ago
Originally Published: 2025-06-19
Article Number
000073457
Applies To

RSA Product Set:  RSA Governance & Lifecycle
RSA Version/Condition: 8.0 P06

Issue

Upon creating an entitlement fulfillment request with the revocation dates included, two distinct requests are created: one for the initial fulfillment of the entitlement and a separate one for its removal. If the fulfillment request is rejected, the associated revocation request remains active and unlinked. 

Cause

When a Change Request is created with a revocation date, 2 requests get automatically created: one for Access, another for the revocation. The revocation request is an independent request which follows the Workflow associated with it.

Actions performed on Access granting Change Request will not impact the revocation Change Request as they are independent and will function as per their separate Workflows are configured.  Change Requests' Workflow paths can neither be modified nor stopped by other Change Requests as both are independently created. 

Resolution

This is functioning as designed.

Workaround

One of the approach is not to create the revocation Change Request immediately when Add access request is generated, but instead to create the revocation Change Request only when the revocation date arrives. By doing so, if the Add Access Change Request is Rejected before the revocation date the revocation request itself will not be created.

Notes

An RFE for the change in design of handling the revocation request has been created.