Does AP harvesting feature work at "User-level" or at "Resource-level"
I want to understand something about the Harvesting feature of Access Policy.
Does Harvesting feature occur at "User-level" or at the "Resource-level"?
By enabling the access policy's retrofit flag, we are allowing the evaluation of policy for the user. The user can have have multiple resources in their accounts tab. If the harvesting feature is enabled, will it harvest all the resources of this user, or will it harvest only that resource of the user whose entitlements are defined in the access policy?
To understand this question, let us consider this scenario-
Let us say there is a Role in OIM. There is one Access Policy associated to that Role.