Hi,
following setup:

Identity Governance client version 3.0.0 was built on Monday, December 4, 2017 8:43 PM from revision 24321
Identity Governance server version 3.0.0 was built on Tuesday, December 5, 2017 1:10 AM from revision 24331
Identity Manager AE Permission Collector - Template Version 3.0.0
IDM 4.6.2, UserApplication 4.6.2

I added an entitlement ready loopback driver to IDM, added a resource in IDM which has the loopback driver group entitlement. This resource was added to a permission role in IDM.

In IG I created a business role which grants access to the prior created IDM permission role. Auto fulfillment is working fine and I was able to verify fulfillment a few minutes later.

Now I want to create a review of all permissions on users which where not granted by business roles (option "Review only items that have not been authorized by a business role"). The IDM permission role itself is - as expected - not in the list of the review items. But the resource is. How can I get rid of the resource in the list of the review items? The resource was implicit granted by the business role becaues the resource is assigned to the permission role which was assigned to the business role. Is there another way than explicit adding both to the business role?

regards
Daniel