Role Assignment Is not Immediately Reflected

If you added new users and assigned them application roles but not any granular roles, ask the users to wait four (4) minutes before attempting to sign in; they can successfully sign into the environment only after a wait period of four minutes. Attempts by such users earlier than this wait period will result in the Not Allowed error.

If you changed the application role assignment of a user who was already assigned to another application role (for example, from Power User to Service Administrator), generate a Role Assignment Report using one of these methods ,to make the change effective in the environment:

To make all role assignment changes to be reflected in the Access Control screen, create a Role Assignment Report using one of the preceding methods.

Note:

If the users and application role assignment were imported using the following commands or REST APIs' the changes are immediately reflected in the Access Control screen: