Intercept Delete Functionality
When an identity is removed from a workgroup, they effectively lose permissions or access to certain functionality that is associated with the workgroup. That change in permissions is now reflected in the identity cube and can be viewed by running the Data Extract task and reviewing the Task Results. This is driven by the Created By and Modified By attributes.