Short answer: treat data consent revocation and active session revocation as separate controls, then connect them with an explicit policy: stop newly forbidden data operations immediately, but terminate the whole session only when identity risk, account recovery, or regulation requires it. Decis...
Source: [Dev.to](https://dev.to/leopoldholm3736/permission-withdrawal-auditable-data-consent-and-active-session-access-lg0)