Changes to a CONNECT THROUGH privilege definition are effective immediately, so the next request submitted in a proxy connection following a change to a CONNECT THROUGH privilege uses the new definition.
Dropped roles are removed from the CONNECT THROUGH privilege definition. Therefore, a rule may be left with no defined roles. When you drop all roles assigned to a CONNECT THROUGH privilege definition, Vantage grants the affected proxy users PUBLIC privileges only.