@Aprakash : Thanks for posting your question. For Role provisioning, you will have to first create Emergency Access (FireFighter) Roles and assign AD Endpoint's Entitlements (AD Groups) to those Roles. Please follow the below articles to create and configure your roles. Once done, end users will start seeing the Roles under the AD Endpoint via the flow of New Privilege Access -> AD Tile and "select role" button against the required AD Endpoint.
@Aprakash Please see the section "updating an account" in this article. This field can be customized and there is an example given for using an if-else statement as well