Any TTL for LDAP role mapping cache?

I know it has such setting for script authentication. Just want to see the same thing for using LDAP. Since I'm wondering any change in LDAP server may affect user permission in Splunk in a short period of time.

Last time, we found users can't get permission to access flashtimeline. But certainly no permission has been touched.

A user's LDAP role memberships are re-checked whenever they log in.