Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to restrict portal issue visibility to user submitted tickets

Kris Phipps March 15, 2023

I'd like to restrict the majority of our portal customers to only be able to view the issues that they submit themselves.  When I have their Organization linked to the ticket, these users are able to see all other tickets related to the Org, regardless of who created them.  Unlinking the Org drops portal visibility down to user generated issues.

I would like to be able to keep the Org tied to the issue.  I would also like to have a separate user role that would still be able to see all tickets across the org from within the portal.  Ideally this would all happen without the need for Help Desk agents to manually set security levels.  Wondering if there are opinions about setting this up using Groups vs Project Roles, how best to implement.

3 answers

0 votes
Dan Breyen
Community Champion
March 16, 2023

Your help desk users would be agents and wouldn't need to use the portal to see the tickets, but can see what ever they need from JSM itself.  You wouldn't need security, they could use a report, filter or JQL query.

0 votes
Dan Breyen
Community Champion
March 16, 2023

Under 'Customer Notifications' in Project Settings, I disabled the 'Organization added' setting. I also turned off under  Atlassian Project Settings for Jira Service Manangement to NOT share new requests with an organization. 

Screenshot came from this community request

JSM request - automatically share with organizatio... (atlassian.com)ProjectSettings.png

In the highlighted box, you would set this to NO.

0 votes
Suzi Firth
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
March 15, 2023

Hi @Kris Phipps 

I noticed this security issue when I was first testing Jira and is the sole reason I didn't use Organisations. It's a huge security issue that all users in the company can view emails being submitted by Management, HR and Payroll that should be confidential. It's also another reason why we never send user's their password via a Jira ticket.

I'm surprised this was overlooked by Atlassian or isn't more clearly stated in the documentation if you use that feature that this occurs.

Either way, I'm following along on this post as I'm interested to see how other admins have workaround it.

Kind regards,

Suzi

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events