Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is there a way to have internal users that can have only access to specific projects?

Brianna Barnes
Contributor
January 16, 2019

I've googled and looked through the community and I've found a few that explain to mess with permission schemes. But this is lengthy, seeing how my company has a very large amount of projects for various teams and subsets of those teams. So I'm looking to see if there is an easier way to accomplish this?

 

It's for a 3rd party company that is working with us. We'd like by default that they can't see anything unless we grant that access. I have created a group, if that helps.

1 answer

2 votes
Joe Pitt
Community Champion
January 16, 2019

The solution isn't simple. Don't use groups. 

First, by default JIRA has a horrible permission scheme that violates security best practices by allowing everyone that can logon to do just about everything.

 

JIRA works by GRANTING access. You can't restrict access. By default, it grants access to the group used to logon (see Global permissions to see the "can use" groups and admin groups).  This is where users are getting the access from.

 

  1. The FIRST thing you need to do to get control is to remove any groups with logon privileges from the permission scheme unless you absolutely want everyone to have that permission.
  2. Then I suggest you setup Project Roles for the various functions like, tester, QA, Browse Only, etc.
  3. By using roles one permission scheme will cover all projects. The project admin controls project role membership

 

This may be a big effort, but it will pay off down the road by making it easy to control access.

 

Most of the 'old timers' use project roles. It meets the best practice for security and gives complete control to the project lead for access to their project. JIRA comes with many project roles, but you can add more if you have a special need.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events