Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Project members can see and assign users who are not members of that project

STX November 10, 2023

In our company-managed project, members can see and assign users to issues that are not part of that specific projects. That's a pretty big data protection issue in my book. Why is that the standard setting and how/where can i adjust it?

 

1 answer

1 accepted

0 votes
Answer accepted
Walter Buggenhout
Community Champion
November 10, 2023

Hi @STX and welcome to the Community!

Check the permission scheme attached to your project, first of all via project settings / permissions. Make sure that browse project / assignable user / ... is not set to any logged in user, as that would effectively make your project accessible to anyone with a Jira license, regardless of who you add to your project on the people tab. If you want to restrict access to a project to a limited set of users, you need to set up a permission scheme where you properly configure permissions using roles. See this support article for more details.

Hope this helps!

STX November 10, 2023

Hey,

thanks, I will look into that. I just cannot wrap my head around why the standard setting right after buying a license and setting up your project is, that ANYONE with a Jira account can just access your enviroment. I've never ever seen that done with any other cloud service.

Walter Buggenhout
Community Champion
November 10, 2023

Hi @STX,

Atlassian indeed strongly believes in open work (Research on the benefits of open work) and openness is therefor a default starting point.

When organizations start using Atlassian tools, it is usually not the case that there are suddenly dozens or hundreds of projects, spaces or service desks created and live in production after a couple of days. So adapting (and reusing) the permission schemes to match your company style / culture is not too difficult to accomplish. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events