I need to create a read-only group in Jira. I went ahead and created one and only gave them "Browse Project" capability. From what I understand, I now need to go into each workflow and set a condition so that all other groups can transition in the workflow other than my read-only group.
Is there a way to set a condition that just says read-only CANNOT transition in the workflow? Otherwise I have to add like 5 conditions to each transition to each workflow for all my projects. Is there a way to add just one condition that simply states that this group is the only group that cannot do this?
Alternatively, is there a simpler way to set up a read only group in Jira? It was super easy in Confluence, but does not seem to be as straight forward a set-up in Jira.
Hi @Elior Odinak,
If you are on jira 6.3 or above you will be seeing "Transition Issues" permission in permission scheme, and If you are not adding your read-only group/user here they won't have permission to make any transitions
I didn't add the group there and the user can still transition. The only permission they are added to is the Browsing permission, so they can see the projects.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Elior Odinak,
Can you give more details on this
Jira version? if it is on 6.3 or above check this "Transition Issues" permission who are all having access/permission
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Jira Software Cloud.
I checked the transition issues permission and the only ones who have access are "Application access: Any logged in user" and some Project role for atlassian add-ons. So not my group or role that I created for Read Only users.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
That makes sense here, "Any logged in user" is like giving access to all users
so anyone has access to browse your project, they can make the transitions too
If you are having access to modify permission scheme then you need remove "any logged in user" and add the "group/project role" whom you want to grant access for making transitions
This page may help in permission scheme configuration: https://confluence.atlassian.com/adminjiracloud/configuring-project-permission-schemes-868982875.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ok so according to that logic I would need to remove any logged in user from all the permissions (which is a lot of permissions) for all my projects, since that is how it is set up at default.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes. Out of the box JIRA has a terrible security model.
JIRA works by GRANTING access. You can't restrict access. By default, it grants access to the group used to logon (used to be JIRA-users but may be different on your version). This is where they’re getting the access from.
This may be a big effort, but it will pay off down the road by making it easy to control access.
Most of the 'old timers' use project roles. It meets the best practice for security and gives complete control to the project lead for access to their project. JIRA comes with many project roles, but you can add more if you have a special need.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, I read this one. The issue I have is I'm going to need to add like 5 conditions to every transition to 3 separate workflows. I was wondering if there was a way to add 1 condition that says this group is the group that DOES NOT have permission to do this. The way this is set up, the condition is for a particular group that CAN do this action which means I need to add every group vs just adding 1 group that can't do it. Hope that makes sense.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.