Documentation
Permission Review for Jira
Opening the app
In Jira: Settings (gear icon) → Apps, then Permission Review in the left menu, under the Apps section at the bottom. Only Jira administrators can reach it.
If you land on a 404, you are almost certainly signed out or signed in as a non-administrator. Jira returns 404 rather than a permission error for admin pages.
What the first line means
«2 of 306 grants were decided by a person.» A permission scheme is born with dozens of grants — to project roles, to the assignee, to the reporter, to licence holders. Those are identical in every Jira in the world and nobody chose them. The rest — grants to a group or to a named person — were added by somebody, on purpose, for a reason usually nobody wrote down. Those are the ones a review is about.
The tabs
- Decided by a person — the short list above, in full.
- People with access — for each project and administrative permission, who actually holds it, and through which hand-granted group («via contractors»). Deactivated accounts are marked.
- Who has what — the same grants one row per holder instead of one per permission.
- Projects — every project, its type, and the scheme governing it.
- All grants — everything, for when you need to check a claim.
Every table has a filter box and sortable headers. The tab you are on is kept in the URL, so it can be bookmarked.
Findings
The report flags, in order of severity:
- permissions granted to anyone, including logged-out visitors;
- projects whose scheme is missing from the scheme list;
- projects governed outside the central schemes (team-managed);
- administrative power granted to named groups or people;
- deactivated accounts still sitting in groups that were granted permissions;
- administrative permissions that currently reach nobody through the scheme;
- schemes nobody uses, and schemes identical under different names;
- anything the scan could not read, and how much of the site it covered.
The report states its own limits. If the app cannot confirm it has Jira administration rights, the first finding says the report may be incomplete — schemes attached to no project are invisible without those rights. A review tool that omits in silence is worse than one that refuses to run.
Marking a review as done
Mark as reviewed records this moment as your baseline. From then on, the box at the top of the page shows only what changed since: grants that appeared or disappeared, and where the number of people holding a permission moved.
People are compared by count because the app stores no names (see the privacy policy). So it will tell you that four people could administer a project when you signed and five can today, and name today's five from live data. It cannot name the one who left — and it says so instead of implying otherwise.
Exports
Download report for auditors (Excel) produces a workbook with a one-page Summary and a sheet per question, headers frozen and filters on. CSV gives the same content raw. Both are built in your browser and carry your site's address at the top, so a reviewer holding several reports knows which Jira each one describes.
Forget stored data
Deletes the signed baseline immediately. The next report is read from Jira, as every report is. The button works even without an active subscription.
What it does not cover
- Permission schemes only — global permissions, issue security levels, notification schemes and project role membership are out of scope.
- Jira, not Confluence.
- It never writes to Jira: it holds no write scope and cannot fix anything for you.
- Site administrators can administer every project regardless of any scheme and are not returned by Jira's permission search. Where a permission reaches nobody through the scheme, the report says «nobody via the scheme» rather than «nobody».
Support
support@softyways.com. Include your Jira site URL and, if the problem is in the report, the numbers line at the top of the page — it says how many schemes, projects and API calls the scan used.