Hi everyone,
I'm looking to make some Jira access configuration/ process changes for a growing organisation and would appreciate advice from others who have implemented something similar.
We have multiple business functions using Jira with around 30+ Jira projects/spaces across these functions and their teams. Some users work only within their own team, while others need access across multiple projects. We're also likely to have Jira projects linked to Confluence spaces in the future.
What We're Trying to Achieve
- Simple and scalable access management
- Support for cross-project collaboration
- Strong governance and auditability
- Minimal central administration
- Alignment between Jira and Confluence permissions where possible
Current Thinking
Our current thinking is:
- Use Entra ID groups for licence assignment only at current and unsure if this should be used further
- Manage Jira access within Jira rather than through Entra ID group synchronisation
- Use Jira groups, project roles and permission schemes to manage access
- Maintain a small number of standard permission schemes
- Delegate some access management to designated project owners where appropriate
Questions
How do you manage access in a similar environment with multiple teams and around 30 projects/spaces?
- Jira groups?
- Project roles?
- Permission schemes?
- A combination of these?
Do you manage project access directly in Jira, or through your identity platform?
Have you successfully delegated access management to Project/Space Administrators without giving them wider Jira administration permissions?
- Can they manage access only for their own projects/spaces?
- What controls or limitations do you apply?
How do you prevent permission scheme, role or group sprawl as the number of projects grows?
If you use both Jira and Confluence, how do you keep permissions aligned between the two platforms?
Looking back, what would you do differently if you were designing your Jira access model from scratch?
I'd be particularly interested in hearing how other organisations balance governance with allowing project owners enough control to manage their own teams.
Thanks in advance for any advice.