Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Unrestricted access to Asset objects (Atlassian Cloud)?

Roshan Shinde
August 25, 2026

Hi All, 

I have a concern regarding accessing Asset objects.

 

I have created an Asset Schema and a couple of Object types in it. I have not configured any role in Schema or the Object types. In this case, every JSM user (i.e. agent), can access the Schema, the object types and its objects.

Does it mean that schemas and object types with no roles added for Object schema managers / Object schema developers / Object schema users / Object viewers are accessible to all JSM users?

 

Regards,

Roshan.

2 answers

3 votes
James Gamble
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 25, 2026

Hola Roshan,

No, leaving the schema and object-type roles unconfigured doesn’t intentionally make the Assets schema public to every JSM agent. Atlassian’s current permission model requires a user to have an appropriate Assets role, in addition to Jira/JSM access, to access the schema.

There’s a default behavior that may explain what you’re seeing. When a new Assets schema is created, Atlassian automatically adds the groups that grant product access to Assets to the Object schema developers role. If your JSM agents belong to one of those product-access groups, they may already have schema access even though you never manually assigned anyone.

I’d check Assets > Schemas > select the schema > Schema configuration > Roles and expand each role, especially Object schema developers. Atlassian documents the role behavior here.

Schema-level roles apply across the object types in that schema unless you configure more restrictive object-type permissions. So if a broad JSM product-access group is present at the schema level, that would explain why those agents can browse the schema, object types, and objects.

There’s also a separate behavior for Assets custom fields: Jira and JSM users can receive enough temporary Assets access to interact with an Assets field on a work item they can already access. That shouldn’t be confused with permission to browse the entire schema in Assets.

If you open the Roles tab and it genuinely contains no users or groups in any schema role, but ordinary JSM agents can still open the full schema directly in Assets, I’d want to see a screenshot of that Roles page and whether those users are Jira admins. That would differ from the documented permission model and warrants further investigation.

Thanks,

James

Roshan Shinde
August 25, 2026

Hi James, 

Thanks a ton for your response.

Let me share a screenshot of the Roles section of the Schema I have created. No Roles configured_AssetSchema.png

 

The same applies for the Roles in the Object Types. Nothing configured.

I am unable to find this "Default Product access" to assets that you are referring to, unfortunately.

 

- Roshan.

James Gamble
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 25, 2026

Hola Roshan,

Thanks for the screenshot. That changes the diagnosis. Your schema-level Roles page shows no users, groups, or apps assigned to any of the four schema roles, and you’ve confirmed the same is true at the object-type level.

Atlassian’s current Assets documentation says that access to Assets requires both a Jira role and the relevant Assets role. It also says schema roles can be assigned as Manager, Developer, User, or Object viewer.

There is one separate permission path that may explain what you’re seeing. Atlassian automatically grants Jira and Jira Service Management users an Object Schema User role when they interact with an Assets object custom field on a work item they already have permission to edit. Portal users can also receive temporary view access when an Assets field is exposed on a request type. Those permissions are specifically intended to allow people to interact with Assets objects in Jira/JSM without requiring you to grant schema roles manually.

What I wouldn’t expect from that behavior, though, is unrestricted browsing of the entire schema through the Assets application. Atlassian distinguishes between access to objects via an Assets field and access to the schema view itself.

Since your Roles screenshot is genuinely empty, and this JSM agent can still open Assets > your schema > object types > objects directly, I’d narrow the next test before changing anything. Could you check whether that agent has Jira administrator permissions, and whether the schema is referenced by an Assets custom field on the Service Management space they belong to?

If the user isn’t a Jira admin but can still browse the full schema directly, even without a schema or object-type role, I’d raise this with Atlassian Support. That doesn’t align cleanly with the permission model that Atlassian currently documents, and I wouldn’t recommend adding or removing roles until they confirm which implicit permissions grant access.

Thanks,

James

Roshan Shinde
August 25, 2026

Hi James,

Sure, I will check whether the agent has Administrator permission or not.

Also, one more interesting made by you is the use of Assets custom field on Service Management space. I will verify that as well. 

I will share an update soon. 

 

Thank you once again for your inputs!

 

- Roshan.

2 votes
Fazila Ashraf
Community Champion
August 25, 2026

Hi @Roshan Shinde 

Welcome to community!

When creating a new schema, all groups that grant product access to Assets will be automatically added to the ‘Object schema developers’ role.  To restrict access, open the schema's Roles settings and remove the default group, replacing it with only the specific users or groups who should have access

Roshan Shinde
August 25, 2026

Hi Faiza,

Thank you for your response. 

In my case I, as an Administrator, created the Schema and Object types myself. However, I did not add any user or group or app in the Roles section in Schema settings as well as Object type settings. Basically, I kept everything in the Roles section untouched. 

Despite this, I see that a JSM user who has access to one Service Management space is able to access the Schema and the object types in it and see all the objects. I want to know if this is the default behaviour if you dont add any role for Object schema developer / Object schema user / Object viewer.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events