Community Announcements have moved! To stay up to date, please join the new Community Announcements group today. Learn more
×Hi all, noticed places that use a "choose user" custom field allows me to pick not just Jira Software users but also any customer in our Jira Service Management.
This worries me because it means we can add a "customer" that should only be Service Desk related, as a pickable user in the Jira Software side. It also means customer emails are leaking from our service desk (which should be secure for only our agents) to our development/test teams.
Is there a permission issue I'm missing? guessing it has something to do with Global Permissions in "Browse users and groups" section?
Thanks
Hello @Calvin
Welcome to the Atlassian Community!
Yes, you need to first check the global "Browse users and groups" permission.
By default, anyone with this global permission can see all users when using user picker fields.
Secondly, you can set a context for the custom field so that only users from a particular group/role are visible in the drop-down:
Go to Jira Settings > Work items > Fields.
Find your user picker field, then select Contexts and default value > Edit User Filtering.
Enable group or project role filtering, and specify only the groups or roles that should be selectable (e.g., only Jira Software users)
Save your changes.
Thank you!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.