Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is it possible to grant access to the audit log to a non-admin user?

Noam Ravid December 20, 2022

Hi, 

We wish to enable logs collection and monitoring however we also want to keep the least privilege principle.

Is it possible to define a role for accessing the audit logs without granting the user full admin rights? 

Thanks, Noam

1 answer

1 vote
Mohamed Benziane
Community Champion
December 20, 2022

Hi,

Welcome to the community

As stated by the documentation you need to have the Administer Jira global permission

https://support.atlassian.com/jira-cloud-administration/docs/audit-activities-in-jira-applications/

Noam Ravid December 22, 2022

Thank you Mohamed,

Can you tell if there are plans to allow RBAC or some sort of least privilege role so API token for security monitoring only purposes won't need admin rights and add unnecessary risk?

Best,

Noam

Mohamed Benziane
Community Champion
December 22, 2022

I don't know you should ask Atlassian directly. But one solution could be to export all the log to an outside product.

Noam Ravid December 22, 2022

Thanks for the response!  What's the best way to ask Atlassian directly?

The API token to access/export the logs requires admin rights, this is what I wish to avoid, and I believe it would be beneficial to all customers if they won't need to use such privileges account/token instead of using an account with RO rights.     

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events