We want to integrate JIRA and Google Workspace for our organization.
Our primary goals for this integration are to streamline user management (auto-provisioning and deactivation based on Google accounts) and optimize our licensing costs by utilizing guest accounts for external partners.
Could you please review the implementation plan given below. Specifically, I would appreciate your confirmation that the outlined steps—covering user synchronization and external user configuration—are correct and follow standard best practices.
Integration Approach
Step 1: Notify all Jira users
- Notify all Jira users regarding the scheduled update. Inform them that they may experience access issues during the outage period.
Step 2: Export current Jira users and verify access
- Take a full export of current Jira users, their assigned projects, and their specific roles to ensure a baseline for verification after synchronization.
- Verify Administrator Access:
- Google Workspace: Super Administrator, User Management, Group Management.
- Jira: Organization Administrator, Site Administrator.
- Create a dedicated Google Workspace group:
- In Google Admin Console, navigate to Directory > Groups > Create Group: jira-users@kloudgin.com.
- Add only the 86 designated internal Jira users to this group; exclude the remaining 178 users and external partners.
Step 3: Configure and run synchronization
- Configure Google Workspace Integration in Jira:
- Navigate to admin.atlassian.com > Security > Identity Providers > Google Workspace > Connect.
- Authenticate using the Google Workspace admin account and approve permissions.
- Enable Google SSO under Security > Authentication.
- Configure User Provisioning:
- Select "Sync specific groups" and choose jira-users@kloudgin.com.
- Ensure account matching (Google Email = Jira Email) to prevent duplicates.
- Run and Validate Sync:
- Start synchronization and verify that 86 users are synchronized while 178 are excluded.
Step 4: Add back external users and configure access
- Verify Jira License and Guest Support: Confirm the 5:1 guest-user model is supported in Billing > Subscriptions.
- Add the 30 external users as guests directly in Jira (do not add them to Google Workspace).
- Restrict Guest Access: Assign users only to their required projects and block access to internal or other customer projects.
Step 5: Review internal user assignments
- Review all project and role assignments for internal users. Ensure the synchronization did not inadvertently drop or reset permissions for internal organisation accounts.
Step 6: Backup and attach final documentation
- Take a final backup export of project and role assignments.
Proposed Final Architecture
- Google Workspace (264 users)
- jira-users@kloudgin.com (86 internal users)
- Google SSO + Provisioning
- Jira
- 86 Internal Users
- 30 External Guest Users
- 178 Google users → Excluded