Hi @Aj ,
In Jira Cloud, there's no built-in "read-only" role out of the box, but you can achieve this through Permission Schemes combined with a custom Project Role. Here's how:
Step 1 – Create a custom Project Role
ViewerStep 2 – Update the Permission Scheme
Viewer role to itViewer role is not listed under any other permission (Create Issues, Edit Issues, Add Comments, Transition Issues, etc.)Step 3 – Add the user to the role in your project
Viewer roleNote for Standard plan users: Permission Schemes are shared across projects, so modifying an existing one will affect all projects using it. It's safer to duplicate the scheme first, adjust the copy, and then assign it to your specific project.
The user will still need a Jira license assigned — there's no way around that unless you use the external guest model (which, as you mentioned, isn't ideal).
Hope this helps! 🙌
Hello @Aj , it's Space Roles — Atlassian recently updated the terminology.
It should be listed in the left sidebar under the Security section. If you're already in System settings, just look for "Space Roles" in the menu — it's usually right there alongside options like Global Permissions and Issue Security Schemes.
Hope that helps! 🙌
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
How classic - change the terminology without updating the documentation! Let the user suffer and waste their time.
Moving on to the next step -- same situation.
There is no Jira Settings → Issues → Permission Schemes!
I only see 'Jira Settings -> Security -> Global Permissions' which has all sort of useless global permissions, nothing project specific.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hey @Aj ,
Apologies for the earlier confusion! There are actually two ways to manage Permission Schemes in Jira Cloud — here's both:
Option A – Directly from the Space
Option B – From Global Settings (if you know the scheme name)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Aj
Glad it helped! Thanks for the clarification on step #10 — duly noted.
Best regards,
Cristian Quiroz Garcia
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hey @Aj
The "guest model" mention makes me fairly confident you mean a Confluence space — @James Gamble is right that it matters, so I'll answer that reading.
For a **licensed user on your site**, read-only is just space permissions:
- Space settings → Space access → add the user, tick only **View**, leave everything else unchecked.
- The bit that catches people: permissions are additive. If `confluence-users` (or any group they're in) already has Add/Delete on that space, your view-only grant does nothing — you have to strip the group's permissions down too.
- Check the default space permissions for new spaces as well, since most spaces inherit generous group access from there.
Docs: [Assign space permissions](https://support.atlassian.com/confluence-cloud/docs/assign-space-permissions/).
If the person is **external to your org**, I'd brace for disappointment: it's guests, anonymous (public) access, or a paid licence with view-only space perms. There's no fourth option, and anonymous exposes the space to everyone.
If this is actually a Jira Product Discovery space, different story — the free contributor role gives read-only plus comments/votes
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hola Aj,
Could you clarify which type of space you mean? The question is posted under Jira Cloud, but “space” could refer to a Confluence space or a Jira Product Discovery space, and the permissions are handled differently.
It’d also help to know whether this person is an internal licensed user or someone external to your organization. Once that’s clear, the correct read-only setup should be much easier to pin down.
Thanks,
James
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.