UPDATE: There is currently no resolution for this issue right now. Please see the accepted answer below for details.
----------------------------------------------------------------------------------------
After reviewing a number of open questions (see this, this, and this, among others) and articles about the subject, I'm still unclear as to the current state of customer portal visibility across portals. At it's core, the question I have is simple: How can I create multiple customer portals but only allow users' respective access to each?
Scenario:
All Atlassian products mentioned are Cloud-based.
Our company develops custom applications for clients. As such, we have Jira Software projects that manage those activities. However, as an app is released for client usage, we have a need to allow clients to submit tickets to us (troubleshooting, bugs, support requests, etc.) via a Service Desk. We have multiple clients, which would necessitate multiple service desks. However, within each client, we do not have an ability to manage users one-by-one (some of our clients have hundreds of employees which change constantly), so we want users to be able to sign up for access to their respective service desk, and not be able to see other client's portals (or even know that they exist). Based on the various instructions I've come across (namely this, this, this, this, and this), we have our system configured as follows:
Jira Service Desk - Configuration:
- Can customers create their own accounts? Yes, by signing up or sending a request
- Can customers access and send requests from the help center without logging in? No
Jira Settings - Security:
- Project Role: Service Desk Customers (no default members configured); displaying as not used in any notification, permission, issue security schemes or workflows
Jira Settings - Issue Attributes:
- Permission Scheme: Our JSD Permission Scheme (which is shared across Service Desks) has the following permissions granted to the "Service desk customer - portal access": Browse Projects, Assign Issues, Close Issues, Create Issues, Delete Issues, Edit Issues, Link Issues, Modify Reporter, Move Issues, Resolve Issues, Schedule Issues, Set Issue Security, Transition Issues, Manage Watchers, View Voters and Watchers, Add Comments, Delete Own Comments, Edit Own Comments, Create Attachments, Delete Own Attachments
Project Customer Permissions:
- Who can access the portal and send requests to <Service Desk Name>? Customers my team adds to the project
***Note: When I flip this over to "Anyone can send a request via the portal or <servicedeske-mail>", this opens the respective portal up to be visible by all customers. This appears to be the key point of failure. However, at least one project needs to have this option to allow for Sign Ups...
Desired Experience:
A user selects their portal link (either via an intranet page, e-mail or however; it shouldn't matter), they are sent to the Service Desk to sign-in. Either they sign-in with their existing account, or they can choose to "Sign Up" and create an account. After signing up/in, the user is redirected to their sole service desk portal where then can initiate a ticket.
Again the moment I allow "Anyone" to be able to send a request within a given project, what it delivers is that all client users can see all client portals that have the "Anyone" option selected - the exact opposite of what I want. And when I don't allow "Anyone" on at least one service desk, the ability to sign-up for an account goes away entirely.
Questions
- Have I just totally biffed something regarding Project Role or Permission usage? Surely it's not expected of a project admin. to go in and manually assign project roles post-customer-registration (as I don't see a way to automate this via workflows).And given that Customers don't auto-populate in the People section of the Project Settings, I don't know why this would be necessary either.
- Do I need to apply the "Service Desk Customers" project role instead/in addition to the "Service desk customer - portal access"?
- Do I need to create a unique permission scheme for each project? I'm not sure how that would actually get me towards my desired experience.
- Given that the user registration appears across portals (....atlassian.net/servicedesk/customer/user/signup?destination=portals), how would the user's account become associated with the intended portal?
- Am I forced to have a "dummy" portal (read: poor experience) with "Anyone" selected just so a user can sign-up for an account for a different portal?
- Presumably, the user is then defaulted into the first/only portal where the "Anyone" option is selected?
- How can I create multiple customer portals but only allow users' respective access to each?