Hi guys
We're using group names for a permission scheme, and we also want our external users to find their issues where (deep breath)...
The user is the assignee, reporter or owner (custom field)
OR
Their primary group is the value of the CC Group custom field (alternatively, a member of their primary group (which copied to the CC Group field for permission reasons) is the assignee or reporter)
i.e. User Alice belongs to the groups: Customers, jira-users, CustomerA
CustomerA is stored in the CC Group field
User Bob also belongs to the same groups, and is a manager - so never logs issues, but expects to see all issues raised by Alice and all issues raised by our helldesk on their behalf.
I'd really just like to have a generic couple of shared dashboards available for all our customers and agents which use the same underlying JQL
The current permission scheme only allows users to view their own reported issues, or when their user-group is in the CC user field - but I'd rather not have an open search on everything just in case there's finger trouble on our end - I do want to explicitly restrict it to assignee, reporter, owner are current user, and assignee or reporter are in the group which is set in CC Groups
It's just such an obvious thing that I can't get my head around it 
What I'm afraid of is that someone sets the cc group field to 'jira-users' or 'customers' but that's not an issue if it's half a dozen issues - it's more of a concern if we fundamentally break the permission scheme and that's really what I want to guard against.
Any thoughts?
Cheers