*Update at bottom*
First off, it appears the permissions for our Bitbucket account are totally independent from Jira (and other Atlassian) permissions. If this is not true, someone please set me straight.
In Bitbucket, our company account has user groups defined by customer and we pay monthly for some of these customer users to have access to their private repositories. (Pretty basic, I think.) All of the customers' private repositories are also under customer-specific private Projects. Correctly, customers can only see and modify their repos because their company group is granted explicit access to each repository. However...
What I just learned today (and I think it's giving me hives) is that customers can see each other's private Projects when they browse at the Project level. They can't by default see the private repositories underneath the private Projects, but they have a profoundly unprofessional (on our end) awareness of our overall client base because of the Project list. Not cool.
How do I limit which Projects our customers can see? It seems that since Bitbucket considers them "members" of our organization (because we pay their monthly fee) they automatically see everything, including all private Projects. The sharing and permissions for Projects seem limited to "Private" or "Public" without any ability to revoke browsing permissions.
It seems crazy there wouldn't be a solution to this--but after a bunch of searching and trying, I'm totally perplexed. Thanks in advance!
UPDATE: Customers who are granted access by repository do not see the private Projects that I want hidden (good news!). Customers who are granted access to their repositories by Bitbucket user group do see all of the private projects. An inconvenient fix is to delete the customer user groups and manage all of the customers' access on a repo-by-repo basis. This cleans up the most egregious problem, but I would prefer the groups feature to allow better control of permissions. Am I expecting too much?