Hi,
I am a newbie in JIRA; we have an instance which hosts one dedicated project, and all the roles, permission scheme, groups, were created specifically for this project.
Due to many other team's interest to use JIRA within our organization, we want to start a new instance which will host all other projects.
We try to start right from the beginning, and not mess with too many admin roles, too much headache for JIRA system admin, and so on.
We use Active Directory for authentification, and i am confused on how to separate admin/dev/user roles.
1. is it better to have AD groups for ADMIN, DEV, USER, and separate the roles directly in AD?
This may lead to too much interference with Active Directory, too may groups inherited(TEAM1_ADMIN, TEAM2_ADMIN, TEAM1_DEV, TEAM2_DEV, etc)
2. is it better to have in AD groups as per our organisational structure(GRP_DIVISION1, GRP_DIVISION2...) and use also JIRA internal groups for separating admin/dev/user roles?
(do I need to create other internal groups also, or only working with permission schemes will be enough?)
3. How can JIRA space be divided for two or more divisions? The only separation I see is using projects, which can share the same workflow, custom fields, etc.
Can/Should any project have one, more or NONE JIRA Admins?
A JIRA Admin can for example edit a workflow, which may be associated to many projects. (His change will be intended for one project, but he will interfere with other projects workflow, which is not desired.)
How would an experienced JIRA system admin start this up?
Any help is appreciated.
Kind Regards,
Carmen