Hello Community,
I'm working on a set of permission which It have to be assigned to a group of users which they have to collaborate with a particular project only. This people don't belong to our organization. So we add those account as guest and they were included on a group and the group was assigned the "viewer" role on that specific project.
After one of that outsiders got into that project the could see (and browse) all other projects hosted on our company Jira site. So I researched a bit and Permission schema topic comes to me. I analyzed all the features that are set on our Company default permission schema and I notice that after modifying "browse project" permission this particular project was pulled off from the list that our outsider users are able to see.
In "granted to" section of "browse projects" configuration row I have two options I) Project Role II) Application access so I just removed application access item and I replaced them with Group and after that I maped this schema with company defined groups where the outsiders does not belong to.
This setting works fine, but I'm not sure why application access are set to "browse projects" feature and many other security options into the permissions schema. Of course that everything that I've told before was deployed on a test instance, but I have to deploy this on production as soon as I can resolve this doubt.
Thank you very much!
Best regards.