We are currently reviewing plugin apps in our JIRA environment, which contains highly sensitive information. Before installing plugins, we need to assess certain measures. Initial investigations revealed that the "Cloud Fortified" app offers the highest security in the Atlassian Marketplace. However, we found that any app installed in our Atlassian environment automatically gains access to Project admin via the "atlassian-addons-project-access" role. We have the following questions:
- Is it safer to remove "atlassian-addons-project-access" from all permission schemes?
- Does the plugin have the capability to limit access to specific projects? Can we trust that the plugin won't access other projects?
Based on the open ticket, even after removing the "Atlassian-addons-project-access" role will be added
Note: We cannot remove the role from the team-managed project permissions. Any guidance on that?