Hi, I need some help with Security Schemes and permissions.
I have 2 groups of people: JSM agents (IT) and Change agents (Business).
I have 3 Issue Types: Service Request, Incidents & Changes.
Within my JSM company managed project, my JSM agents must be able to create, edit, close, delete all work items.
Within this same JSM managed project, the Change agents must only be able to create, edit and close Change issue type work items.
I have allocated JSM licenses to both groups of people. The JSM agents are added as people directly in the project and given Service Desk Team roles.
I created a Security Scheme with 2 levels of security:

In the Change request type, I added these restrictions:


Under project permissions, I have added my Change group into the below permissions:
- Service Project Agent permission,
- Create Issues
- Delete Issues
What role do I give the Change agents group in the project when I add the group?

I have added the group before and given them Service Desk Team role, but when I do, my test user is still able to see all the issues, not just the Change ones.
What am I doing wrong?
I followed these instructions as best I could, but some of it wasn't very clear and it still didn't work.
https://support.atlassian.com/jira-service-management-cloud/docs/create-security-levels-for-issues/