Hi community,
I am designing an IT Service Management solution with many different physical locations. I am hitting a wall regarding data isolation in Jira Assets and would love to hear your architectural advice.
The Hard Requirements:
Single Customer Portal: All end-users must go to one unified JSM portal to report issues.
Strict Data Isolation for End-users: When an end-user raises a request, they must ONLY see the IT assets belonging to their specific location.
Strict Data Isolation for IT Agents: IT Agents at Location A must NOT be able to see assets, users, or tickets from Location B.
The Architecture Challenge:
Because Jira Assets currently lacks Object-level or Attribute-level security, I am caught between two suboptimal paths:
Path A: 1 Global Schema + AQL. Pros: Clean backend, easy to maintain. We can use AQL on the portal to filter assets by the reporter's location.
Cons: Fails the Agent isolation requirement. If an Agent gets Object Schema User permission, they can see the entire global inventory of all locations.
Path B: 17 Independent Schemas
Pros: Absolute data isolation. Agents only get permissions for their specific schema.
Cons: Admin nightmare. We would need many Custom Fields (mapping to 17 schemas). To keep the "Single Portal" experience, we'd have to rely heavily on JSM
My Questions:
Has anyone successfully implemented strict Agent-level data isolation across multiple sites without creating a massive maintenance burden (like Path
?
Would a model (1 main portal project syncing to 17 backend projects via Automation) be overkill here?
Appreciate any insights or war stories you can share!