Hi everyone,
we’re using Jira Software Cloud (company-managed projects) and I’m trying to design a permission model for the following scenario:
Context
- We have a restricted “leadership” project where only a small leadership group can see all issues.
- We also have multiple team projects/boards (separate teams) where each team works on their own backlog.
Goal / Problem
Leadership wants to delegate tasks created in the leadership context to one or more teams, while ensuring:
- Teams must not see the full leadership backlog/project
- Leadership must be able to track the status/progress after delegation
- Delegation should support:
- assigning to one team
- assigning to multiple teams
- in some cases, visibility limited to a single specific person in a team
- Teams should ideally be able to work from their own board (or a team view) without constantly switching into the leadership project.
- We want to avoid a solution that requires creating hundreds of manual security combinations (team A + leadership, team B + leadership, team A+B+leadership, plus user-specific cases, etc.).
What we tried / constraints
- Using separate projects and linking issues doesn’t work well because links are only visible to users who have access to both projects.
- Classic permission schemes / project roles are too coarse.
- Issue Security seems promising, but:
- each issue can only have one security level, and
- we are unsure how to handle multiple team combinations and person-specific visibility without making it unmanageable.
- We can use Automation, but we want a robust design that reduces human error (e.g., wrong security level set).
Questions
- Is there a recommended Jira Cloud design pattern for this?
- Can Issue Security be configured to grant access dynamically based on:
- a multi-group picker (teams) and/or
- a multi-user picker (specific individuals),
while still allowing leadership to track everything?
- If the issue stays in the leadership project (for visibility), how can teams work on it from their own board/view without seeing other leadership issues? (e.g., cross-project boards vs. dashboards vs. filters)
- What are the main pitfalls/limitations in Jira Cloud for this kind of “delegate without exposing everything” setup?
Any guidance, best practices, or examples would be highly appreciated. Thanks!