I'm designing a single company-managed JSM project where several teams work out of the same project but should not see each other's tickets. My plan is to use issue security levels so each team only sees its own work items, with queues layered on top. Normal tickets get a per-team level based on which team they belong to.
The part I want to sanity-check is a "shared" state where one work item must be visible to exactly two teams at once, while staying hidden from everyone else. The scenario is a hand-off: a ticket owned by one team gets passed to another team to action, and during that period both the originating team and the handling team need to see it.
How I intend to model it:
- A group-picker custom field holding the handling team (call it Assignment Team), populated with that team's group.
- A second group-picker custom field holding the originating team (call it Delegating Team), populated with that team's group.
- A single security level (call it "Delegated") whose grantees are: Reporter, plus "group custom field value" pointing at Assignment Team, plus "group custom field value" pointing at Delegating Team.
The idea is that this one level serves any pair of teams, because it reads whichever two groups are sitting in those fields on that specific issue, rather than needing a separate level per team-pairing. Normal tickets keep their single-team level; only hand-off tickets get the "Delegated" level.
Where I'd like community input:
1. Is a single security level with two "group custom field value" grantees a supported and reliable way to express "visible to exactly these two teams," or does dynamic-grantee resolution have limitations I should know about?
Before I go further, I've had a couple of Atlassian partners tell me that issue security "doesn't work well" at this kind of granularity and that the practical answer is to make everything visible to everyone in the project and rely on queues alone. That surprised me, so I'd like to sanity-check it with the community.
I'm keeping the question at the design level on purpose. I'm not asking anyone to debug a specific configuration, just whether the overall approach is sound and supported, or whether there's a reason the "visible to everyone" camp is right.