Hi @Oliver Wright and welcome to the community
Good that you are adressing these issues early since it is a bit of a nightmare to clean up later.
My last thoughts are:
I hope this gives you some input to start with!
Best regards,/Staffan
@Oliver Wright , @Staffan Redelius makes the best point here of designing the system first. I'm sure his comment about the nightmare of cleaning up someone else's "Wild West" permissions as well as other types of creep (Status, links, resolutions) rings true for many admins.
Try to find some of the admin training available and take those courses also. I wish I had done that first.
One last tip: if you have the luxury of setting up your system using the sandbox first and testing it will save you hours of troubleshooting.
Good luck, and keep asking questions in the various community forums if you get stuck or need some advice.
Hi! In our organization, we had a similar challenge and found that integrating access management directly with our onboarding/Identity Provider system (in our case, Google Workspace, but this applies perfectly to your Entra ID setup) was the best solution.
Instead of managing access inside Jira, we shifted the source of truth to our IdP. Here is how we do it and how it answers some of your questions:
1. Manage Access via Identity Platform (Entra ID / Google)I highly recommend using Entra ID for more than just licensing. In our setup, whenever a new user joins the company, they are added to their specific "Squad/Team Group" directly in Google. This group is automatically synced to Jira (via Atlassian Guard/Access).
2. Squad-Based Groups over Individual ProvisioningBecause the synced groups already represent our squads, we assign these groups directly to the project roles. As soon as the user is created in the IdP, they instantly have access to all the projects their squad works on. When they leave or change teams, updating the IdP automatically revokes or changes their Jira access. This provides strong governance and auditability with zero manual Jira administration.
3. Standardized Global Permission SchemesTo prevent permission sprawl, we do not allow custom permission schemes per project. We use standard, global permission schemes based on simple levels:
Viewers (Read-only access)
Creators/Contributors (Can create and edit issues)
Editors/Admins (Project management)These global schemes are tied to Project Roles. So, the central administration only maintains the schemes, and the Squad Groups (from our IdP) are placed into those roles.
4. Delegation and Confluence AlignmentBecause the groups are managed centrally in the IdP, keeping Confluence aligned is incredibly easy. The exact same squad group that grants "Creator" access in a Jira project is used to grant access to the linked Confluence space. This means Project/Space admins don't really need to micromanage individual users in Jira—they just rely on the automated squad groups.
Looking back: Automating group assignment at the onboarding stage (via your IdP) is the ultimate way to achieve that "simple, scalable, and minimal central administration" you are looking for. Don't be afraid to lean on Entra ID for group syncing!"
@Oliver Wright@Staffan Redelius's advice above is solid: start with groups, minimize custom permission schemes, and lean on an identity provider like Entra ID for licensing. Those are the right structural choices as you scale.
One thing that gets harder as projects multiply is simply knowing the current state of who can do what. Even a well-designed scheme drifts over time: a consultant gets Browse added directly, a permission scheme gets cloned with a small tweak, a new project lead forgets to follow the template. At 30+ projects, manual spot-checks become impractical.
I'm the founder of Katabarwa Labs and we built Access Governance Reporter specifically for this scenario:
It does not design your permission model for you, but once the structural foundation is in place, it gives you ongoing visibility to confirm that model is actually being followed.
Marketplace listing: https://marketplace.atlassian.com/apps/3162504883/access-governance-reporter
If it does not quite fit your situation, tell us what would and we will build it.
It looks like you're new here. Sign in or register to get started.