We have a third party application that logs crashes from our software, and when it reaches a specified number it uses a webhook into JIRA to create a bug in the engineering project.
We want to restrict people outside the engineering team from lodging bugs directly (they have another mechanism).
What permissions does a webhook into JIRA require? I've currently got the Create Issues action as having JIRA Software application access, but this obviously also gives everyone permission to create issues.
The other alternative I tried to find (but couldn't) is to explicitly restrict groups...