I have a Service Desk project that requires adding an agent in a different company since some issues are outsourced. I'm trying to restrict that agent so they can only see issues where they are the assignee or reporter, not all the other issues that are to be kept confidential. I found some articles that describe how to do this, but it isn't working.
I've created the Issue Security Scheme and a default level. In that level I've enabled current assignee, reporter, my internal agents and project administrators.
The project permissions allow project administrators, Service Desk Team and my internal agents.
When the external agent signs in, they can see and edit all issues, not just those assigned to or reported by them.
As a test, I removed the Service Desk Team from the Edit Issues project permissions. This allowed them to edit only their own issues, none of the others. That's what I want. However, Jira warns that the permissions are incorrect because the Service Desk Team must have permission to Edit Issues.
When using the permission helper, it looks like the Service Desk Team project role is superseding the issue security. I can't remove the external agent from the Service Desk Team because of licensing.
Any help would be appreciated. Thanks.