Currently, my companies Jira projects automatically use the 'Default scheme' for permissions. However, this scheme grants excessive access to various groups, such as 'Any logged in user,' allowing them to view, create, or close issues in any project under this scheme. This is a problem as it prevents me from adding contractors to Jira and restricting their access within the tool.
How do I enable full access to Full time employees while restricting contractors to only the project that they are assigned to work on?
Hi @Laurie Sciutti thanks for your reply! I would like to enable full access for full timers but restrict access for contractors. If I remove “any logged in user” and replace with new group that’s dedicated to contractors, will my full time users still be able to access all projects or would I need to create a group for them as well?
Currently all of the of the permission scheme has assigned “atlassian-addon-project-access”.
If all my full time users are assigned to that, does that mean they can access all projects and functions within the project?
You'll need to create several groups, at least one for your normal users and for another for contractors.
These groups will need to be granted the global "can log in" permission, and then you'll need to remove "any logged in user" from all of your permission schemes, and add (ideally role based) access for the new groups as appropriate.
Do not mess with the "atlassian-addon-project-access", this only gets used by apps, and you should not add humans to it.