How do you prevent project administrators from assigning (specific) user groups to project roles in the project?

Oliver Wahler September 23, 2012

Hi,

Unfortunately some of our project administrators occasionaly assign the "jira-users" group to a project role on their project, which results in potentially disclosing project data to undesired groups of users. The users are internal and client users in quite a large organization where the projects are highly independend.

Currently, we just try to teach our project admins in not doing so. However in some cases this doesn't help. We manually remove the group from the project again.

I am interested to hear, how you handle this in your organisation.

Additionally, maybe you know os a setting or plugin, which I am failing to find, which disables the project role assignment by user group.

Thanks,

Oliver

3 answers

1 accepted

1 vote
Answer accepted
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 23, 2012

You can't disable it (without coding in the core anyway)

I've always handled it with education myself, as you've tried. Tell administrators not to use the group in the roles if they want any form of privacy. In the rare cases where they repeatedly make the mistake, the stick comes out - remove them from the admin roles and tell their boss that they're not fit for the role.

Oliver Wahler September 24, 2012

I like the latter :-)

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 24, 2012

Sadly, it's the only way to deal with the ones who won't listen. Fortunately, in my experience, they are very few and far-between. On the rare times I've had to go to someone's boss and say "we have a problem with this user", I've always had a reply along the lines of "you aren't the first person to tell me that".

0 votes
Ankush Kumar February 14, 2022

Hi @Nic Brough -Adaptavist- 

I am facing same issue in my instance. Is there any possibility with the scriptrunner to do that.

If yes can you please share script if you are already having.

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
February 14, 2022

All you could do with SR is write a script that removes the unwanted groups from roles and run it regularly.

Ankush Kumar February 15, 2022

Hi @Nic Brough -Adaptavist- 

can you please help me with the script, if you are already having any.

0 votes
Jobin Kuruvilla [Adaptavist]
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 23, 2012

There isn't anything you can do via configurations to prevent this. Actually, it is a good practice to use groups in project roles.

If you want to restrict groups like jira-users used in the project roles, you are looking at some plugins and disabling of standard functionality which does that.

Oliver Wahler September 24, 2012

When talking about looking at some plugins: Do you know of any existing plugin in particular?

Regarding the good practics of uing groups in project roles: Basically I agree with you. Unfortunately we do not have project based group management in place. Hence the JIRA admins manage the groups on request and and project admins do not have immidiate visibility in nor control of the group members. This is why we educate our users to assign project mambers individually.

Suggest an answer

Log in or Sign up to answer