Wow, got some good suggestions to my Question as I was typing it, but alas, I need a solution for Cloud:
Back in 2018, Michael asked:
I would like to pull a list of all project roles where the "staff" group is located and add the "Employees" group into the role as well. Where do I even start? I'm hoping for a groovy solution to run in Script Console.
That's exactly what I want to do, except... I'm on Cloud. So the awesome solution that @Ivan Tovbin gave will very likely not work, since I won't have access to the various internals that you have with on-prem Jira.
Whilst we were still on Server (which is when I should have made this change), I found this great article, which tells you how to Find All Projects with a Specific Project Role.
I was able to hack it to just print out matches for the particular Group I was looking for:
import com.atlassian.jira.component.ComponentAccessor;
import com.atlassian.jira.project.Project;
import com.atlassian.jira.project.ProjectManager;
import com.atlassian.jira.security.roles.ProjectRole;
import com.atlassian.jira.security.roles.ProjectRoleActors;
import com.atlassian.jira.security.roles.ProjectRoleManager;
import com.atlassian.jira.security.roles.RoleActor;
def roleName = "Roku"
StringBuilder output = new StringBuilder();
ProjectManager projectManager = ComponentAccessor.getProjectManager();
ProjectRoleManager projectRoleManager = (ProjectRoleManager) ComponentAccessor.getComponentOfType(ProjectRoleManager.class);
//gets all project roles
def projectRoles = projectRoleManager.getProjectRoles()
//for each project
for(Project project : projectManager.getProjectObjects())
{ //and each project role
for(ProjectRole projectRole: projectRoles)
{
if(projectRole.getName() == roleName){
//see if that project uses the project role
def ProjectRoleActors projectRoleActors = projectRoleManager.getProjectRoleActors(projectRole, project)
for (RoleActor actor : projectRoleActors.getRoleActors()) {
if(actor.getDescriptor() == 'Roku Users')
output.append(project.getKey()).append("\n")
}
}
}
}
return output.toString();
BUT, yeah, now I'm on Cloud, so that's not gonna work.
So one of the other suggestions I got was: How to identify group usage in Jira Cloud?, where @Angélica Luz points to this ticket: JRACLOUD-71967 - Group usage - List of project permission per group
Basically, Cloud lost the functionality that was on Server/DC, to see all the Permissions (and Notifications, and Issue Security) Schemes that a Group has, like this:

BUT ACTUALLY, because I folllow best practices (like @Jimmy Seddon's here) I don't put Groups in Permission Schemes? I put them in Roles.
But Atlassian has not seen fit to show Groups that are in Project Roles. There's probably a ticket for that too.
I GUESS I could iterate through EVERY project in Jira using ACLI and do:
acli -a getProjectRoleActorList --project SAM --role Roku --select "Group: Roku Users"
But man, that's ugly.
Any other ideas?