The requirement:
We have qualified a few issues across projects as secure issues which needs to be seen only by the assignee and reporter of the issue. The projects' Security Scheme has a level created called "Secure" so that issues that are moved to that level have only assignee and reporter access.
However, since this configuration can only be done by a System Administrator(s), it is open to errors or vulnerabilities if the sys admins inadvertently add any additional users to this level. The assignee and reporter of the issues marked "Secure" wouldn't possibly be aware of more users being able to access their secure issue.
1. Whats the best way to revert or disable any change to the "Secure" level by Sys Admins whose only users can be assignee and reporter?
2. How can assignee and reporter know who all can access their secure issue from the issue itself?
Thanks,
Ambica