Why does an external user in Security Level able to view tickets not assigned to them?

Efrain plascencia September 17, 2014

I have an external user that is in the proper security level to see a ticket assigned to them. They also have the following permissions for the project:

  • Browse Project
  • Assignable User
  • Assign Issues
  • Transition Issue
  • Add Comments 
  • Edit Own Comments
  • Create Attachments

However, it seems like this user is still able to look at other tickets in the project that are not assigned to him/her. This user is only 'jira-user' group and all permissions and security levels have been assigned individually. (Not because this user is in a group) Any suggestions to help me out? I want this user to only be able to see the issues that are assigned to it.

2 answers

0 votes
Efrain plascencia September 18, 2014

Thanks for the response, David!

Removed the Browse Project permission and now the user cannot access the project at all. Where can I go to implement issue security?

Dave
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 18, 2014

That's on a per-project basis, you can find the instructions at https://confluence.atlassian.com/display/AOD/Configuring+Issue-level+Security

Efrain plascencia September 18, 2014

I see that you can edit/define users in Issue Security Scheme and Security Levels with this link but where would I define what a specific security level can do?

0 votes
Dave
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 17, 2014

Browse project allows them to see all of the issues in that project, you would need to remove that permission for this restriction to work, or implement issue security to restrict the views further.

Suggest an answer

Log in or Sign up to answer