Limit Admin Viewing Rights

Alex InterTechSol February 6, 2012

7-Feb-12

Good Morning,
We have numerous administrators throughout the country using JIRA. I want to create a project where only members of a group can view the project. I don't want any of the administrators to view this particular project (it contains sensitive information). Is this possible? If so, please list the steps.

Again, I don't want any administrators to view this project unless they're in the group.

Thanks for your time and consideration!

1 answer

1 accepted

0 votes
Answer accepted
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
February 6, 2012

You can set that up - admin rights really do mean "rights to administer system" and NOT "rights to do everything" (which is a dumb security model anyway). Just leave them out of the group that allows access.

However, there is absolutely nothing to stop them from

  • Seeing that the group is used in a permission scheme
  • Seeing that there are projects using the permission scheme
  • Changing the project(s)
  • Changing the permission scheme
  • Adding themselves to the group

So, although you could set this up, it's going to be very weak - any administrator who knows the basics will be able to find it, and change things in a way that allows them to see it.

Alex InterTechSol February 6, 2012

7-Feb-12

Nic,
Thanks for your quick response. Is there an alternative solution you, or anybody else recommends?

I'm sure I'm not the first whose encountered this before. What you listed, as far as what the administrators can do, is what I want to prevent for my project.

Thanks!

francis
Marketplace Partner
Marketplace Partners provide apps and integrations available on the Atlassian Marketplace that extend the power of Atlassian products.
February 6, 2012

Setup a separate JIRA where access is restricted to the people who are allowed to see the content of the project ?

Francis

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
February 6, 2012

Basically, yes, what Francis says. Your options are either

  1. Set up a separate Jira
  2. Trust your administrators

Thing is, you need system administrators, and they're *always* going to be able to get around restrictions, so you have to trust the ones who have access to the systems.

Alex InterTechSol February 6, 2012

7-Feb-12

Nic/Francis,
Thanks for your response. I had a feeling a separate JIRA would be the solution, but thouhgt I'd ask anyway.

Thank you!

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events