Access Governance for Jira

User guide · Getting started

Access Governance for Jira shows you who can do what across your Jira site, lets you preview what breaks before you change a group, helps you reclaim unused licenses, and runs attested access reviews — all from one admin screen, without your data ever leaving Atlassian.

Where to find it

The app lives in Jira's admin area. Go to Settings (the gear icon) → Apps → Access Governance. It opens as a full-page admin screen with a row of tabs across the top. Only Jira administrators can open it.

The Access Governance app open in Jira's admin area, with Jira's navigation and the Apps section in the settings sidebar around it.
Access Governance opens as a full-page admin screen inside Jira — find it under Apps in the Jira admin settings sidebar.

Your data never leaves Atlassian

The app is built on Atlassian Forge and is read-only by default. It reads your Jira permission configuration to build a picture of who has access, and stores that picture only in Atlassian-hosted Forge storage — in your own site's data-residency region. It declares no external network access, so nothing is ever sent to us or any third party. When you uninstall, the stored data is deleted.

The app makes changes only when you explicitly preview, confirm, and apply them (see Preview changes and Access reviews). Every change is recorded and can be undone.

How it works: the scan

Everything you see in the app comes from a scan — a snapshot of your site's access configuration. The app reads the last completed snapshot, so it's fast and never slows Jira down. The snapshot refreshes automatically once a day, and you can refresh it any time.

  1. Open the app. The status bar at the top shows whether a scan has run (Ready, Scanning, or No scan yet).
  2. If it's your first time, select Run scan (top right). The first scan takes a few minutes depending on site size; you can keep using Jira while it runs.
  3. When it finishes, the status bar reads “Last scanned …” and every tab is populated. After you apply a change, run a scan again so the rest of the app reflects it.

Reading the Overview

The Overview tab opens first. At the top is the Access topology — a single picture of how access flows across your site, left to right: users → groups → permission schemes → projects. Purple is who has access; teal is what it reaches. Each column shows a representative sample with a “+N more” pill, and the headline number above each column is the true total. Below it, the Licenses table shows seats used vs. owned per product, highlighting anything at or over its limit.

Access topologyRepresentative sample: 327 access grants link 142 users → 21 groups in use → 6 permission schemes → 14 projects.Access topologyHow access flows across your sitewho has accesswhat it reaches142Users21Groups in use6Permission schemes14ProjectsAvery ChenAvery ChenJordan DiazJordan DiazPriya NairPriya Nair139 more users — Open the User access tab to look up any user.+139 moresite-adminssite-adminsdevelopersdevelopersqa-engineersqa-engineers18 more groups — Open the Preview changes tab to browse all groups.+18 moreDefault schemeDefault schemeSoftware schemeSoftware schemeService Management schemeService Manageme…3 more permission schemes — Open the Project access tab to see each project’s permission scheme.+3 moreAlphaAlphaPaymentsPaymentsMobileMobile11 more projects — Open the Project access tab to look up any project.+11 moreRepresentative sample: 327 access grants link 142 users → 21 groups in use → 6 permission schemes → 14 projects.
The Access topology on the Overview tab. Purple = who has access (users, groups); teal = what it reaches (permission schemes, projects). The numbers above each column are true site totals; the chips are a representative sample.

The tabs at a glance

TabWhat it answers
OverviewHow much access exists across the site, and how seats are used.
User access“What can this person reach, and how?”
Project access“Who can access this project, and via which group or role?”
Preview changes“If I remove this group, what breaks — and then remove it safely.”
Reclaim seats“Which inactive users are costing me licenses, and how do I free them?”
Access reviewsRecertify access on a cadence — keep/revoke, sign off, apply, export evidence.
Audit logThe evidence trail of every scan, check, and applied change — with one-click undo.
SettingsYour per-seat cost and the inactivity threshold used elsewhere in the app.

Two honest limits worth knowing up front

  • Inactivity is an activity signal, not a login time. “Last issue activity” is the most recent time someone acted on an issue. It's a strong indicator of who's active, but a privacy-safe app can't see exact last-login times — so confirm before removing anyone.
  • Two kinds of access can't be read. Issue-security level membership and global permissions (like “Administer Jira”) aren't readable by a privacy-safe app, so they aren't shown. The app points you to the right Jira admin page to check them yourself where it matters.