Access & Change Governance for Jira
Set-up takes one click. The first report is ready within the hour, or in about a minute if you ask for it.
Install
Install from the Atlassian Marketplace as a Jira site administrator. The app asks for read scopes only, plus app storage. It performs no writes to your Jira configuration and makes no network calls outside Atlassian.
Open the app
In Jira, open Settings, then Apps, then Access & Change Governance in the left sidebar. Only site administrators can see it.
First snapshot
The app crawls your site once an hour. On first open you will see "No snapshot yet". Click Run snapshot now, wait a minute, and reload. The line under the tabs shows when the snapshot ran and how many users, groups and projects it covered.
Access tab
One row per person per project: the roles they hold, the path that grants them (direct, or through which group), and the permissions that result from the project's permission scheme. Filter by any word, pick a project, show humans only, or show only inactive accounts. Export CSV downloads the filtered rows with account ids included.
Product access tab
The groups that grant Jira Software or Jira Service Management access, their member counts, which are default groups for new users, and product users against seats bought. This is where seat spend comes from.
Changes tab
A running record of configuration changes from three sources, each labelled:
- event: Jira told the app the moment it happened, with the actor's account id.
- audit: a copy of a native Jira audit log record. Kept after Jira's own retention expires.
- snapshot: a difference between two hourly crawls, for settings the native log does not record.
The Actor column says how the app knows. A name alone came from the event or the audit record. "Inferred from audit log" means the app matched a change to an audit record for the same object within ten minutes. "Unknown" means it does not know and will not guess.
What the app cannot see
- When a user last logged in. Atlassian does not expose it to apps.
- Admin webhooks, work item archiving, issue layout edits, app installs, backups, and Jira Service Management feature toggles. No API or event exists for them.
- The native audit log on the Free plan, where Atlassian does not provide it. Events and snapshot diffs still work.
Large sites
A crawl has a fourteen-minute budget. If a very large site exceeds it, the snapshot is marked incomplete and the page says which sections come from the previous run. The next hourly run continues. Tell us your project and user counts through support and we will look at it.
Data and privacy
Everything the app stores lives in Atlassian Forge storage in your site's region. Uninstalling the app deletes it. Details in the privacy policy.