What your configuration actually means: who can do what, where the seats go, and who changed it.
One app, three answers. Runs entirely on Atlassian infrastructure, so nothing leaves your site.
Every project role, group and permission grant expanded into one table: this user, in this project, holds these permissions, because of this group. Filter it, find inactive accounts, export CSV.
The groups that grant Jira Software or Jira Service Management access, member counts, default-group flags, and product users against seats bought. See where the renewal goes before it lands.
Jira events as they happen, the native audit log kept past its retention, and hourly diffs of what neither records. Every actor is labelled by source, inferred with evidence, or marked unknown.
No app can see when a user last logged in, or watch webhooks, archiving, layouts, app installs or backups. Atlassian exposes none of it. We say so on the listing, in the docs, and on the page.
Email [email protected] or raise a request in the portal. Either way you get a key you can follow.