Access Review for Jira — Documentation

Forge-native access review & audit evidence. Your data never leaves Atlassian.

What it does

Access Review shows who can access which Jira project, at what level, and via which path (the group → role → scheme chain), flags access risks and inconsistencies, and produces auditor-ready evidence for ISO 27001 / SOC 2 access reviews — all without your data leaving Atlassian.

Getting started

  1. Install from the Atlassian Marketplace.
  2. Open Jira Settings (⚙️) → Apps → Access Review.
  3. The app analyses your site automatically. Use Refresh analysis to rebuild.

The app is available to Jira administrators only.

Tabs

Project Access Overview

Pick a project to see every user with access, their status, the permission, and the access path (why). Filter by permission, search, "direct grants only", "deactivated only", and optionally show app/system accounts. Path legend:

Risks & Inconsistencies

A prioritised (high / medium / low) list of findings: deactivated users who still have access, direct user grants, too many project admins, public ("anyone") access, empty groups used in schemes, unused permission schemes, and licensed users without project access.

Access Review

Run a repeatable certification round: start a review (all projects or one), then mark each user's access Approve / Remove / Exception. Decisions save as you go. Complete the review to lock it with a timestamp as evidence. Export the round as PDF or CSV. Note: the app reports decisions; it does not remove access from Jira.

Export & Evidence

Generate auditor-ready files: an Audit report (opens a printable page → Print → Save as PDF) and CSV exports of the overview and the risk findings. Each export embeds the site, timestamp, who generated it, and the scope. Everything is produced in your browser — nothing is sent anywhere.

Data & security

Read-only scopes only; all processing on Forge; no external egress. See the privacy policy.

Support

See the support page.