Grant JSM administration access without giving Jira global admin rights
Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.
Summary
Adding a user to a JSM admin group can unintentionally grant Jira global administration access if that group also carries the global admin permission.
Solution
Which user-management experience do you have?
The steps below differ depending on your admin UI.
Centralized user management (Directory > Users in admin.atlassian.com) — assign the Jira Service Management Administrator product role on the target site.
Original user management — go to App access > Administration Access and add the user to a group that already has admin access to the target app.
Not sure which you have? If you see a Directory menu in admin.atlassian.com, you're on centralized user management.
Grant JSM admin to the user
For centralized user management
Go to admin.atlassian.com > Directory > Users.
Select the user.
Under Product access, locate the target Jira Service Management site, then assign the Jira Service Management Administrator role.
Save changes.
For original user management
Go to admin.atlassian.com > Apps > select your site.
Open App access > Administration Access.
Add the user to a group that has JSM admin access — or create a dedicated group scoped only to JSM admin.
Review Global admin permissions
After granting the JSM admin role, confirm the user does not hold the Jira global admin role unintentionally:
In your Jira site, go to Settings (⚙) > System > Global permissions.
Find the user (or the groups they belong to) under the Administer Jira permission.
If they appear there and should not have global admin, remove them from that group — or remove the group from the Administer Jira permission entirely if it should not carry that right.
Related documentation
Was this helpful?