Grant JSM administration access without giving Jira global admin rights

Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.

Summary

Adding a user to a JSM admin group can unintentionally grant Jira global administration access if that group also carries the global admin permission.

Solution

Which user-management experience do you have?

The steps below differ depending on your admin UI.

  • Centralized user management (Directory > Users in admin.atlassian.com) — assign the Jira Service Management Administrator product role on the target site.

  • Original user management — go to App access > Administration Access and add the user to a group that already has admin access to the target app.

Not sure which you have? If you see a Directory menu in admin.atlassian.com, you're on centralized user management.

Grant JSM admin to the user

For centralized user management

  1. Go to admin.atlassian.com > Directory > Users.

  2. Select the user.

  3. Under Product access, locate the target Jira Service Management site, then assign the Jira Service Management Administrator role.

  4. Save changes.

For original user management

  1. Go to admin.atlassian.com > Apps > select your site.

  2. Open App access > Administration Access.

  3. Add the user to a group that has JSM admin access — or create a dedicated group scoped only to JSM admin.

Review Global admin permissions

After granting the JSM admin role, confirm the user does not hold the Jira global admin role unintentionally:

  1. In your Jira site, go to Settings (⚙) > System > Global permissions.

  2. Find the user (or the groups they belong to) under the Administer Jira permission.

  3. If they appear there and should not have global admin, remove them from that group — or remove the group from the Administer Jira permission entirely if it should not carry that right.

Related documentation

Updated on July 23, 2026

Still need help?

The Atlassian Community is here for you.