Manage Goals app group permissions
Group permissions for the Goals app are currently in early access. This feature will be rolled out to all eligible customers later this year.
Group permissions let admins control what different groups of people can do across the Goals app. They work alongside the per-goal permissions you set on individual goals.
Groups are created and managed in admin.atlassian.com by an org admin. The roles assigned to each group determine the maximum level of access, and app admins for Goals can further tune access by editing group permissions.
Before you start
Only users with the App admin role on the Goals app can access and change group permissions.
Groups and roles are managed in admin.atlassian.com. Contact your org admin to create or modify groups.
Group permissions set a ceiling: they define what users in a group could do across the app. Users still need Can view or Can edit permissions on individual goals to take actions on them.
How roles and groups work
In admin.atlassian.com, every group is assigned a role for the Goals app. The role, not the group, determines a group's permissions. Default groups and custom groups with the same role work the same way.
The permissions set in group permissions can never exceed what the role allows.
The Goals app supports these roles set in admin.atlassian.com:
App admin: has all permissions across the app. Any group with the App admin role gets every permission, and those permissions can't be removed. App admins also override permissions set on individual goals.
User: has all available actions by default. You can edit a User-role group's permissions to restrict specific actions.
The app ships with a default group for each role. For example, goal-admins has the App admin role and goal-user has the User role. You can ask your org admin to create custom groups with any role, and they follow the same rules as the default groups.
Permission categories
Permissions are grouped into categories that match the columns on the Access and permissions page. Each category contains one or more permissions.
Goals
Permissions for working with goals themselves.
View: see goals in the app. This permission is on by default for everyone with app access, and can't be changed.
Create: create new goals in the Goals app, and in other apps that support goals such as Jira and Focus.
Update: post, edit, and delete goal updates, including status, dates, learnings, risks, and decisions.
Manage: edit goal description and fields, rename goals, edit custom field values, teams, followers, and the goal owner. Create and manage metrics. Delete a goal. Manage who has access to a specific goal.
Archive: archive and restore goals.
Connections
Permissions for connecting goals to other items.
Manage: link and unlink projects, related goals, focus areas and Jira work items. Add and remove tags.
To create a new metric and link it to a key result, or to link a supporting metric to a key result, users need both the Create > Manage and Connections > Manage permissions.
Views
Permissions for exporting goal data.
Export: export the goal directory as a CSV file.
Edit group permissions
Select the Settings icon, then select Goals settings.
Select the Access and permissions tab. The groups with app access appear on the page, with the default groups listed first.
Select Edit.
Checkboxes appear for permissions that can be changed. Permissions that are locked by a group's role show a non-editable check or cross and can't be changed.
Use the Select all checkbox to give a group all available permissions, then clear individual checkboxes as needed.
Select Save. Changes take effect immediately.
How group permissions and per-goal permissions work together
Group permissions and per-goal permissions are two separate layers that work together:
Group permissions set what a user could do across the entire Goals app.
Per-goal permissions set what a user can do on a specific goal.
Both layers must grant access for a user to take an action. For example, if a user's group has the Goals > Manage permission but they only have Can view on a specific goal, they can't edit that goal's details.
Note: Group permissions can never grant more access than the group's assigned role allows.
Permissions FAQ
Question | Answer |
|---|---|
Why can't I change some permissions? | Some permissions are locked by the group's role. For example, admin groups have all permissions enabled and can't be restricted. Viewer groups can only view and can't be given additional permissions. Only groups with the User role have editable permissions. |
Can I set permissions for individual users? | Group permissions apply to groups, not individual users. If one person needs unique permissions, they must be in their own group. For per-goal access, use the Share dialog on the individual goal. |
Where do I create or manage groups? | Groups are created and managed in admin.atlassian.com by your org admin. The Goals app uses the groups and roles assigned there. |
What if someone is in more than one group? | A person gets the combined permissions of every group they belong to. If their groups have different roles, the highest level of access applies. |
Was this helpful?