Manage Projects app group permissions

Group permissions let admins control what different groups of people can do across the Projects app on your site. They work alongside the per-project permissions you set on individual projects.

Groups are created and managed in admin.atlassian.com by an org admin. The roles assigned to each group determine the maximum level of access, and the App admin can further restrict their access by editing the group permissions.

Before you start

  • Only users with the App admin role on the Projects app can access and change group permissions.

  • Groups and roles are managed in admin.atlassian.com. Contact your org admin to create or modify groups.

  • Group permissions set a ceiling: they define what users in a group could do across the app. Users still need Can view or Can edit permissions on individual projects to take actions on them.

How roles and groups work

In admin.atlassian.com, every group is assigned a role for the Projects app. The role, not the group, determines a group's permissions. Default groups and custom groups with the same role work the same way.

The permissions set in group permissions can never exceed what the role allows.

The Projects app supports these roles set in admin.atlassian.com:

  • App admin: has all permissions across the app. Any group with the App admin role gets every permission, and those permissions can't be removed. App admins also override permissions set on individual projects.

  • User: has all available actions by default. You can edit a User-role group's permissions to restrict specific actions.

The app ships with a default group for each role. For example, project-admins has the app admin role and project-user has the user role. You can ask your org admin to create custom groups with any role, and they follow the same rules as the default groups.

Permission categories

Permissions are grouped into categories that match the columns on the Access and permissions page. Each category contains one or more permissions.

Projects

Permissions for working with projects objects themselves.

  • View: see projects in the app. This permission is on by default for everyone with app access and can't be changed.

  • Create: create new projects in the Projects app, and in other apps that support projects such as Jira.

  • Update: post, edit, and delete project updates, including status, dates, learnings, risks, and decisions.

  • Manage: edit project details in the About tab, edit project name and fields, update custom fields, followers and contributors, the project owner, and who has access to a specific project.

  • Archive: archive and restore projects.

Connections

Permissions for connecting projects to other items.

  • Manage: link and unlink goals, related projects, focus areas, and work items from Jira and Jira Align; add and remove links and tags.

Views

Permissions for exporting project data.

  • Export: export the project directory as a CSV file.

Edit group permissions

  1. Select the Settings icon, then select Project settings.

  2. Select the Access and permissions tab. The groups with app access appear on the page, with the default groups listed first.

  3. Select Edit.

  4. Checkboxes appear for permissions that can be changed. Permissions that are locked by a group's role show a non-editable check or cross and can't be changed.

  5. Use the Select all checkbox to give a group all available permissions, then clear individual checkboxes as needed.

  6. Select Save. Changes take effect immediately.

How group permissions and per-project permissions work together

Group permissions and per-project permissions are two separate layers that work together:

  • Group permissions set what a user could do across the entire Projects app.

  • Per-project permissions (Can view or Can edit on the Share dialog) set what a user can do on a specific project.

Both layers must grant access for a user to take an action. For example, if a user's group has the Projects > Manage permission but they only have Can view on a specific project, they can't edit that project's name.

Permissions FAQ

Question

Answer

Why can't I change some permissions?

Some permissions are locked by the group's role. For example, admin groups have all permissions enabled and can't be restricted. Only groups with the User role have editable permissions.

Where do I create or manage groups?

Groups are created and managed in admin.atlassian.com by your org admin. The Projects app uses the groups and roles assigned there.

Can I set permissions for individual users?

Group permissions apply to groups, not individual users. If one person needs unique permissions, they must be in their own group. For per-project access, use the Share dialog on the individual project.

What if someone is in more than one group?

A person gets the combined permissions of every group they belong to. If their groups have different roles, the highest level of access applies.

Still need help?

The Atlassian Community is here for you.