Manage third-party spreadsheet app permissions for project data

Use the App access control in your organization’s data security policy to prevent third-party apps, including Google Sheets and Microsoft Excel, from reading protected Jira project data. What is a data security policy?

Block all eligible Marketplace and custom apps

Who can do this?
Role: Organization admin
Plan: Atlassian Guard Standardor Premium
Atlassian Government Cloud: Available

How do I use this control?

Block export and App access are separate data security policy controls. To restrict native Atlassian exports, use Block export. To prevent third-party apps such as Google Sheets or Microsoft Excel from reading Jira data, configure the App access control.

You can set App access as the default configuration for your organization, or add overrides for specific projects, spaces, or classification levels. Apply a default configuration to a policy control

Configure app access

  1. Go to admin.atlassian.com.

  2. Select your organization.

  3. From the navigation, select Security, then Data protection, then Data security policy.

  4. Open the App access control.

  5. Create a draft of the control.

  6. Set the control to Blocked for the default configuration, or add an override for the projects, spaces, or classification levels you want to protect.

  7. If an allowlist is available, leave it empty to block all third-party apps, or add only the apps you want to allow.

  8. Review your changes and activate the control.

What will my users experience?

The information on this page describes what your users will experience when you apply the App access control to your organization. If you add overrides, test the results to make sure the policy protects the data you expect. Configure an override for a control

Blocked user experience

When App access is set to Blocked:

  • Third-party apps can’t access data covered by the policy.

  • Users can still see app menu options such as Open in Google Sheets or Open in Microsoft Excel.

  • If a user opens Jira issue data in Google Sheets or Microsoft Excel, issues from protected projects aren’t returned to the spreadsheet.

  • If a search includes both protected and unprotected projects, only issues from projects not covered by the policy are returned.

Allowed user experience

When App access is set to Allowed:

  • Third-party apps can access data according to the permissions granted to the user and the app.

Limitations

  • The App access control doesn’t hide app menu options, such as Open in Google Sheets or Open in Microsoft Excel.

  • Block export doesn’t control third-party app access. Use Block export for native Atlassian exports, such as CSV, XML, HTML, or Word exports.

  • App access is allowed by default until you configure and activate the control.

Still need help?

The Atlassian Community is here for you.