Jira · Access Governance Reporter
See who can access what in Jira and prove it with audit-ready CSV, then revoke the access that should not exist.
Runs entirely on Atlassian Forge inside your own tenant. No external servers, no data egress.
This app answers a request that has been open on Atlassian's public tracker for years: JRACLOUD-71967, "Group usage: list of project permissions per group", with 1,002 votes. We wrote up the problem and the native workarounds on Atlassian Community.
Jira has no screen that answers "which projects can this user reach, and why?" or "where is this group actually used?" Permission schemes, project roles, and group memberships each tell a fragment; the effective answer lives in nobody's head. Access reviews end up as spreadsheets built from a dozen admin screens.
Built on Atlassian Forge: the app runs on Atlassian's own serverless platform inside your tenant, stores its data in Forge storage, and makes no external network calls. Every scope it requests, and why:
| read:jira-work | projects, permission schemes, and project roles |
| read:jira-user | user details for the matrix and CSV |
| storage:app | the cached report, entirely in your tenant |
Atlassian's own documentation for what Jira does out of the box, so you can see exactly where the gap is:
No. The app runs on Atlassian Forge inside your own tenant with zero external egress, which makes it eligible for Atlassian's Runs on Atlassian trust marker.
Through the Atlassian Marketplace, on your existing Atlassian bill, priced per user like any Cloud app. The listing has a free evaluation and the exact calculator for your tier.
Email support@llmgraph.ai or open an issue from the documentation page. You talk directly to the people who build the app.
Free evaluation from the Marketplace listing. If it does not fit your workflow, tell us what would and we will build it.