What are Jira permissions?

Jira permissions control what each person can see and do, from administering your whole site down to viewing a single work item (formerly issues). Jira manages access at three levels, global, space, and work item.
You grant that access through groups and roles rather than one person at a time. This keeps access consistent as your team grows and makes it easy to see who can do what.
Access works at three levels. Global permissions cover your whole site, space permissions cover a single space (previously projects), and work item security covers individual work items.
You grant access through groups and roles. Assigning people to groups and space roles scales better than setting permissions user by user.
Permission schemes make access reusable. A permission scheme is a set of permissions you build once and apply to many spaces with the same needs.
Give people the access they need. Keep the list of admins small, use roles for everyone else, and review access as teams and spaces change.
What are users and groups in Jira?
A user is anyone who can log in to your Jira site, and each user counts toward your Jira license. A group is a collection of users who share the same access.
Instead of granting permissions to people one by one, you add them to a group and manage the whole group at once. Groups are the simplest way to handle access for people who need the same thing.
When someone joins the team, you add them to the right group and they inherit its access; when they leave, you remove them. Organization admins create and manage groups, and Jira admins use those groups to grant permissions across the site.

What are the types of Jira permissions?
Jira has three types of permissions, from the broadest to the most specific: global permissions, space permissions, and work item security. Each layer controls a different scope of access.
Global permissions apply across your entire site, not to any one space. They cover site-wide actions like administering Jira, browsing users and groups, and creating team-managed spaces. Global permissions are granted to groups and should be kept to a small, trusted set of people.
Space permissions control what people can do inside a single space, such as viewing the space, creating and editing work items, assigning work, and commenting. You manage these through permission schemes and grant them to groups, individual users, or space roles.
Work item security is the most granular level. It restricts who can see specific work items within a space, which is useful for sensitive work like HR or security cases. You manage this with work item security schemes.
These layers work together: a person needs the right access at each level to act. For example, someone has to be able to view a space before they can edit a work item in it.

What is a permission scheme?
A permission scheme is a set of space permissions you define once and reuse across multiple spaces. Rather than setting permissions individually for every space, you build a scheme that matches a common need, then apply it wherever that need exists.
Most organizations have spaces with the same access requirements. An engineering team, for example, may want the same setup across every one of its spaces.
With a scheme, you configure that once and apply it to all of them. When the requirements change, you update the scheme and every space using it stays in sync.
One scheme can serve many spaces, which keeps access consistent and cuts down on repetitive setup.
What are space roles in Jira?
Space roles (previously project roles) are a flexible way to connect people to a function within a specific space. They work like groups, with one key difference: group membership is site-wide, while space role membership applies only to the space it belongs to.
That makes roles ideal for granting access per space without creating a new group every time.
Jira includes default space roles, Administrators, Developers, and Users, and admins can create more to fit how a team works. In a permission scheme, you grant permissions to a role instead of to named people.
Then, in each space, you decide who fills that role. Reassigning access becomes simple: add someone to the role and they inherit its permissions, no scheme changes needed.
Roles are also easier to manage over time than naming individuals. When you grant permissions to a role and assign people to it, you can see at a glance who can do what, and reassign it cleanly as responsibilities shift.
How do you restrict access to sensitive work items?
When some work needs tighter control than the rest of a space, you have two options: work item security schemes and guest access.
Work item security schemes: Set security levels on individual work items so only certain users, groups, or roles can see them. This keeps sensitive work, like legal, HR, or security cases, hidden from the wider space while the rest stays visible.
Guest access: Bring in external collaborators without a full license. Guests are free and limited to a single space with a fixed set of permissions, so you can work with clients or vendors while keeping the rest of your site private.
How do you decide who gets which permissions?
A good permission setup gives people the access they need to do their work, and no more. A few practices keep it manageable as you scale:
Grant access through groups and roles, not to individuals. It is easier to manage and audit, and reassigning access is a single change.
Keep the admin list small. Global and admin permissions affect everything, so reserve them for a few trusted people.
Match access to the work. Give each role what its function needs, and use work item security only for genuinely sensitive work.
Review access regularly. As teams and spaces change, check that permissions still reflect who does what.
Get control of Jira without the slow down
Jira gives you control over access without slowing your team down. Set the right permissions once, grant them through groups and roles, and let people focus on the work.
Try Jira for free to see how permissions, roles, and spaces fit together, or read the Jira getting started guide to set up your first space.
Frequently asked questions about Jira permissions
Who can change Jira permissions?
Jira admins manage global permissions and permission schemes across the site. Space admins can manage the people in their space's roles, so they can grant access to their own team without help from a Jira admin.
What is the difference between a group and a space role?
A group is site-wide: its membership applies everywhere and is managed by admins. A space role applies only to one space, and a space admin can change who fills it. Use groups for broad, consistent access and roles for per-space access.
What is the difference between global and space permissions?
Global permissions cover site-wide actions across your whole Jira site, like administering Jira. Space permissions cover what people can do inside a single space, like viewing, creating, and editing work items.
Can you restrict access to a single work item in Jira?
Yes. Work item security schemes let you set security levels on individual work items so only chosen users, groups, or roles can see them, even within a space others can access.
Are Jira permission schemes available on the Free plan?
No. Space permission schemes, space roles, and work item security schemes aren't available on Free Jira sites. They're available on paid plans for teams that need more granular access control.
How do you troubleshoot Jira permissions?
If someone has too much or too little access, you can use Rovo to explain and troubleshoot your setup. In Rovo Chat, enter /manage-jira-permissions and describe the problem, or ask for a rundown of your current permissions.