Members, roles, and groups
Four role templates, assigned directly to a member or to a group of them.
Four role templates
- Read Only — can view ticket fixes, nothing else.
- Engineer — Read Only, plus manages connectors and on-prem agents.
- Reviewer — Read Only, plus approves or rejects proposed remediation actions. Deliberately not the same grant as Engineer: reviewing a proposed infrastructure change and configuring the connectors that feed the pipeline are different responsibilities.
- Administration — everything: manages members, groups, connectors, agents, and reads the audit log.
Assign a role directly, or to a group
The simplest case — most organisations — just needs Members: invite someone by email and pick their role there. A group is for when several people should share a role without editing each person individually, or when someone needs one extra capability (approving remediation actions, say) without a full role change: add them to a Reviewer group instead of changing their direct role.
A member's actual access is the union of their own direct role and every group they belong to — never a replacement. Someone with Read Only as their direct role who's also in a Reviewer group can view tickets and approve remediation actions, but still can't manage connectors; removing them from the group removes exactly that one extra capability, leaving their direct role untouched.
Scope a group to one team
A group can also carry a team scope — the same routing key you already give a connector or on-prem agent to run one team's Jira project, repository, and cloud accounts independently. Set one on a group and its members see only that team's own connectors, agents, and ticket fixes, plus anything left unscoped (the organisation's shared defaults) — never another team's.
This restricts what a member can see, not just what they can do — a separate axis from the role templates above. It's additive across every group someone belongs to, and Administration always sees everything regardless of scope, the same posture as role grants.
Leave the team scope blank (the default) for a group that only grants a role, with no visibility change at all — most organisations that aren't running separate teams will never need this.
Set it up
- Administration → Members → invite by email and pick a role, for the common case
- Administration → Groups → Create group, name it, pick the role template it grants, and optionally a team scope
- Add existing members to the group — only people already invited to this organisation can be added