Forge-native access review & audit evidence. Your data never leaves Atlassian.
Access Review shows who can access which Jira project, at what level, and via which path (the group → role → scheme chain), flags access risks and inconsistencies, and produces auditor-ready evidence for ISO 27001 / SOC 2 access reviews — all without your data leaving Atlassian.
The app is available to Jira administrators only.
Pick a project to see every user with access, their status, the permission, and the access path (why). Filter by permission, search, "direct grants only", "deactivated only", and optionally show app/system accounts. Path legend:
group — access via a grouprole → group — a project role granted to a group you belong torole → individual user — you are added to the role directlydirect grant — granted to you directly in the permission schemeproduct — via product access (application role)A prioritised (high / medium / low) list of findings: deactivated users who still have access, direct user grants, too many project admins, public ("anyone") access, empty groups used in schemes, unused permission schemes, and licensed users without project access.
Run a repeatable certification round: start a review (all projects or one), then mark each user's access Approve / Remove / Exception. Decisions save as you go. Complete the review to lock it with a timestamp as evidence. Export the round as PDF or CSV. Note: the app reports decisions; it does not remove access from Jira.
Generate auditor-ready files: an Audit report (opens a printable page → Print → Save as PDF) and CSV exports of the overview and the risk findings. Each export embeds the site, timestamp, who generated it, and the scope. Everything is produced in your browser — nothing is sent anywhere.
Read-only scopes only; all processing on Forge; no external egress. See the privacy policy.
See the support page.