← Accessroll
DocumentationPrivacyEULASupport

Accessroll for Jira: documentation

Public docs for https://greatwork.company/apps/accessroll.

Getting started

  1. Install Accessroll from the Atlassian Marketplace. Only Jira admins see it.
  2. Open Jira settings > Apps > Accessroll. The first time, Jira asks you to allow the app to act for you; Accessroll only ever acts with your own permissions.
  3. Pick a tab: Import CSV, People, Copy and offboard. Each one builds a preview; you confirm on the batch page.

Who can do what: changing group membership and removing people from Jira need a site admin (or a user access admin). Project roles need Administer projects in each project, or Administer Jira.

Import CSV

The first row is a header. Columns (any order, any case):

ColumnAlso accepted asWhat to put
useremail, accountId, nameAn email address, an account ID, or a display name that only one person has
actionoperationadd, remove or remove from Jira (optional; the screen sets a default)
groupgroups, group nameA group name. Several: `design
projectproject key, spaceA project key or name. Several: `WEB
roleproject roleA role name in those projects. Several: `Member

Example:

user,action,group,project,role
ana.ruiz@example.com,add,design,,
ana.ruiz@example.com,add,,WEB|OPS,Member
ben.okafor@example.com,remove,contractors,,
chloe.park@example.com,remove from Jira,,,

Upload the file or paste rows straight from Excel or Google Sheets (tab separated works). Semicolon separated files from European Excel work too.

The preview and confirming

Every line gets one of: Will change, Already so (nothing to do), Error (with the reason), Skipped (duplicate, or moot because the person is removed from Jira in the same batch). Contradicting lines (one adds, another removes the same thing) are errors.

To apply, type the phrase shown, for example REMOVE 12 when twelve lines take access away, or REMOVE 2 FROM JIRA. Batches run in steps with a progress bar. If you leave the page, the batch pauses; open it from Batches and press Resume. Retry failed re-runs only the lines Jira refused.

People

Scan users reads every account on the site (up to 20,000): status, account type, groups, Jira products, and whether they updated an issue in the window you choose (30 to 365 days) or ever. Then filter: account type, active or inactive, in or not in a group, no issue activity, never updated an issue, no Jira product, name or email. Export these as CSV gives you the list. Act on everyone who matches previews one of: remove them from one group, take them out of every group and project role, or remove them from Jira. App accounts are never included.

"Activity" is issue updates in Jira, the signal Jira gives apps. Jira does not give apps login dates, so someone who only reads issues shows as idle.

Copy and offboard

  • Copy access: pick a person to copy from and the people to copy to. Groups and project roles they were added to directly are copied. Admin and protected groups are left out and listed.
  • Offboard: take people out of every group and every project role, or remove them from Jira. Jira keeps project role entries after a removal, so Accessroll removes those first.

Both read every project's roles first (a few seconds per 10 projects, kept for an hour).

Undo

Open a finished batch and press Undo this batch. You get a new preview that reverses every applied change. Removing someone from Jira cannot be reversed by an app, so for those people Accessroll recorded their groups and project roles before the removal: re-invite them in Atlassian Administration, then confirm the undo (or Retry failed if you ran it first).

Audit log

Every preview, confirmation, pause, retry, settings change and individual change, with the admin, the person, the target and the result. Export the audit log as CSV for your records. Changes are made as you, so Jira's own audit log shows them under your name too.

Settings

  • Protected groups: never changed by Accessroll.
  • Allow changes to admin groups: off by default (site-admins, jira-admins and similar).
  • Allow removing people from Jira: off by default.
  • Most lines in one batch: default 5,000, up to 10,000.

Always on: app accounts and Atlassian-managed groups are never changed; nobody can remove their own access.

Limits

  • Accessroll cannot create, invite, suspend or deactivate Atlassian accounts. Use Atlassian Administration for those, then Accessroll for groups and roles.
  • Project roles: only people added directly are changed; group actors in roles are left alone.
  • Batches up to 10,000 lines; scans up to 20,000 accounts.