Sealfield documentation
Public knowledge base source. Host at https://greatwork.company/apps/sealfield/docs.
What Sealfield is
Sealfield adds restricted fields to Jira Cloud work items. A restricted field looks like a field on the work item, but its value is stored by the app on Atlassian's Forge platform, not in Jira. Only the people a Jira admin chooses can see or change it.
Because Jira never holds the value, Jira search (JQL), filters, list views, CSV exports, dashboards, the REST API, Automation and other apps cannot read it.
Set up (Jira admins)
- Go to Jira settings > Apps > Sealfield > Fields and click Add restricted field.
- Name it and pick a type: short text, paragraph, number, date, select list or link.
- Choose where it appears: project keys and work types (empty means all).
- Choose Who can see it and Who can change it: project roles, groups, people, the work item's reporter, the work item's assignee. Editors can always see the value.
- Choose what everyone else sees: nothing, or the field name marked Restricted.
- Optional: Mask the value until the viewer clicks Reveal. Each reveal is logged.
- Optional (on by default): editors also need Jira's Edit work items permission.
People still need to be able to open the work item in Jira. Sealfield never widens Jira's permissions, and Jira admins get no automatic access to values.
Use it (everyone)
Open a work item and expand Restricted fields in the context area. You see the fields you are allowed to see. Click Edit to change a value, Reveal to show a masked one.
If someone changed the value after you opened it, saving is refused so you don't overwrite their change; reload and try again.
Report
Apps > Restricted fields report: pick a field (and optionally a project key) to list its values across the work items you can see. Download CSV gives the same rows (up to 5,000). Every report and download is logged.
Move values from an existing Jira field
- Create the restricted field first (same kind of values).
- Copy from a Jira field: pick the restricted field, the Jira field to copy from, and a JQL
query (for example
project = HR). Start the copy. - The copy never changes the Jira field. Existing restricted values are kept unless you turn on overwrite. The job shows counts and the first 50 work items it could not convert.
- When you're ready, click Clear Jira field... on the finished copy job and type CLEAR. Sealfield empties the Jira field only on work items where the restricted copy holds exactly the same value. The rest are left alone and listed.
- Jira's History tab keeps the old values of the Jira field. Sealfield cannot remove them.
Audit log
Jira settings > Apps > Sealfield > Audit log lists reveals, edits, clears, refused reveals and edits, reports, exports, rule changes and jobs, newest first, with who and when. It never contains values. Filter by field or work item key; export as CSV. Keep it 30, 90, 180 or 365 days (Settings). Turn on Log every view to also log each time someone opens a work item showing them a non-empty restricted value.
Delete and export
- Clear a value: Edit, empty it, Save.
- Deleting a work item deletes its restricted values.
- Deleting a restricted field (type its name to confirm) deletes all its values.
- Export on the Fields tab gives Jira admins a CSV of every value of a field, for backups or leaving the app. It is logged. Restricted values are not part of Jira's own site backups.
What Sealfield does not do
- It does not hide or lock Jira's own fields (system fields or existing custom fields).
- Restricted values cannot be searched with JQL, shown on boards or list views, used in Automation, or entered on create or transition screens or the customer portal.
- People allowed to see a value can still copy it or take a screenshot.
- Jira admins can change the rules (logged) and export values (logged).
- Up to 50 restricted fields per site.