Governance
Users
Navigate to Governance → Users for a security and access risk audit of every user licensed in the org. The Governance pillar audits people, access, and directory health. A single over-provisioned account or misconfigured permission scheme can expose data across the entire instance.

Risk Categories
| Risk Category | Condition | Notes |
|---|---|---|
| Dormant | Active account with last activity older than 90 days. | Active = true but not recently used. |
| Inactive Admin | Admin with no activity for ≥ 60 days. | Review and remove from admin group. |
| Overpermissioned | Admin on 15+ projects simultaneously. | Review project-level permissions. |
| No Group | User with no group membership. | May have direct permission grants. |
Note: User deactivation must be performed in the Atlassian Admin Console (admin.atlassian.com) - the Jira REST API does not support direct deactivation on Jira Cloud.