Permissions
Role Comparison Table
| Capability | Global Admin | Member | No Role |
|---|---|---|---|
| Log time against issues | Yes | Yes | No |
| Edit own time entries | Yes | Yes | No |
| Approve / reject time entries | Yes | No | No |
| View capacity analytics | Yes | Yes | Read-only |
| Run backlog prioritization | Yes | Yes | Read-only |
| Score backlog items | Yes | Yes | No |
| View portfolio data | Yes | Yes | Read-only |
| Access Settings | Yes | No | No |
| Assign / revoke Member roles | Yes | No | No |
| View My Permissions tab | Yes | Yes | Yes |
| Create billing accounts | Yes | No | No |
| Create scoring templates | Yes | Member (own) | No |
| Create and save portfolios | Yes | Yes | No |
| Delete portfolios created by others | Yes | No | No |
How Global Admin Works
Global Admin is automatically detected - not assigned inside the app. Anyone with the Jira site-level ADMINISTER permission is automatically a Global Admin in this app.
- To grant Global Admin: add the user to the Jira administrator group in Jira user management
- To revoke Global Admin: remove the user from the Jira administrator group
- The app detects changes automatically on the user's next action - no manual sync needed
Common Permission Scenarios
A new hire needs to start logging time → Assign them the Member role via RBAC → User Roles.
A contractor's engagement has ended → Remove the Member role via RBAC → User Roles. Their read-only access remains but they can no longer log time or modify data.
A team lead was promoted and needs full admin access → Add them to the Jira administrator group in Jira user management. The app automatically recognizes them as Global Admin.
A user doesn't know why they can't log time → Direct them to Settings → My Permissions. If they have no role, the Restricted Actions section will confirm they need the Member role.
A user asks why they can see portfolios but not edit them → Portfolio viewing is available to Members. Creating, editing, and saving portfolios requires the Member role; editing portfolios created by others requires Global Admin.