Getting started
Installing the app
What the app needs, what permissions it requests, and how to find it after install.
Before you install
You need:
- a Jira Cloud site on Standard, Premium, or Enterprise (see the note about Free below)
- the Administer Jira global permission on that site
- permission to install Marketplace apps, which on most sites is the same person
Installing
- Open Jira Settings → Apps → Explore more apps, or go to the Atlassian Marketplace listing directly.
- Search for Permission Audit.
- Choose Try it free or Buy now. Atlassian’s standard 30-day trial applies, and a trial gives you the full Advanced experience regardless of which edition it is attached to.
- Confirm the permission request (see below).
Installation is handled entirely by Atlassian. There is no account to create with QuinTek, no key to paste, and no configuration required before the first scan.
What the app asks for
Forge shows you the scopes an app requests at install. Permission Audit requests read access to the Jira configuration it has to resolve:
| What it reads | Why |
|---|---|
| Projects and project settings | To enumerate the estate and find each project’s schemes |
| Permission schemes | The grants themselves — the source of every permission |
| Project roles and role actors | The middle of the derivation chain |
| Groups and group membership | How an account reaches a role or a direct grant |
| The user directory | To report on every account, including those with no access |
All of it is used as read access: the app never changes a scheme, a role, a group, or a
grant. One scope on the consent screen, manage:jira-configuration, is nonetheless admin-level —
it is the only way Jira lets an app read group membership, and the
security page explains it
scope by scope.
After installing
The app appears under Jira Settings → Apps → Permission Audit.
Opening it requires Administer Jira. A project administrator without site-admin rights cannot reach the app through this entry point — that is a property of the Jira admin page module, not a setting you can change.
Nothing has been scanned yet. Continue to Running your first scan.
A note on what the app itself can do
Worth knowing before your security review asks: at install, Atlassian places app principals with admin-level scopes into an administrator group on your site. The practical effect is that such apps hold Administer Jira.
This is standard Atlassian behaviour and applies to many of the apps already on your site — including this one. Permission Audit reports it rather than hiding it, because an app quietly holding site admin is exactly the kind of invisible privilege an access review exists to surface. You will see app principals in the report with the access they actually hold.
Uninstalling
Uninstall from Jira Settings → Apps → Manage apps. Atlassian removes the app’s data with the installation. Because everything the app stored lived inside your own tenant, there is nothing held anywhere else to request the deletion of.