QuinTek

Getting started

Installing the app

What the app needs, what permissions it requests, and how to find it after install.

Before you install

You need:

  • a Jira Cloud site on Standard, Premium, or Enterprise (see the note about Free below)
  • the Administer Jira global permission on that site
  • permission to install Marketplace apps, which on most sites is the same person
On Jira Free. Permission schemes and project roles do not exist on the Free plan. The app will install and run, but there is very little for it to resolve, and the report will be close to empty. This is a property of the plan, not a fault in the scan.

Installing

  1. Open Jira Settings → Apps → Explore more apps, or go to the Atlassian Marketplace listing directly.
  2. Search for Permission Audit.
  3. Choose Try it free or Buy now. Atlassian’s standard 30-day trial applies, and a trial gives you the full Advanced experience regardless of which edition it is attached to.
  4. Confirm the permission request (see below).

Installation is handled entirely by Atlassian. There is no account to create with QuinTek, no key to paste, and no configuration required before the first scan.

No app should ever ask you for an API token. Permission Audit does not, and cannot — Atlassian's Marketplace Security Enforcement Policy prohibits the pattern outright. If any Marketplace app asks an administrator to paste a personal access token, that is grounds to decline it.

What the app asks for

Forge shows you the scopes an app requests at install. Permission Audit requests read access to the Jira configuration it has to resolve:

What it reads Why
Projects and project settings To enumerate the estate and find each project’s schemes
Permission schemes The grants themselves — the source of every permission
Project roles and role actors The middle of the derivation chain
Groups and group membership How an account reaches a role or a direct grant
The user directory To report on every account, including those with no access

All of it is used as read access: the app never changes a scheme, a role, a group, or a grant. One scope on the consent screen, manage:jira-configuration, is nonetheless admin-level — it is the only way Jira lets an app read group membership, and the security page explains it scope by scope.

After installing

The app appears under Jira Settings → Apps → Permission Audit.

Opening it requires Administer Jira. A project administrator without site-admin rights cannot reach the app through this entry point — that is a property of the Jira admin page module, not a setting you can change.

Nothing has been scanned yet. Continue to Running your first scan.

A note on what the app itself can do

Worth knowing before your security review asks: at install, Atlassian places app principals with admin-level scopes into an administrator group on your site. The practical effect is that such apps hold Administer Jira.

This is standard Atlassian behaviour and applies to many of the apps already on your site — including this one. Permission Audit reports it rather than hiding it, because an app quietly holding site admin is exactly the kind of invisible privilege an access review exists to surface. You will see app principals in the report with the access they actually hold.

Uninstalling

Uninstall from Jira Settings → Apps → Manage apps. Atlassian removes the app’s data with the installation. Because everything the app stored lived inside your own tenant, there is nothing held anywhere else to request the deletion of.