Documentation

Access Review & Audit Trail for Jira · Last updated: 25 June 2026

Overview

Access Review & Audit Trail helps Jira admins prove who has access to what — and exactly how it changed over time. It takes periodic snapshots of project, group, and role permissions, shows a clean diff of every grant added or removed since the last review, lets reviewers sign off on each cycle, and exports audit-ready evidence as CSV or PDF. The App runs entirely on Atlassian infrastructure with no data egress.

Installation

  1. Open the App's Atlassian Marketplace listing and choose Try it free (30-day trial) or Buy now.
  2. Select the Jira site to install on and approve the requested read-only permissions.
  3. Open the App from your Jira apps menu. You will land on the Access Review page.

Permissions the App requests (all read-only)

ScopeWhy it is needed
read:group:jira, read:user:jira, read:avatar:jira Read group membership and account labels (who is in which group).
read:jira-work Iterate projects and read project-role actors.
read:permission-scheme:jira Read project permission-scheme grants per project.
read:audit-log:jira Read permission-change events to enrich the change history.

The App requests no write scopes and declares no external network domains.

Getting started

1. Run your first snapshot

On first open you will see an empty state. Click Run your first access snapshot. The App scans your group memberships, project roles, and project permissions and stores a baseline snapshot. The first run also prepares the App's storage automatically.

2. Review the current access

After a snapshot, the Current access card shows how many access grants exist by category (group membership, project role, project permission). This is the authoritative picture of who has access right now.

3. Let snapshots accumulate

Snapshots run on a weekly schedule automatically, and you can trigger one any time. Each new snapshot is compared against the previous one so the App can show what changed between two points in time.

Running an access review (attestation)

  1. Open a review cycle. A cycle covers the changes since the last closed review up to the most recent complete snapshot.
  2. Review the change list. Every ADDED and REMOVED grant in the period is listed, grouped by project, group, and role. Changes are matched on stable account/group IDs, so renaming a user or group is never shown as a false change.
  3. Record a decision. For the cycle, a reviewer records a sign-off decision — approved, revoke (flag access that should be removed), or acknowledged. Each decision is stored with the reviewer's account ID and a timestamp.
  4. Close the cycle. Closing locks the review as a permanent, append-only attestation record that your auditors can rely on.

Changing a decision: records are append-only. To change a previously recorded decision within an open cycle, submit a new decision for the same item — the latest decision is the effective one, and the full trail is retained. Once a cycle is closed it is immutable; start a new cycle for subsequent changes.

Exporting audit evidence

From a review cycle you can export:

  • CSV — the review, sign-off, and change history as data for spreadsheets or evidence repositories.
  • PDF — a formatted, branded report suitable for SOC 2 and ISO 27001 audit evidence.

Both formats are generated locally in your browser and downloaded directly to your device. No export data is sent to any external service.

Free vs. paid features

CapabilityPlan
View current access & snapshotsFree
Permission change diffFree
Reviewer sign-off (attestation)Paid
CSV / PDF audit exportPaid
Full append-only history beyond 180 daysPaid

Entitlement is enforced on the server. A 30-day free trial unlocks all paid features.

Coverage note

Project, group, and role access is read authoritatively. Global / admin-level access is shown as an approximate layer with a clear confidence flag, because it is derived rather than read directly. Treat approximate-flagged rows as indicative.

Privacy & security

The App runs entirely on Atlassian infrastructure, stores data only in Atlassian-hosted Forge SQL, requests read-only scopes, and performs no data egress. See the full Privacy Policy.

Support

Questions, bugs, or feature requests: support@dvlslabs.com. We typically respond within two business days.