Documentation
Access Review & Audit Trail for Jira · Last updated: 25 June 2026
Overview
Access Review & Audit Trail helps Jira admins prove who has access to what — and exactly how it changed over time. It takes periodic snapshots of project, group, and role permissions, shows a clean diff of every grant added or removed since the last review, lets reviewers sign off on each cycle, and exports audit-ready evidence as CSV or PDF. The App runs entirely on Atlassian infrastructure with no data egress.
Installation
- Open the App's Atlassian Marketplace listing and choose Try it free (30-day trial) or Buy now.
- Select the Jira site to install on and approve the requested read-only permissions.
- Open the App from your Jira apps menu. You will land on the Access Review page.
Permissions the App requests (all read-only)
| Scope | Why it is needed |
|---|---|
read:group:jira, read:user:jira, read:avatar:jira |
Read group membership and account labels (who is in which group). |
read:jira-work |
Iterate projects and read project-role actors. |
read:permission-scheme:jira |
Read project permission-scheme grants per project. |
read:audit-log:jira |
Read permission-change events to enrich the change history. |
The App requests no write scopes and declares no external network domains.
Getting started
1. Run your first snapshot
On first open you will see an empty state. Click Run your first access snapshot. The App scans your group memberships, project roles, and project permissions and stores a baseline snapshot. The first run also prepares the App's storage automatically.
2. Review the current access
After a snapshot, the Current access card shows how many access grants exist by category (group membership, project role, project permission). This is the authoritative picture of who has access right now.
3. Let snapshots accumulate
Snapshots run on a weekly schedule automatically, and you can trigger one any time. Each new snapshot is compared against the previous one so the App can show what changed between two points in time.
Running an access review (attestation)
- Open a review cycle. A cycle covers the changes since the last closed review up to the most recent complete snapshot.
- Review the change list. Every ADDED and REMOVED grant in the period is listed, grouped by project, group, and role. Changes are matched on stable account/group IDs, so renaming a user or group is never shown as a false change.
- Record a decision. For the cycle, a reviewer records a sign-off
decision —
approved,revoke(flag access that should be removed), oracknowledged. Each decision is stored with the reviewer's account ID and a timestamp. - Close the cycle. Closing locks the review as a permanent, append-only attestation record that your auditors can rely on.
Changing a decision: records are append-only. To change a previously recorded decision within an open cycle, submit a new decision for the same item — the latest decision is the effective one, and the full trail is retained. Once a cycle is closed it is immutable; start a new cycle for subsequent changes.
Exporting audit evidence
From a review cycle you can export:
- CSV — the review, sign-off, and change history as data for spreadsheets or evidence repositories.
- PDF — a formatted, branded report suitable for SOC 2 and ISO 27001 audit evidence.
Both formats are generated locally in your browser and downloaded directly to your device. No export data is sent to any external service.
Free vs. paid features
| Capability | Plan |
|---|---|
| View current access & snapshots | Free |
| Permission change diff | Free |
| Reviewer sign-off (attestation) | Paid |
| CSV / PDF audit export | Paid |
| Full append-only history beyond 180 days | Paid |
Entitlement is enforced on the server. A 30-day free trial unlocks all paid features.
Coverage note
Project, group, and role access is read authoritatively. Global / admin-level access is shown as an approximate layer with a clear confidence flag, because it is derived rather than read directly. Treat approximate-flagged rows as indicative.
Privacy & security
The App runs entirely on Atlassian infrastructure, stores data only in Atlassian-hosted Forge SQL, requests read-only scopes, and performs no data egress. See the full Privacy Policy.
Support
Questions, bugs, or feature requests: support@dvlslabs.com. We typically respond within two business days.