Documentation — Group Audit for Jira

Setup, usage, CSV reference and troubleshooting.

1. Setup

  1. Install Group Audit for Jira from the Atlassian Marketplace (as a Jira admin: Apps → Explore more apps, search for “Group Audit”, then Install; or use the “Try it free” button on the listing).
  2. Open it under Jira Settings (⚙) → Apps → Group Audit. The page is visible to Jira administrators only, and the app additionally verifies the ADMINISTER permission on every request.
  3. No configuration is needed. The app stores nothing and writes nothing.

2. Running a scan

  1. Start typing a group name and pick the group from the suggestion list (keyboard: arrow keys + Enter).
  2. Click Scan usages. A checklist shows each area being scanned. Large sites are scanned in resumable chunks; hundreds of projects or thousands of filters are fine — the scan just takes longer.
  3. Read the summary (“N usages in M places · affects P projects”), the result table, and — always — the coverage notes at the bottom.

What is scanned

What is not scanned (coverage notes)

Every report discloses its limits — in the UI and in the CSV:

Rule of thumb: a report is a decision aid, not a green light. Read the coverage notes, and never delete a group based on an incomplete report.

3. CSV export

Download CSV saves the full report; Copy CSV puts it on the clipboard. The file is UTF-8 with BOM (opens correctly in Excel, Google Sheets and Numbers). Values that could be interpreted as spreadsheet formulas are prefixed with an apostrophe on purpose (formula-injection protection).

ColumnMeaning
SurfaceWhere the group is used (e.g. “Permission scheme”, “Filter JQL”) — plus the special rows “Manual check required”, “Scan error” and “Coverage note”
LocationThe scheme, project, filter or dashboard name
DetailThe specific grant, event, role or note
ProjectsAffected projects; “unknown (lookup failed)” or “(list may be incomplete)” when attribution data could not be fully read — never silently empty
LinkDeep link to the place in Jira (or admin.atlassian.com for product access)
Group / Group IDThe audited group (audit metadata on every row)
Scanned at (UTC)ISO timestamp of the scan
SiteYour Jira site URL
Scan statusComplete (see coverage notes) — every report carries at least the standing coverage notes — or INCOMPLETE — n checks failed

If any check failed, the filename carries an -INCOMPLETE suffix and each failure appears as a “Scan error” row.

4. Permissions & security

5. Troubleshooting

“Incomplete scan” banner

One or more checks could not finish — usually Jira rate limiting on very large instances or a transient Jira error. The failed checks are listed in the banner and as “Scan error” rows in the CSV. Fix: run the scan again (off-peak hours help on big sites). Never act on an incomplete report alone.

“Could not verify permissions”

Jira was temporarily unavailable while checking your admin permission. Retry in a moment.

“No active license”

The trial or subscription is inactive. A Jira admin can manage it under Apps → Manage apps.

“The site URL could not be determined”

Reload the page. Result links and the CSV link column need the site URL; everything else works without it.

Scan is slow on a large site

The app scans sequentially with rate-limit-aware backoff on purpose, so it never degrades your instance. Hundreds of projects can take a few minutes — the progress checklist shows where it is.

Contact

Anything unclear or broken? Support page · kontakt@arbeitstyp.de