Group Audit for Jira

See every place a group is used in Jira Cloud — before you change or delete it.

Read-only Runs on Atlassian CSV export Free up to 10 users

Install from the Atlassian Marketplace

Jira Cloud only. Free for sites with up to 10 users; per-user pricing above that, with a free trial.

Jira can't tell you where a group is used (JRACLOUD-71967, 1,000+ votes, open since 2019). So admins delete groups blind, break permissions, and rebuild access by support ticket. Group Audit answers the question in seconds: open Jira settings → Apps → Group Audit, type a group name, click Scan.

What it scans

Every row has a deep link to the place it was found, and the CSV export carries the group, site, scan time and a status per row — built for ISO 27001, SOC 2 and SOX user access reviews.

Honest by design. If any check cannot finish, the report is marked incomplete — in the UI and in the CSV export — because an audit tool must never silently omit. Every report also carries coverage notes that spell out what this version cannot scan (workflow conditions, comment visibility restrictions, automation rules, global permission grants and more) instead of hiding it. See the documentation for the full list.

Permissions and data

All scopes are granular read scopes, deliberately not "Administer Jira". The app cannot change or delete anything, stores nothing, and sends nothing out of your site — it runs entirely on Atlassian infrastructure ("Runs on Atlassian"). The security page lists every scope with a reason.

Guide

Where is this group used in Jira Cloud? — every place a group can be used, what the UI and the REST API can tell you without any app, and a checklist before you delete a group.

Documentation & support

Setup, usage and the CSV column reference are in the documentation. Questions, bug reports, feature requests: see the support page or write to kontakt@arbeitstyp.de. We usually reply within two business days.

Privacy in one sentence

The app is read-only, stores nothing, and no data ever leaves your Atlassian instance — see the privacy policy.