Project Access Review
The Project access source renders a table of role assignments per project: each project’s roles and the users (or groups) assigned to them. It answers “who has access to what, and as what?” — the recurring question behind access reviews, offboarding, and permission audits.
Configuring it
Section titled “Configuring it”One field: Projects — a comma-separated list of project keys (e.g. PAY, OPS), up to 10 projects per table. Leave it empty and Spotlight uses your first projects.
Or ask the AI: “Who has access to which projects, and in what roles?” — also available as a quick-start template.
Permissions — and honesty about them
Section titled “Permissions — and honesty about them”Jira only reveals a project’s role members to users with project-admin permission on that project. Spotlight inherits this rule, because it always reads with the viewer’s own permissions:
- Projects you administer show their role → members breakdown (up to 20 roles per project).
- Projects you don’t administer appear with an honest no access note — not silently omitted, and never filled in from someone else’s permissions.
- If some role reads fail mid-fetch, the table discloses which projects are partial.
This also means a shared access review is safe by construction: each viewer sees exactly the slice of the table their own Jira permissions allow. See Sharing & Team Gallery.
What it’s useful for
Section titled “What it’s useful for”- Quarterly access reviews — a live table beats a stale spreadsheet export.
- Offboarding checks — scan a departing user’s remaining role memberships, project by project.
- Least-privilege audits — spot broad role assignments (whole groups in admin roles).
Live data
Section titled “Live data”Like every spotlight, the table stores only its definition. Every render re-reads the current role assignments — the review you open today shows today’s access, not the state at save time.
- Sharing & Team Gallery — publishing a review without leaking data.
- Custom Plans — for access questions this table doesn’t answer.