Skip to content

Project Access Review

The Project access source renders a table of role assignments per project: each project’s roles and the users (or groups) assigned to them. It answers “who has access to what, and as what?” — the recurring question behind access reviews, offboarding, and permission audits.

One field: Projects — a comma-separated list of project keys (e.g. PAY, OPS), up to 10 projects per table. Leave it empty and Spotlight uses your first projects.

Or ask the AI: “Who has access to which projects, and in what roles?” — also available as a quick-start template.

Jira only reveals a project’s role members to users with project-admin permission on that project. Spotlight inherits this rule, because it always reads with the viewer’s own permissions:

  • Projects you administer show their role → members breakdown (up to 20 roles per project).
  • Projects you don’t administer appear with an honest no access note — not silently omitted, and never filled in from someone else’s permissions.
  • If some role reads fail mid-fetch, the table discloses which projects are partial.

This also means a shared access review is safe by construction: each viewer sees exactly the slice of the table their own Jira permissions allow. See Sharing & Team Gallery.

  • Quarterly access reviews — a live table beats a stale spreadsheet export.
  • Offboarding checks — scan a departing user’s remaining role memberships, project by project.
  • Least-privilege audits — spot broad role assignments (whole groups in admin roles).

Like every spotlight, the table stores only its definition. Every render re-reads the current role assignments — the review you open today shows today’s access, not the state at save time.