Access Review logo: an open padlock Access Review for Jira

Support

Access Review for Jira is built and supported by Bobook Limited, Dublin, Ireland.

Contact us

Email: support@bobook.club

You are writing to the people who wrote the app. There is no ticket-deflection bot and no first-line script.

Response times

Target
First reply 1 business day
A defect that blocks the report Worked on the day it is reproduced
Feature requests Answered honestly — including "no", with the reason

Business days are Monday to Friday, 09:00–18:00 Irish time (UTC / UTC+1).

What to include

The more of this you send, the faster the answer:

If you attach the CSV export, redact any individual names first — grants made to a single person appear in it.

Reporting a security issue

Please email support@bobook.club with "SECURITY" in the subject. Do not open a public report. We will acknowledge within one business day and keep you updated until it is resolved.

Before you write

Three things account for most surprises.

"It says a group can reach a project, but those people cannot open it." Holding a permission in the scheme is not the whole story — the user must also have a Jira licence, and a team-managed project may apply its own access rule. The report tells you what the permission scheme grants, which is what an auditor asks for.

"jira-guest-member or atlassian-addons-project-access appears everywhere." Jira adds those roles to schemes itself. They are usually expected, and seeing them listed is not a finding on its own. What matters is whether they hold a permission you did not intend.

"The report is slow on a large site." The app makes one call per project to resolve its permission scheme, because Jira's project search does not return the scheme. A few hundred projects takes a while. If this is hurting you, say so — it is the first thing on the list to improve, and a real customer asking moves it up.

What the app cannot do

Stated here so you do not spend time looking for it: