Support
Access Review for Jira is built and supported by Bobook Limited, Dublin, Ireland.
Contact us
Email: support@bobook.club
You are writing to the people who wrote the app. There is no ticket-deflection bot and no first-line script.
Response times
| Target | |
|---|---|
| First reply | 1 business day |
| A defect that blocks the report | Worked on the day it is reproduced |
| Feature requests | Answered honestly — including "no", with the reason |
Business days are Monday to Friday, 09:00–18:00 Irish time (UTC / UTC+1).
What to include
The more of this you send, the faster the answer:
- Your Jira site URL (for example
yourcompany.atlassian.net) - Which permission you selected
- Roughly how many projects the site has
- A project key whose result looks wrong
- What you expected that project to show, and what it showed instead
If you attach the CSV export, redact any individual names first — grants made to a single person appear in it.
Reporting a security issue
Please email support@bobook.club with "SECURITY" in the subject. Do not open a public report. We will acknowledge within one business day and keep you updated until it is resolved.
Before you write
Three things account for most surprises.
"It says a group can reach a project, but those people cannot open it." Holding a permission in the scheme is not the whole story — the user must also have a Jira licence, and a team-managed project may apply its own access rule. The report tells you what the permission scheme grants, which is what an auditor asks for.
"jira-guest-member or atlassian-addons-project-access appears everywhere."
Jira adds those roles to schemes itself. They are usually expected, and seeing
them listed is not a finding on its own. What matters is whether they hold a
permission you did not intend.
"The report is slow on a large site." The app makes one call per project to resolve its permission scheme, because Jira's project search does not return the scheme. A few hundred projects takes a while. If this is hurting you, say so — it is the first thing on the list to improve, and a real customer asking moves it up.
What the app cannot do
Stated here so you do not spend time looking for it:
- It cannot change a permission. It is read-only by design.
- It does not expand groups into named people; it reports group names.
- It does not cover user provisioning, licence cost or identity-provider sync.
Access Review