For Jira Cloud admins in regulated industries

Prove who can access what in Jira — at a point in time.

Jira can tell you who is in a project. It cannot tell you which projects a group can reach, and it cannot show you what permissions looked like on the last day of the quarter. AccessLens does both, and turns the answer into audit evidence.

Coming to the Atlassian Marketplace No egress. Your permission data never leaves Atlassian.

The gap this fills

Reverse permission lookup has been an open Jira Cloud request since 2019 (JRACLOUD-71967, over a thousand votes) and is still unresolved. Meanwhile the native audit log retains 180 days and is an event stream — it cannot reconstruct who held access on a given date, or show that anyone signed off on it.

What it does

Reverse lookup, three ways

Pick a group, a user, or a project. Get the flattened answer — including access inherited through project roles and group membership, expanded for you.

Point-in-time snapshots

Capture the whole site's permission state on a schedule. A snapshot is the evidence: it does not decay, and it does not expire after 180 days.

Quarter-over-quarter diff

Compare two snapshots and get exactly what changed — "the Contractors group gained admin on Payments" — not a wall of raw events to read.

Access reviews with sign-off

Walk the project list, mark each one confirmed or needs-remediation, and export a record carrying the reviewer's account and a UTC timestamp.

Public-access alarms

Any project readable by anonymous users, or granted to every licensed user, is flagged as a risk finding rather than buried in a scheme.

Everything exports to CSV

Lookups, snapshots, diffs and sign-off records. Generated in your browser, UTF-8, opens cleanly in Excel.

The quarterly SOX access review, end to end

1

Snapshot on the last day of the quarter

Scheduled monthly or weekly, so the evidence exists before anyone asks for it.

2

Diff against last quarter

Every access grant and revocation since the last review, listed once each.

3

Reviewers walk the list

Highest-risk projects first. Confirm, or flag for remediation with a note.

4

Export the sign-off record

Reviewer account id, UTC timestamp, and the snapshot it was judged against.

Against what you have today

Question Native Jira AccessLens
Which projects can this group access? Not supported Yes
What could this user reach on 30 September? Not supported Yes
What changed since last quarter? 180-day event stream Diff
Who signed off on the review? Not recorded Recorded
Which projects are publicly readable? Scheme-by-scheme Flagged

Availability

AccessLens is built and deployed on Atlassian Forge. It is going through Atlassian Marketplace review; this page will link to the listing as soon as it is live.

Questions, bug reports and feature requests: open an issue.

Found a security issue? Please report it privately rather than in a public issue.

Documentation · Privacy policy