More free tools
Free tool
Is your Jira project leaking?
A guided self-audit of the settings that most commonly expose a Jira Cloud project to the wrong people. Answer each question about your own project, get a plain- language verdict and what to change. This doesn’t connect to Jira — it just asks you the questions and nothing you enter is stored or sent anywhere.
Questions
- How do I check who can see a Jira project?
- Open Project settings → People and Project settings → Permissions, and look at who holds the Browse Projects permission. That single permission is what decides visibility: anyone granted it, directly or through a group or project role, can see the project's issues. Groups are where surprises hide — a group like jira-software-users can include every licensed person on your site, so granting Browse Projects to it makes the project visible site-wide.
- Does this tool connect to my Jira site?
- No. It never touches Jira and asks for no credentials. It's a structured set of questions you answer by looking at your own project settings, and your answers stay in your browser — nothing is stored on a server or sent anywhere.
- What is the most common Jira permission mistake?
- Granting Browse Projects to a broad group rather than to a project role. It's the fastest way to set a project up and the easiest to forget about, and it quietly means every licensed user on the site can read the project — including work for one client being visible to people staffed on another.
- Can external clients see my Jira issues?
- Only if they have a licensed account with Browse Projects, or the project has anonymous access enabled. Jira Cloud has no free guest or viewer role, so there's no state where an unlicensed client is quietly reading your project — but anonymous access genuinely is public to anyone with the URL, which is the one setting worth checking first.
- How often should I audit Jira project permissions?
- Any time the shape of the team changes — a client offboards, a contractor's engagement ends, a project is cloned from a template — and on a fixed cadence otherwise, quarterly being a reasonable default. Permission drift comes from accumulated small grants, not one big mistake, so the periodic re-read matters more than the thoroughness of any single audit.
Further reading
External and anonymous access ties directly into a couple of the questions above: Jira guest access in 2026: what’s actually possible.