The Adaptavist Group LogoDocumentation

Permissions

Understand which permissions you need to configure ScriptRunner, and which permissions your scripts run with.

Configuring any ScriptRunner feature requires the Administer Jiraglobal permission. For background on how Jira permissions work, see Atlassian's permissions overview.

Three levels of access are relevant:

  • Jira administrator: Holds the Administer Jira global permission. Can create and manage every kind of ScriptRunner content, and configure workflow rules.
  • Site or organization administrator: Manages your Atlassian organization. Required only to approve the external domains your scripts can call. This is a separate role rather than a higher one: a site or organization administrator must also belong to the jira-administrators group to configure ScriptRunner.
  • Jira users: Everyone else. They see the results of scripts, such as a scripted field on a work item, but cannot configure ScriptRunner.
CAUTION: Space administrators cannot configure ScriptRunner. ScriptRunner's workflow rules are available in company-managed workflows only, and editing a company-managed workflow requires the Administer Jira global permission. The Administer spaces permission is not sufficient, even for selecting an existing script on a transition. Team-managed projects, where space administrators do edit their own workflows, are not currently supported.

Feature permissions

Every feature is configured by a Jira administrator, with one exception: approving external domains requires a site or organization administrator. What differs between features is the permissions a script runs with, which you set per script with Run as.

Configuration and runtime permissions by feature

FeatureRuns as (default)Notes
Script consoleThe current userCan be changed to the app, or to a specific user.
Event listenersThe appRuns whenever its event occurs, whoever or whatever caused it: a user of any type, an automation rule, or the app. Can be changed to run as a specific user.
Scripted fieldsThe current userCan be changed to the app, or to a specific user.
Work item picker fieldsThe current userCan be changed to the app, or to a specific user.
Workflow actions (scripted)The appCompany-managed workflows only. Can be changed to run as a specific user.
Workflow restrictions (Jira expression)Not applicableCompany-managed workflows only. Jira expressions are evaluated by Jira, not run as a user.
Workflow validators (scripted)The appCompany-managed workflows only. Can be changed to run as a specific user.
Workflow validators (Jira expression)Not applicableCompany-managed workflows only. Jira expressions are evaluated by Jira, not run as a user.
Scheduled jobsThe appCan be changed to run as a specific user.
Field behavioursThe current userCannot be changed. Runs for anyone who opens a screen it applies to, including unlicensed, anonymous, and Jira Service Management customer (portal) users.
HTTP endpointsThe current userCan be changed to the app, or to a specific user.
Automation integrationsThe current userCan be changed to the app, or to a specific user.
Allowed domainsNot applicableApproving a domain requires a site or organization administrator. A Jira administrator can add a domain to a script, but cannot approve it.

What a script can do

Who configures a script and what that script can do are separate questions. A script does not inherit the permissions of the administrator who wrote it. It uses the permissions of whoever it runs as:

  • The current user: the script can only see and change what that user could. A user who cannot browse a space gets no results from it.
  • The app: the script uses ScriptRunner's own permissions, which are not limited by space permission schemes. Use this when a script must work regardless of who triggered it.
  • A specific user: the script always uses that user's permissions, whoever triggered it.
CAUTION: Running as the app bypasses space permissions. Anyone who can trigger the script, including through a work item transition or an HTTP endpoint, causes it to act with those permissions. Prefer running as the current user unless you specifically need to bypass permissions.

Approving external domains

Scripts cannot call an external domain until it has been approved, and only a site or organization administrator can approve one. A Jira administrator can add a domain to a script, but cannot approve it.

Search documentation

Start typing to search the docs.