Global vs Project Specific Permissions

Preston Mitchell
Preston Mitchell
  • Updated
  • Jama Connect® All Versions
    • Cloud/CVC
    • Self-hosted

Summary

Permissions assigned at the organization level are inherited by projects, components, sets, and folders unless they are explicitly overridden. While Jama Connect® supports permission overrides at lower levels, Jama Software recommends keeping your permission model as simple as possible to reduce administrative overhead and improve long-term maintainability.

Resolution

Use organization-level permissions whenever possible

Organization-level permissions should serve as the foundation of your permission model. Allow projects to inherit these permissions by default and create project-level overrides only when there is a clear business requirement.

Keeping permissions centralized helps reduce administrative effort and makes it easier to understand and troubleshoot user access. Over time, highly granular permission structures can become difficult to maintain.

Manage permissions with User Groups

Rather than assigning permissions directly to individual users, use User Groups to simplify administration and ensure consistency.

When creating User Groups:

  • Establish a consistent naming convention that identifies the group's purpose or functional area.
  • Consider using a prefix (such as PER) for groups created specifically to manage permissions.
  • Assign permissions to groups rather than individual users whenever possible.

Maintain a consistent permission strategy

Whether your organization primarily uses inherited permissions or requires some project-level overrides, establish a consistent approach across your Jama Connect instance. A standardized permission model is easier to administer, document, and troubleshoot as your organization grows.

Provide appropriate access for external stakeholders

When granting access to external stakeholders, follow the principle of least privilege by providing only the permissions required for their role. For example, users participating in Review Center reviews or collaborating through @mentions may not require broader project permissions. Limiting access helps protect project data while still enabling effective collaboration.

Additional Resources

Feedback:
We welcome your input! Please sign in to leave any comments, suggestions, or ideas for improvement below.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.