Schema Software

Groups

User guide · The “Groups” tab

Removing a group in Jira is easy to do and hard to undo — you often can't see everything it touches first. The Groups tab shows the full blast radius of removing a group, then lets you remove it safely, one place at a time. Nothing changes until you explicitly confirm.

The Groups tab showing the blast radius of removing a group — affected projects, filters, dashboards, and users.
Previewing a group shows everywhere it grants access — projects, filters, dashboards, and how many users are affected — before you change anything.

How to use it

  1. Start from the Groups table, which lists every group on the site ranked by how many projects it reaches, or narrow it with Find a group by name. Select Preview removal on the group you want to examine.
  2. Read the Blast radius — the projects, filters, dashboards, and number of users that would lose access, broken down by where the access comes from.
  3. When you're ready to act, select Show removable access and choose which removals to apply (see “Removing access safely” below).

The Groups table

The table answers “which groups should I look at?” before you preview anything. Every group in the site's directory is listed, not just the ones that grant something, with these columns:

  • Members — how many accounts are in the group. Blank for groups the scan did not expand (unused groups); select Count to fetch it live.
  • Projects — how many company-managed projects the group can act in, by a permission-scheme grant or by a project role. Hover for the split and for how many it can browse.
  • Highest permission — the strongest permission the group holds anywhere.
  • Filters / Dashboards — shared content the group can see.
  • FlagsEmpty (no members), Unused (grants nothing anywhere: no scheme, role, share, or product seat) and Over-broad (can browse at least the share of projects set in Settings, 50% by default). A seat marker means membership grants a product licence, so the group is never counted as unused.

The filter buttons show only the flagged groups. Sort any column. Export CSV / JSON downloads the table as evidence for a group clean-up, narrowed to whatever you are looking at.

Reading the blast radius

  • A one-line summary, e.g. “Removing “jira-software-users” would remove the access it grants across 1 filter and 1 dashboard, affecting up to 12 users.
  • A breakdown by surface — permission scheme, project role, notification, filter share, dashboard share — and the affected projects (with links to their permissions in Jira), filters, and dashboards.
  • A short caveat noting what a preview can't see — issue-security levels and global permissions, and, if your site has any, team-managed projects (they do not use permission schemes, so a group's access inside them isn't part of the blast radius) — with links to check them in Jira.

Removing access safely

Select Show removable access to turn the preview into an action. The app sorts the removals into two kinds:

The removable-access step: a checklist of changes the app can apply, plus guided steps for the ones it can't.
You opt in to each change. The app applies what it safely can; for user-owned content it gives you exact steps to do it in Jira.
  • Changes the app can apply — removing the group from a permission scheme or a project role. Tick the ones you want, select Review, confirm, and the app applies them in Jira immediately.
  • Changes you do in Jirafilter and dashboard shares are owned by the person who created them, so an app can't change them. The app gives you a direct link and step-by-step instructions to remove the share yourself.

Every change is the classic preview → confirm → apply → undo loop: a confirmation dialog restates exactly what will change, the results show what was Applied, Already removed, or Failed, and each applied change has an Undo button (also available later in the Audit log).

Why the app shows stale data right after a change

The whole app reads the last scan (that's what keeps it fast). After you apply a change, the change is live in Jira immediately, but the rest of the app won't reflect it until the next scan. The app prompts you with a Run scan now button when this happens.