Admin roles
Who administers what, whether they still sign in, and which of them a second factor is not protecting.
What this tab is for. The accounts that can do the most damage, on one page: organisation admins, site admins, Jira system administrators, product admins and user-access admins — each with their last activity, their two-step verification, and whether the account is even one you manage.
Where the roles come from — read this once. Atlassian publishes no API for roles: every candidate endpoint answers 404, and the role field the directory does have comes back empty. So the page reads roles from two honest sources and says which it used. Group names — org-admins, site-admins, system-administrators, and the product patterns — cover roles granted through groups. The Org role column of the users-and-groups export names organisation admins outright, including the ones no admin-named group would ever reveal; on one real customer, all nineteen organisation admins were visible only that way. A role granted directly to a person, outside both, cannot be seen by anyone — which is why the page says at least this many.
Two views of the same people
- By person
- A table: who, which roles (with the group each role was read from, or “named by the export”), last active, two-step verification, and whether the account is yours to manage.
- By level
- The same people as a ladder — most powerful role at the top, the people who hold it on each rung, with the role's reach explained in a sentence. Someone holding two roles appears on both rungs, deliberately: the lower rung is the access that survives revoking the top one.
What to look for
- Dormant admins — an account that can grant itself anything and has not signed in for months is the risk column's first row. The Only those worth a look toggle narrows to these.
- No second factor and no single sign-on — counted separately from accounts merely lacking 2FA: someone behind an enforced identity provider is protected, and calling them exposed would describe your SSO configuration as a breach. This split needs the CSV import, because no API reports SSO.
- Admins you do not manage — a role held by an account on a domain you never verified is a role you cannot revoke from here.
- App accounts are listed apart from people, not counted as administrators alongside them.
org-admins and site-admins to Protected Groups in Settings, so no rule can ever act on them.