Browsing and acting on users
The filters, the CSV export, and the six bulk actions ranked by risk.
What this tab is for. Looking at the actual people behind the numbers, and acting on them. If it says there is no data, go and run a scan on the Dashboard first.
Users
| User | Products | Last active | Groups | ||
|---|---|---|---|---|---|
RMRenata Marques | renata.marques@example.com | JiraConfluence | 214 days | jira-software-users | |
TSTomas Silva | tomas.silva@contractor.example | Jira | Never active | jira-software-users | |
AKAnna Kowalski | anna.kowalski@example.com | JiraJSM | 96 days | jsm-agents, jira-software-users |
The filters
| Filter | What it answers |
|---|---|
| Product | “Who has Confluence but never opens it?” Pick several and choose Holds any of these or Holds all of these. |
| Status: All, Enabled accounts, Disabled accounts, Never signed in | Whether the account is switched on — which decides whether it costs anything. Disabled accounts keep their product columns in an export but occupy no seat. Where the source distinguishes, rows say the specific word: Suspended can be restored, Deactivated is on its way out. Never signed in is your highest-confidence group: a licence assigned and never used at all. |
| Inactive For | A slider from 0 to 365 days, defaulting to the threshold you set in Settings — how long since the person actually used anything, a separate fact from the account being enabled. The STATUS column says the account's state; the LAST ACTIVE column says this. |
| Licence | Any, Holds a paid seat, or Holds no paid seat. A seat is only a seat while the account is on: product access AND an enabled account, which is the dashboard's own definition of Licensed People — so the filter and the figure always agree. |
| Account: Billed for Guard, Managed, Unmanaged | Billed for Guard is what Atlassian actually charges Guard on — the population every Guard figure on the dashboard counts. Managed means you verified their email domain and can administer the account; it is a much larger set. Unmanaged accounts you cannot administer, and Guard is not billed for them. |
| Access reaches | Any site, also other sites, only this site — or one named site: the sites your people reach outside this one are listed by name with a count each, straight from the same figures the dashboard charts. Clicking a site chip on the dashboard lands here with the site pre-selected. |
| 2FA | With or without two-step verification — as reported for managed accounts. Needs a CSV import or the data stays unknown rather than pretending. |
| Domain | Contractors, an acquired company, a partner. Each domain carries its own count. |
| Department / Job title | Identity-provider attributes, when your directory sets them. Frequently blank — the filters appear only when the snapshot actually carries values. |
| Search | One person by name or email. |
Arriving from the Dashboard — a Guard figure, a site chip — lands here with the matching filter already applied, and the filter controls show it, so the number you clicked and the list you got always agree.
What each row tells you
- User
- Avatar, name and email. The name links to that account's page in admin.atlassian.com, so acting on one person is a click, not a search in another tab. Two flags appear where they apply: External account — a domain you never verified, so Guard is not billed and you cannot administer it — and Also on N other site(s), for access that reaches beyond this instance.
- Status
- Whether the account is switched on — the fact that decides whether it costs anything. Disabled accounts show their specific state where the source said it: Suspended can be restored, Deactivated is on its way out.
- Products
- One badge per seat the person holds. What the badges show is what the seat filters count.
- Last Active
- Today, yesterday, 53d ago — in the page's language. The colour bands come from your threshold, not a fixed 90: past a third of it is amber, past all of it is red, and Never carries the invitation date when there is one.
- Domain
- The email domain, or Email not visible where Atlassian withholds the address.
- Groups
- Group membership opens the person's groups in place — the licence groups marked apart — so you can see exactly which membership grants the seat you are about to reclaim.
Sort by name, email, last activity or domain from the column headers. Ticking people raises the bulk bar with the count and the actions; the selection belongs to the page you are on — changing page or filter clears it, so an action never carries invisible passengers from three pages back.
Reset clears them all. Export CSV hands the current list to a spreadsheet — the file uses exactly the filters on screen, which is still how most licence reviews actually happen.
The six bulk actions, least risky first
| Action | What it does | Reversible? | Use when |
|---|---|---|---|
| Add to Group | Adds the selected people to a group. Most often used to grant access back, or to tag a set of people you have just acted on. | Yes — remove them from the group. | Marking a set of users for follow-up. |
| Grant Product Access | Adds the selected people to the groups that grant the products you pick. The dialog says plainly that each product they gain becomes a seat you are billed for. | Yes — revoke it again. | Putting access back after a reclaim went too far, or onboarding a set of people at once. |
| Remove from Group… | Removes the selected people from the group you pick. Groups managed by your identity provider are skipped, because it would put everyone back on its next sync. A person who was not in the group is recorded as skipped, not as a success. | Yes — add them back to the same group. | You want to free the seats a specific group grants, and you know which group grants them. |
| Revoke Product Access… | You tick which licences to revoke; the app works out which groups grant them and removes the person from those, so you do not have to know the mapping. The account stays active and keeps its Atlassian identity, so access can be granted again later. Tick nothing and it tells you nothing would be revoked rather than running empty. | Yes — grant the products back. The audit log lists who was affected. | You want the seats back but the person may return, or you do not know which groups to name. |
| Suspend Users | Suspends the accounts at organisation level. Requires the organisation API connection and a directory ID, which is detected during a successful scan. | Yes — with Restore Users, below. | Genuine leavers, after HR has confirmed. |
| Restore Users | Lifts a suspension and hands the account back its access. | Yes — suspend again. | A suspension that turned out to be wrong, or somebody returning from a long absence. |
Bulk actions run in the background and land in the audit log with a result for each person. Only one operation runs at a time.