Browse documentation
Docs/License Waste Manager/Browsing and acting on users

Browsing and acting on users

The filters, the CSV export, and the six bulk actions ranked by risk.

What this tab is for. Looking at the actual people behind the numbers, and acting on them. If it says there is no data, go and run a scan on the Dashboard first.

Jira → Apps → License Waste Manager → UsersIllustration

Users

DashboardUsersAdmin RolesAPI TokensAutomationAudit LogSettings
Product
Jira Software
Status
Enabled accounts
Inactive For
90 days
Licence
Holds a licence
Domain
All Domains
Search
Search by name or email...
ResetExport CSV87 users match · 4 selected
UserEmailProductsLast activeGroups
RMRenata Marques
renata.marques@example.com
JiraConfluence
214 daysjira-software-users
TSTomas Silva
tomas.silva@contractor.example
Jira
Never activejira-software-users
AKAnna Kowalski
anna.kowalski@example.com
JiraJSM
96 daysjsm-agents, jira-software-users
Bulk actions — 4 users selected
Add to GroupGrant Product Access…Remove from Group…Revoke Product Access…Restore UsersSuspend UsersClear

The filters

FilterWhat it answers
Product“Who has Confluence but never opens it?” Pick several and choose Holds any of these or Holds all of these.
Status: All, Enabled accounts, Disabled accounts, Never signed inWhether the account is switched on — which decides whether it costs anything. Disabled accounts keep their product columns in an export but occupy no seat. Where the source distinguishes, rows say the specific word: Suspended can be restored, Deactivated is on its way out. Never signed in is your highest-confidence group: a licence assigned and never used at all.
Inactive ForA slider from 0 to 365 days, defaulting to the threshold you set in Settings — how long since the person actually used anything, a separate fact from the account being enabled. The STATUS column says the account's state; the LAST ACTIVE column says this.
LicenceAny, Holds a paid seat, or Holds no paid seat. A seat is only a seat while the account is on: product access AND an enabled account, which is the dashboard's own definition of Licensed People — so the filter and the figure always agree.
Account: Billed for Guard, Managed, UnmanagedBilled for Guard is what Atlassian actually charges Guard on — the population every Guard figure on the dashboard counts. Managed means you verified their email domain and can administer the account; it is a much larger set. Unmanaged accounts you cannot administer, and Guard is not billed for them.
Access reachesAny site, also other sites, only this site — or one named site: the sites your people reach outside this one are listed by name with a count each, straight from the same figures the dashboard charts. Clicking a site chip on the dashboard lands here with the site pre-selected.
2FAWith or without two-step verification — as reported for managed accounts. Needs a CSV import or the data stays unknown rather than pretending.
DomainContractors, an acquired company, a partner. Each domain carries its own count.
Department / Job titleIdentity-provider attributes, when your directory sets them. Frequently blank — the filters appear only when the snapshot actually carries values.
SearchOne person by name or email.

Arriving from the Dashboard — a Guard figure, a site chip — lands here with the matching filter already applied, and the filter controls show it, so the number you clicked and the list you got always agree.

What each row tells you

User
Avatar, name and email. The name links to that account's page in admin.atlassian.com, so acting on one person is a click, not a search in another tab. Two flags appear where they apply: External account — a domain you never verified, so Guard is not billed and you cannot administer it — and Also on N other site(s), for access that reaches beyond this instance.
Status
Whether the account is switched on — the fact that decides whether it costs anything. Disabled accounts show their specific state where the source said it: Suspended can be restored, Deactivated is on its way out.
Products
One badge per seat the person holds. What the badges show is what the seat filters count.
Last Active
Today, yesterday, 53d ago — in the page's language. The colour bands come from your threshold, not a fixed 90: past a third of it is amber, past all of it is red, and Never carries the invitation date when there is one.
Domain
The email domain, or Email not visible where Atlassian withholds the address.
Groups
Group membership opens the person's groups in place — the licence groups marked apart — so you can see exactly which membership grants the seat you are about to reclaim.

Sort by name, email, last activity or domain from the column headers. Ticking people raises the bulk bar with the count and the actions; the selection belongs to the page you are on — changing page or filter clears it, so an action never carries invisible passengers from three pages back.

Reset clears them all. Export CSV hands the current list to a spreadsheet — the file uses exactly the filters on screen, which is still how most licence reviews actually happen.

The six bulk actions, least risky first

ActionWhat it doesReversible?Use when
Add to GroupAdds the selected people to a group. Most often used to grant access back, or to tag a set of people you have just acted on.Yes — remove them from the group.Marking a set of users for follow-up.
Grant Product AccessAdds the selected people to the groups that grant the products you pick. The dialog says plainly that each product they gain becomes a seat you are billed for.Yes — revoke it again.Putting access back after a reclaim went too far, or onboarding a set of people at once.
Remove from Group…Removes the selected people from the group you pick. Groups managed by your identity provider are skipped, because it would put everyone back on its next sync. A person who was not in the group is recorded as skipped, not as a success.Yes — add them back to the same group.You want to free the seats a specific group grants, and you know which group grants them.
Revoke Product Access…You tick which licences to revoke; the app works out which groups grant them and removes the person from those, so you do not have to know the mapping. The account stays active and keeps its Atlassian identity, so access can be granted again later. Tick nothing and it tells you nothing would be revoked rather than running empty.Yes — grant the products back. The audit log lists who was affected.You want the seats back but the person may return, or you do not know which groups to name.
Suspend UsersSuspends the accounts at organisation level. Requires the organisation API connection and a directory ID, which is detected during a successful scan.Yes — with Restore Users, below.Genuine leavers, after HR has confirmed.
Restore UsersLifts a suspension and hands the account back its access.Yes — suspend again.A suspension that turned out to be wrong, or somebody returning from a long absence.
Removing a licence is not the same as removing a person
Removing product access keeps the account, its history and its issue assignments. The person simply cannot use that product. Suspension blocks the account entirely. Always prefer the narrowest action that recovers the seat, which is usually removing one licence group.
All three protection lists are enforced
Accounts in Protected Users, members of Protected Groups, and anyone whose email is on a Protected Domain are skipped by every bulk action and every rule run, with no override. Each skip is recorded in the audit log with its reason, so you can see who was spared and why. One limit worth knowing: protection by domain can only match people whose email address the API returns, and Atlassian redacts that for many accounts — so protect those individually or by group.

Bulk actions run in the background and land in the audit log with a result for each person. Only one operation runs at a time.

Something missing or wrong on this page? Tell us in the support portal or email contact@synapseoasis.com.