Offboard a leaving employee, or shut down a vendor group

Start from the person or the group instead of the project, and see every project role they hold across the site — with access reached through a group marked separately from direct grants.

Offboard Users and Vendor Groups

Getting started

Both views in this guide live under Project Access → Roles & Permissions, visible to Jira administrators only. By User answers "everywhere this person can go"; By Group answers the same question for a group such as vendors-external.

Before you start

  • You have the person's display name or account, or the exact group name.
  • You can edit group membership and project roles in Jira — the app reports, you remediate in Jira.
  • If the Snapshot banner shows a stale Last site sync time, run Update site inventory first so the footprint is complete.

Why this is hard in native Jira

HR says a contractor's last day is Friday. Security asks which projects an external vendor group can reach. Native Jira has no person-centric or group-centric view at all: the People tab only exists inside a project, so "everywhere this person or group can go" means opening every project one at a time and trusting that nothing was missed.

The shape of the problem is inherent to how Jira exposes permissions. A permission granted to a group applies immediately to every project that shares the scheme, while a permission granted through a project role is assigned per project — so one person's real footprint genuinely spans many separate screens today.

What Access Reviewer360 shows

By User lists every role × project row for one person, with a Via Group column: a group name means the access is inherited, a dash means it was granted directly. That distinction is what tells you where to revoke.

Access Reviewer360 Roles and Permissions by User

By Group does the same for a group — every project role the group reaches, so you can retire a vendor or contractor group with confidence instead of guessing at its blast radius.

Access Reviewer360 Roles and Permissions by Group

Setup, step by step

  • Open Project Access → Roles & Permissions. Click Update site inventory if the Snapshot banner shows a stale Last site sync time.
  • Switch to By User and search for the person.
  • Review every role × project row. A dash in Via Group means direct access; a group name means inherited access.
  • Or switch to By Group, search for the group (e.g. vendors-external), and review every project role it holds.
  • Export CSV — this is your "before" record for the offboarding ticket.
  • Remediate in Jira: fix group membership first, then clean up any leftover direct grants.
  • Run Update site inventory, re-check, and export again as the "after" record.

Tips

  • Fix the group first. Removing one membership usually clears a dozen rows at once, and it prevents the access returning with the next re-add.
  • Direct grants are the ones that outlive people. Treat any dash in Via Group as a finding worth a note in the ticket.
  • Run By Group on every external or vendor group once a quarter, whether or not anyone is leaving.

Contact

If you need help or want to ask questions, please contact us through miniOrange Support or via email to atlassiansupport@xecurify.com

miniOrange Atlassian Contact Us

Book a Free Consultation with
Our Experts Today!

Schedule a call now!


Contact Us