Skip to content

Permissions and Access Requirements

Out of Office Assistant works inside Jira Cloud's own permission model and adds three app-level roles on top of it. This page explains who can do what, where each role is granted, and what each integration needs.

How the permission model works

Everyone can manage their own Out of Office rules without being granted anything. Broader rights are granted inside the app, under App Settings > Permissions.

Out of Office Admin is granted in the app alone. A Space Admin needs two grants, and neither works on its own: the app selection under App Settings > Permissions, and Jira space administration rights for that space under Space settings > Access. Being the Space Owner does not grant them.

The Permissions screen states the model directly and is where both roles are assigned.

settings-permissions.webp
App Settings > Permissions, where Space Admins and Out of Office Admins are granted

Roles at a glance

Role

Granted where

Can do

Everyone

No grant needed

Create and manage their own rules and templates, and connect their own integrations

Space Admin

App Settings > Permissions > Space Admins

Manage Out of Office rules for members of the selected spaces

Out of Office Admin

App Settings > Permissions > Out of Office Admins

Manage rules and templates for all users, plus app settings and global integrations

Jira Admin

Automatic

Full access to everything, without being added to either list

Everyone

Any licensed Jira user can, for their own account:

  • Create, edit, disable and delete their own Out of Office rules

  • Create and manage their own templates

  • Connect their own integrations from My Integrations

  • See their team's availability on the Team Availability tab

They cannot create or edit rules for anyone else, and they cannot open App Settings.

Space Admin

A Space Admin manages Out of Office rules for members of specific spaces. This suits team leads who cover for their own team but should not administer the whole app.

To grant it, open App Settings > Permissions, then under Space Admins select the spaces. The screen states the effect: Space Admins of the selected spaces can create and manage Out of Office rules for members within those spaces.

The grant is per space. A Space Admin of a space that is not selected here gets no additional Out of Office rights.

Out of Office Admin

An Out of Office Admin can manage Out of Office rules and templates across all users, as well as app settings and global integrations. It is the right role for an HR team or an app owner who should run the app without becoming a Jira administrator.

Grant it under App Settings > Permissions > Out of Office Admins. There are two pickers:

  • Users - grant to named people

  • Groups - grant to a Jira group, so membership changes flow through automatically

Jira Admin

Jira administrators always have full permissions automatically. They do not need to be added to the Space Admins or Out of Office Admins lists, and adding them changes nothing.

Jira admins are also the people who install the app and who control REST API access under App Settings > Rest API Permissions.

Service desk agents

Agents in Jira Service Management get the same self-service rights as everyone else, plus approval delegation: they can nominate approver coverers so approvals keep moving while they are away.

Two related settings live under App Settings > General Settings > Service Management: which spaces display agent Out of Office status in the customer portal, and whether customers may have Out of Office rules of their own.

REST API access

REST API access is controlled under App Settings > Rest API Permissions, which only Jira admins and Out of Office Admins can reach. Access is either All users or Only specific users.

Tokens are created with Create New Token and listed with their user, description, scope, creation date, last access and expiry.

What each integration requires

Personal integrations are connected by each user from My Integrations. Global integrations are configured once under App Settings > Global Integrations.

Integration

Scope

Requirements

Office 365 (Outlook)

Personal

A Microsoft 365 account with a mailbox. Authorization fails without one. You are asked to pick the Microsoft account to authorize

Google Calendar

Personal

A Google Workspace account. Personal Gmail accounts are not supported

Slack

Personal

Access to the Slack workspace. Installing the app into the workspace needs a Slack workspace administrator

Tempo

Global

A Tempo administrator generates the API token; an app admin adds it under Global Integrations

Microsoft 365

Global

Added with + Add Microsoft 365 under Global Integrations by an app admin