Skip to content

Permissions and Access Requirements

Out of Office Assistant works inside Jira Cloud's own permission model and adds two app-level roles on top of it. This page explains who can do what, where each role is granted, and what each integration needs.

How the permission model works

Everyone can manage their own Out of Office rules without being granted anything. Broader rights are granted inside the app, under App Settings > Permissions.

Out of Office Admin is granted in the app alone. A Space Admin needs two grants, and neither works on its own: the app selection under App Settings > Permissions, and Jira space administration rights for that space under Space settings > Access. Being the Space Owner does not grant them.

The Permissions screen states the model directly and is where both roles are assigned.

settings-permissions.webp
App Settings > Permissions, where Space Admins and Out of Office Admins are granted

Roles at a glance

Role

Granted where

Can do

Everyone

No grant needed

Create and manage their own rules and templates, and connect their own integrations

Space Admin

App Settings > Permissions > Space Admins

Manage rules, templates and integration settings for members of their spaces

Out of Office Admin

App Settings > Permissions > Out of Office Admins

Manage rules, templates and integration settings for all users

Jira Admin

Automatic

Full access to everything, without being added to either list

Everyone

Any licensed Jira user can, for their own account:

  • Create, edit, pause and delete their own Out of Office rules

  • Create and manage their own templates

  • Connect their own integrations from My Integrations

  • See their team's availability on the Team Availability tab

They cannot create or edit rules for anyone else, and they cannot open App Settings.

Space Admin

A Space Admin manages Out of Office rules for members of specific spaces. This suits team leads who cover for their own team but should not administer the whole app.

To grant it, open App Settings > Permissions, then under Space Admins select the spaces. The screen states the effect: Space Admins of the selected spaces can create and manage Out of Office rules for members within those spaces.

The grant is per space. A Space Admin of a space that is not selected here gets no additional Out of Office rights.

Out of Office Admin

An Out of Office Admin can manage rules, templates and integration settings for every user, and can create ADMIN-scope REST API tokens. It suits an HR team or team leads who maintain absences for others, or an HR system that syncs absences through the REST API, without giving them Jira administrator rights. Setting up the app itself — App Settings, including permissions and global integrations — stays with Jira admins.

Grant it under App Settings > Permissions > Out of Office Admins. There are two pickers:

  • Users - grant to named people

  • Groups - grant to a Jira group, so membership changes flow through automatically

Jira Admin

Jira administrators always have full permissions automatically. They do not need to be added to the Space Admins or Out of Office Admins lists, and adding them changes nothing.

Jira admins are also the people who install the app and who control REST API access under App Settings > Rest API Permissions.

Service desk agents

Agents in Jira Service Management get the same self-service rights as everyone else, plus approval delegation: they can nominate approver coverers so approvals keep moving while they are away.

Two related settings live under App Settings > General Settings > Service Management:

  • Display agent out of office status in the Customer Portal: choose the spaces whose customer portal shows the assigned agent's out of office status. The same list decides where Share this message with service desk customers. is offered on the rule form.

  • Allow customers to have out of office rules: lets portal customers have out of office rules of their own. Once it is ticked, Jira admins and Out of Office Admins get a Customer Rules tab next to Team Availability, where they manage those rules. The option is greyed out when the site has no Jira Service Management spaces. See Creating Out of Office Rules for JSM Customers.

REST API access

Only Jira admins can change who may create REST API tokens. They do this under App Settings > Rest API Permissions, setting Who can create REST API Tokens to either:

Option

Details

All users (the default)

All users can create REST API tokens.

Only specific users

Pick named users, groups, or both.

Jira admins and Out of Office Admins can always create tokens, whatever this setting says. Only they can create tokens with ADMIN scope; everyone else gets PERSONAL tokens, which act on their own rules only.

Scope and existing tokens

The setting controls only who can create new tokens. Tokens people already hold keep working when you switch to Only specific users, so revoke any that should stop.

Where people create and where admins manage

Who

Where / What they see

Individual users

People create their own tokens under My Integrations > REST API.

Jira admins

On the Rest API Permissions screen, Jira admins see every token on the site under Created tokens, with its user, description, scope, creation date, last access and expiry, and can delete any of them.

Tokens from Connect app

Tokens imported from the Connect app are listed separately under Legacy tokens. These can be revoked but not regenerated.

What each integration requires

Personal integrations are connected by each user from the My Integrations tab.

A Jira admin decides which of them are offered at all under App Settings > Personal Integrations, where Outlook, Google Workspace and Slack can each be switched off.

Turning one off removes its card for everyone who hasn't set it up yet; people who already connected it keep it, and it keeps working.

Global integrations are configured once by a Jira admin under App Settings > Global Integrations.

Integration

Scope

Requirements

Office 365 (Outlook)

Personal

A Microsoft 365 account with an Exchange mailbox. You are asked to pick the Microsoft account to authorize. An account without a mailbox can still be connected, but the card then shows Integration paused and no rules are created; use Connect to authorize a different account.

Google Calendar

Personal

A Google Workspace account. Personal Gmail accounts are not supported

Slack

Personal

Access to the Slack workspace. Installing the app into the workspace needs a Slack workspace administrator

Tempo

Global

A Tempo administrator generates the API token; a Jiar admin adds it under Global Integrations

Microsoft 365

Global

Added with + Add Microsoft 365 under Global Integrations by a Jira admin