Assets roles and permissions

This page explains how access to Assets works, from assigning product-level roles in AdminHub to managing schema and object type access inside the Assets app.

The topic doesn’t cover org admin roles, Jira project permissions, authentication, or account creation.

How access to Assets works

Access to Assets is granted in layers. Each layer builds on the one before it.

Step

Who does this

Where

What it unlocks

1. Site access

Org Admin or Site Admin

AdminHub - Users

User is added to the Atlassian site. Does not grant Assets access on its own.

2. Product access

Org Admin, Site Admin, or User Access Admin

AdminHub - Assets app entry

User is assigned the Assets User or Assets App Admin role. They can now access the Assets app. No Jira or JSM license required.

3. Schema access

Assets App Admin or Schema Manager

Inside the Assets app - schema settings

User is assigned an in-product schema role. They can now view or edit objects in that schema.

4. Object type access

Assets App Admin or Schema Manager

Inside the Assets app - object type settings

Optional. User is assigned an object type role for more granular control within a schema.

AdminHub roles

These roles control access to the Assets app. They are assigned in AdminHub under the Assets app entry.

Role

Description

User

Allows access to the Assets app and the ability to:

  • Interact with Schemas (and data within) that they have been granted permissions for via in-product schema and object type roles (see below).

  • Access and create Dashboards (for Assets data they have permission to access).

App admin

Everything from “User“ plus:

  • Ability to create and delete schemas.

  • Ability to access Assets app settings area (from the top right cog menu).

    • Implicit object schema manager role permissions on every schema (see below)

User access admin

Does not provide access to Assets but allows administering the User role.

A Creator role (allowing schema creation without full App Admin access) is planned for a future release and is not available at launch.

New schema default behaviour: When a new schema is created, all groups that grant product access to Assets are automatically added to the Object Schema Developers role for that schema.

In-product roles

These roles are assigned inside the Assets app. They control what a user can do within a specific schema or object type. They are separate from AdminHub roles and must be assigned in addition to a product role.

Schema-level roles

Area

Permission

Object viewer

Object schema users

Object schema developers

Object schema managers

Schemas

Create schema

 

 

 

 

 

Delete schema

 

 

 

X

 

Edit schema settings

 

 

 

X

 

Import into schema

 

 

 

X

Object types

Create / edit / delete object types

 

 

 

X

 

Create / edit / delete object type attributes

 

 

 

X

Objects

Create / edit objects

 

 

X

X

 

View objects

 

X

X

X

 

Delete objects

 

 

 

X

 

Create / Edit / Delete object comments

 

 

X

X

Dashboards

Create dashboards (Containing data you have permission to view)

 

X

X

X

Confluence macro

View object data displayed in Assets Confluence macro

X

X

X

X

 

Edit object data displayed in Assets Confluence macro

 

 

 

X

Object type-level roles

Object type roles apply to a specific object type within a schema. Use them when you need more granular access control than the schema-level role provides.

Important: Object type roles can override schema-level roles for that specific object type. For example, if a user is an object schema developer but a separate group is assigned as object type developers for a specific object type within that schema, the user's access to that object type is downgraded to object schema user (view only, no create or edit). Their original schema developer permissions apply to all other object types in the schema. To restore their access, add them individually or into the object type developer group for that object type.

Area

Permission

Object type users

Object type developers

Object type managers

Object types

Create / edit / delete object types

 

 

X

 

Create / edit / delete object type attributes

 

 

X

Objects

Create / edit objects

 

X

X

 

Delete objects

 

 

X

 

Create / Edit / Delete object comments

 

X

X

Dashboards

Create dashboards

(Containing data they have permission to view)

X

X

X

Confluence macro

View object data displayed in Assets Confluence macro

X

X

X

 

Edit object data displayed in Assets Confluence macro

 

 

X

Role permissions reference

This table shows what each in-product role can do across the full permission set.

Permission

Object Viewer

User

Developer

Manager

Read object data in Confluence Assets macro

X

X

X

X

View linked issues panel

 

X

X

X

Search for Assets objects and attributes

 

X

X

X

Export objects

 

X

X

X

Create and edit Assets objects

 

X

X

X

Add, edit, and delete comments

 

 

X

X

Delete Assets objects

 

 

X

X

Create and edit attributes

 

 

X

X

Manage references

 

 

X

X

Move object type (drag and drop)

 

 

X

X

Create Assets object types

 

 

 

X

Modify Assets object schema

 

 

 

X

Delete Assets object schema

 

 

 

X

Import Assets object schema

 

 

 

X

Edit object data in Confluence Assets macro

 

 

 

X

Create Assets object schema

 

 

 

X (App admin only)

Create and manage Assets custom fields

 

 

 

X (App admin only)

Assets object custom fields on Jira issues

When an Assets object custom field is added to a Jira issue or request type, standard Jira permissions apply. Any Jira user with edit permissions on an issue can add or remove objects in an Assets object custom field, without needing a separate Assets role.

Portal users, including users without any Atlassian license, can view Assets object fields on a request type if the field has been made available on the portal. These roles do not count towards license totals.

What changed with the Assets platform app

Before the Assets platform app launch, Assets access was managed inside JSM settings. It is now managed in AdminHub alongside other Atlassian products.

Permission

Jira space user

Anyone with create / edit permissions on work items / requests in a space

Jira space admin

Jira App admin

Create / configure Assets object custom field

 

 

X

Add Assets object custom field to work item

 

X

X

Add / remove objects in Assets object custom field

X

X

X

 

Still need help?

The Atlassian Community is here for you.