Align OKR has a rich set of permissions controlling both user, workspace and OKRs rights.
Permission Limitations (readme)
User Access
Jira edition - Users assigned to Jira Global Permission “OKR by BOJA Access“ can open the add-on
Web edition - All users invited
monday.com - All users except viewers
User Admin
Admin users differs between the web and Jira edition.
Jira edition - Users assigned to Jira global permission “OKR by BOJA Administrator“
Web edition - All users with the role admin
monday.com - monday.com admins
Permission Manager
Restrict or grant actions such as “delete workspace” to admins or all users.
OKR Workspace Permission Scheme
Create workspace permission schemes and assign too workspaces. Schemes enables full control over who can view and edit workspaces as well as view, edit and delete permissions to individual OKRs.
All workspaces has a scheme assigned with the “all user access“ scheme as default.
Permission Limitations
BOJA OKR permissions limit user access to app functionality through the BOJA OKR user interface. Permissions are not checked at the database level so users with access to the Jira instance might through “hacking“ and direct API calls gain access.
Please note that access to Jira and monday.com data is protected by those build in permissions.