Permissions
Align OKR has a rich set of permissions controlling both user, workspace and OKRs rights.
Permission Limitations (readme)
User Access
Jira edition - Users assigned to Jira Global Permission “OKR by BOJA Access“ can open the add-on
Web edition - All users invited
monday.com - All users except viewers
User Admin
Admin users differs between the web and Jira edition.
Jira edition - Users assigned to Jira global permission “OKR by BOJA Administrator“
Web edition - All users with the role admin
monday.com - monday.com admins
Permission Manager
Restrict or grant actions such as “delete workspace” to admins or all users.
OKR Workspace Permission Scheme
Create workspace permission schemes and assign too workspaces. Schemes enable full control over who can view and edit workspaces as well as view, edit and delete permissions to individual OKRs. The “all user access“ scheme is the default scheme creating workspaces.
Private workspaces can only be accessed by the creator and persons invited by the creator. Admins can manage private workspaces such as delete however not view the data.
Permission Limitations
BOJA OKR permissions limit user access to app functionality through the BOJA OKR user interface. Permissions are not checked at the database level so users with access to the Jira instance might through “hacking“ and direct API calls gain access.
Please note that access to Jira and monday.com data is protected by those build in permissions.