Convince My Boss
Delegate individual admin pages to user groups so you can share the workload without handing out Jira administrator rights.
Copy whichever of these fits your situation, fill in the brackets, and send it. The two variables are how formal your organisation is, and whether the problem you have today is too many Jira administrators or too few.
Informal Email - Currently have multiple Jira admins
Subject: A way to cut down how many full Jira admins we need
Hi [Boss’s Name],
I hope you’re doing well!
I wanted to flag a tool that would help with how we’re running Jira administration at the moment. It’s called Secure Admin, a Forge app for Jira Cloud from Redmoon Software.
The issue we have is that Jira Cloud is close to all-or-nothing: to let someone add a user to a group, or create a version, we have to make them a Jira admin, which also gives them permission schemes, workflows and everything else. That’s why we have [number] admins right now, and most of them only need one small part of it.
Here’s why I think Secure Admin is worth a look:
- Delegate one page at a time. It provides its own versions of sixteen admin pages, and we choose which user groups can use each one. The service desk could get Users and Groups, and nothing else.
- Fewer full admins. Most of our current admins could hand the role back and keep only the page they actually use. That’s a real reduction in risk.
- People can’t grant themselves more. Anyone we let manage groups can be blocked from adding members to our admin groups, so they can’t quietly promote themselves.
- Nothing leaves our site. It’s built on Forge and the configuration is stored inside our own Jira site.
It’s a straightforward setup — one configuration screen where we pick groups per page — and we can start with a single page and expand from there.
What do you think? I’d suggest we try it on the group membership requests first, since that’s where most of the interruptions come from.
Best,
[Your Name]
Formal Email - Currently have multiple Jira admins
Subject: Recommendation: Secure Admin for Jira Cloud to reduce administrator count
Dear [Boss’s Name],
I hope this message finds you well.
I am writing to recommend a tool that would materially reduce the number of full Jira administrators we maintain. The tool is Secure Admin, a Forge app for Jira Cloud developed by Redmoon Software.
The problem. Jira Cloud’s administration rights are close to binary. To allow a colleague to perform a single routine task — adding a user to a group, creating a version, adding a value to a custom field — we must grant them the Jira administrator role, which simultaneously grants permission schemes, work item security, notification schemes and every other site setting. We currently hold [number] Jira administrators, the majority of whom require only a narrow slice of that authority.
The proposal. Secure Admin supplies its own versions of sixteen administration pages, twelve site-wide and four acting on a single Space. A Jira administrator determines, page by page, which user groups may use each one. Members of those groups perform that work without holding the administrator role and without access to Jira’s native administration screens.
The specific benefits I would expect:
- A reduced administrative surface. Colleagues who today hold the full role because of one task would hold only that task’s page. Every other setting becomes unreachable for them.
- Demonstrable segregation of duties. We can grant user and group management to one team and permission schemes to another, with no overlap. That is materially easier to evidence at audit than our present position.
- Protection against privilege escalation. Groups named on the exclusion list cannot have members added from within the app, so a delegated user cannot widen their own access.
- Incremental and reversible adoption. Access is evaluated live against group membership, so a grant takes effect immediately and can be withdrawn just as quickly. We can pilot a single page.
- Data residency. The app is built on Atlassian’s Forge platform and stores its configuration within our own Jira Cloud site. No data is transmitted to the vendor or to any third party.
I would propose a trial covering user and group management first, as that accounts for the majority of the requests currently reaching the administration team, and reviewing after [period] before extending it.
I am happy to prepare a fuller assessment if that would be useful.
Best regards,
[Your Name]
Informal Email - Currently have just one Jira admin
Subject: I’m the bottleneck for Jira admin — here’s a fix
Hi [Boss’s Name],
I hope you’re doing well!
As you know, every Jira administration request currently comes to me — group memberships, new versions, a tweak to a custom field. Most take two minutes, but they arrive constantly, and when I’m away or on leave nothing moves at all.
I’ve been looking at Secure Admin, a Forge app for Jira Cloud from Redmoon Software, and I think it solves this properly.
- I can hand out individual pages. It provides its own versions of sixteen admin pages and I choose which user groups get each one. The service desk could handle group membership themselves without becoming Jira admins.
- It removes the single point of failure. If I’m on leave, the work someone else needs to do is already delegated rather than blocked.
- I keep control of the risky parts. Permission schemes and work item security can stay with nobody but me. Delegating one page doesn’t leak the rest.
- It’s safe to try. Nothing is granted by default, and any grant can be removed and saved in seconds.
I’d like to start by delegating group membership to [team], which is where most of the interruptions come from, and see how it goes over a few weeks.
Happy to walk you through it if that’s easier.
Best,
[Your Name]
Formal Email - Currently have just one Jira admin
Subject: Recommendation: Secure Admin for Jira Cloud to address administration single point of failure
Dear [Boss’s Name],
I hope this message finds you well.
I am writing to raise a continuity risk in our Jira administration, and to recommend a tool that addresses it. The tool is Secure Admin, a Forge app for Jira Cloud developed by Redmoon Software.
The problem. I am presently the sole Jira administrator. Every routine administrative request is therefore routed to me, and during any absence that work stops entirely. The conventional remedy — appointing a second administrator — is unattractive, because Jira Cloud’s administrator role is close to all-or-nothing: it would grant permission schemes, work item security and every other site setting in order to solve a problem that concerns group memberships and versions.
The proposal. Secure Admin provides its own versions of sixteen administration pages, twelve site-wide and four acting on a single Space, and allows me to determine page by page which user groups may use each. Colleagues can therefore be given precisely the administrative capability their role requires, and no more.
The specific benefits I would expect:
- Continuity. Routine work continues during absence because it is already delegated, rather than queued against one person.
- Proportionate access. A colleague granted the Users page receives that page alone. The settings that carry genuine risk remain restricted.
- Retained control of sensitive configuration. Pages with no groups assigned are usable by nobody, which is the app’s default state. Permission schemes and work item security can remain closed.
- Protection against privilege escalation. Administrator groups can be placed on an exclusion list so that a delegated user cannot add themselves or others to them.
- Low adoption risk. Configuration is a single screen of group selections, access is evaluated live, and any grant can be withdrawn immediately.
- Data residency. Built on Atlassian’s Forge platform; configuration is stored within our own Jira Cloud site and is not transmitted to the vendor.
I would propose beginning with a single delegated page for [team], and reviewing after [period] before extending the arrangement.
Thank you for considering this. I am happy to discuss it at your convenience.
Best regards,
[Your Name]
Supporting material
- Overview — what the app does and where its limits are.
- User guide — the configuration screen in detail.
- Use cases — worked examples you can quote in the email above.