Handover for Jira

Administrator guide

What Handover does · Running an offboarding · The audit report · Manual steps · Groups · Settings · Permissions · Troubleshooting · Data & privacy · Support

What Handover does

When a person leaves your organization, deactivating their Atlassian account changes nothing about what they own. Handover inventories what a departing user still holds in Jira and transfers it to successors you choose, in one audited run:

CategoryWhat happens
Open issues assigned to themReassigned to a successor (optionally with an explanatory comment)
Saved filters they own, including private filtersOwnership transferred
Dashboards they ownGuided manual step with a Mark done control (see below)
Components where they are leadLead changed
Projects where they are leadLead changed
Group membershipsSnapshot only: recorded in the audit, never edited

Closed and Done issues are deliberately untouched: reassigning finished work would rewrite history. Scans cover up to 5,000 open issues per run and say so in the wizard when capped.

Running an offboarding

  1. Choose person: search by name. Active or deactivated accounts both work.
  2. Review inventory: a read-only scan shows totals per category. Nothing is modified at this step, ever.
  3. Assign successors: pick one default successor; optionally override per project (issues and component leads) or per category. The leaver can never be chosen as a successor, and successors are verified as active before the plan is created.
  4. Confirm: a summary of every transfer that will run, including any manual steps you will be left with.
  5. Execute: transfers run in background batches with live progress. You can leave the page; the run continues and is always visible under History → In progress. When finished, the audit report opens.

The audit report

Every run is recorded: who ran it, when, every item, its successor and its outcome (done, manual, or failed with Jira's error). Export any run as CSV; the export opens with a header naming the plan, the person, who executed it, and start and finish times. The file is assembled on Atlassian's Forge infrastructure from data stored in your own Jira and downloaded straight to your browser; it never touches an external service. Admins can permanently delete any record from its report page.

Why dashboards are a manual step

Jira Cloud's only endpoint for changing a dashboard's owner is marked Experimental, so Handover does not build your compliance record on it. Instead it lists each affected dashboard with exact instructions (Jira Settings → System → Shared dashboards → Change owner), gives the row a Mark done button, and records the step and who completed it in the audit.

Scope limit worth knowing: no Jira API can list a dashboard the leaver never shared with anyone. Site admins can review those on the same Shared dashboards admin page. Private filters are fully included in scans.

Why groups are snapshot-only

Group membership is frequently directory-managed (SCIM, Okta, Microsoft Entra). An app-side removal would silently revert on the next sync or conflict with your identity source of truth. Handover records the leaver's memberships in the audit so your identity team can act with full information in the system that owns it.

Settings

Comment on reassigned issues by default pre-checks the wizard option. Comment template supports {leaver} and {successor} placeholders, replaced with display names.

Permissions (scopes) and why

ScopeUsed for
read:jira-userFinding the leaver and successors
read:jira-workScanning issues, filters, dashboards
write:jira-workReassigning issues, adding comments, transferring filters
manage:jira-projectChanging project and component leads
manage:jira-configurationAdmin-level reads, including private-filter visibility
storage:appStoring plans, progress and audit history in Forge storage

All scopes are declared up front so an update never surprises you with a permission re-approval. Every backend operation additionally re-verifies that the invoking user is a Jira administrator.

Troubleshooting

Data & privacy

Handover runs entirely on Atlassian's Forge platform: no external servers, no data egress, data residency follows your site automatically. It stores plans (including issue keys and one-line summaries), progress and audit summaries in Forge storage. Delete any record from its report page. Before uninstalling, export the audit CSVs you need; uninstalling removes the app's storage under Atlassian's Forge data lifecycle. See the Privacy Policy.

Support

support@greylineinteractive.com. We respond within one business day. Include the plan ID from the audit report for fastest help.