Atlassian Administrator Expert
Workflows
User Provisioning
- Create user account:
admin.atlassian.com > User management > Invite users- REST API:
POST /rest/api/3/userwith{"emailAddress": "...", "displayName": "...","products": [...]}
- REST API:
- Add to appropriate groups:
admin.atlassian.com > User management > Groups > [group] > Add members - Assign product access (Jira, Confluence) via
admin.atlassian.com > Products > [product] > Access - Configure default permissions per group scheme
- Send welcome email with onboarding info
- NOTIFY: Relevant team leads of new member
- VERIFY: Confirm user appears active at
admin.atlassian.com/o/{orgId}/usersand can log in
User Deprovisioning
- CRITICAL: Audit user's owned content and tickets
- Jira:
GET /rest/api/3/search?jql=assignee={accountId}to find open issues - Confluence:
GET /wiki/rest/api/user/{accountId}/propertyto find owned spaces/pages
- Jira:
- Reassign ownership of:
- Jira projects:
Project settings > People > Change lead - Confluence spaces:
Space settings > Overview > Edit space details - Open issues: bulk reassign via
Jira > Issues > Bulk change - Filters and dashboards: transfer via
User management > [user] > Managed content
- Jira projects:
- Remove from all groups:
admin.atlassian.com > User management > [user] > Groups - Revoke product access
- Deactivate account:
admin.atlassian.com > User management > [user] > Deactivate- REST API:
DELETE /rest/api/3/user?accountId={accountId}
- REST API:
- VERIFY: Confirm
GET /rest/api/3/user?accountId={accountId}returns"active": false - Document deprovisioning in audit log
- USE: Jira Expert to reassign any remaining issues
Group Management
- Create groups:
admin.atlassian.com > User management > Groups > Create group- REST API:
POST /rest/api/3/groupwith{"name": "..."} - Structure by: Teams (engineering, product, sales), Roles (admins, users, viewers), Projects (project-alpha-team)
- REST API:
- Define group purpose and membership criteria (document in Confluence)
- Assign default permissions per group
- Add users to appropriate groups
- VERIFY: Confirm group members via
GET /rest/api/3/group/member?groupName={name} - Regular review and cleanup (quarterly)
- USE: Confluence Expert to document group structure
Permission Scheme Design
Jira Permission Schemes (Jira Settings > Issues > Permission Schemes):
- Public Project: All users can view, members can edit
- Team Project: Team members full access, stakeholders view
- Restricted Project: Named individuals only
- Admin Project: Admins only
Confluence Permission Schemes (Confluence Admin > Space permissions):
- Public Space: All users view, space members edit
- Team Space: Team-specific access
- Personal Space: Individual user only
- Restricted Space: Named individuals and groups
Best Practices:
- Use groups, not individual permissions
- Principle of least privilege
- Regular permission audits
- Document permission rationale
SSO Configuration
- Choose identity provider (Okta, Azure AD, Google)
- Configure SAML settings:
admin.atlassian.com > Security > SAML single sign-on > Add SAML configuration- Set Entity ID, ACS URL, and X.509 certificate from IdP
- Test SSO with admin account (keep password login active during test)
- Test with regular user account
- Enable SSO for organization
- Enforce SSO:
admin.atlassian.com > Security > Authentication policies > Enforce SSO - Configure SCIM for auto-provisioning:
admin.atlassian.com > User provisioning > [IdP] > Enable SCIM - VERIFY: Confirm SSO flow succeeds and audit logs show
saml.login.successevents - Monitor SSO logs:
admin.atlassian.com > Security > Audit log > filter: SSO
Marketplace App Management
- Evaluate app need and security: check vendor's security self-assessment at
marketplace.atlassian.com - Review vendor security documentation (penetration test reports, SOC 2)
- Test app in sandbox environment
- Purchase or request trial:
admin.atlassian.com > Billing > Manage subscriptions - Install app:
admin.atlassian.com > Products > [product] > Apps > Find new apps - Configure app settings per vendor documentation
- Train users on app usage
- VERIFY: Confirm app appears in
GET /rest/plugins/1.0/and health check passes - Monitor app performance and usage; review annually for continued need
System Performance Optimization
Jira (Jira Settings > System):
- Archive old projects:
Project settings > Archive project - Reindex:
Jira Settings > System > Indexing > Full re-index - Clean up unused workflows and schemes:
Jira Settings > Issues > Workflows - Monitor queue/thread counts:
Jira Settings > System > System info
Confluence (Confluence Admin > Configuration):
- Archive inactive spaces:
Space tools > Overview > Archive space - Remove orphaned pages:
Confluence Admin > Orphaned pages - Monitor index and cache:
Confluence Admin > Cache management
Monitoring Cadence:
- Daily health checks:
admin.atlassian.com > Products > [product] > Health - Weekly performance reports
- Monthly capacity planning
- Quarterly optimization reviews
Integration Setup
Common Integrations:
- Slack:
Jira Settings > Apps > Slack integration— notifications for Jira and Confluence - GitHub/Bitbucket:
Jira Settings > Apps > DVCS accounts— link commits to issues - Microsoft Teams:
admin.atlassian.com > Apps > Microsoft Teams - Zoom: Available via Marketplace app
zoom-for-jira - Salesforce: Via Marketplace app
salesforce-connector
Configuration Steps:
- Review integration requirements and OAuth scopes needed
- Configure OAuth or API authentication (store tokens in secure vault, not plain text)
- Map fields and data flows
- Test integration thoroughly with sample data
- Document configuration in Confluence runbook
- Train users on integration features
- VERIFY: Confirm webhook delivery via
Jira Settings > System > WebHooks > [webhook] > Test - Monitor integration health via app-specific dashboards
Global Configuration
Jira Global Settings (Jira Settings > Issues)
Issue Types: Create and manage org-wide issue types; define issue type schemes; standardize across projects
Workflows: Create global workflow templates via Workflows > Add workflow; manage workflow schemes
Custom Fields: Create org-wide custom fields at Custom fields > Add custom field; manage field configurations and context
Notification Schemes: Configure default notification rules; create custom notification schemes; manage email templates
Confluence Global Settings (Confluence Admin)
Blueprints & Templates: Create org-wide templates at Configuration > Global Templates and Blueprints; manage blueprint availability
Themes & Appearance: Configure org branding at Configuration > Themes; customize logos and colors
Macros: Enable/disable macros at Configuration > Macro usage; configure macro permissions
Security Settings (admin.atlassian.com > Security)
Authentication:
- Password policies:
Security > Authentication policies > Edit - Session timeout:
Security > Session duration - API token management:
Security > API token controls
Data Residency: Configure data location at admin.atlassian.com > Data residency > Pin products
Audit Logs: admin.atlassian.com > Security > Audit log
- Enable comprehensive logging; export via
GET /admin/v1/orgs/{orgId}/audit-log - Retain per policy (minimum 7 years for SOC 2/GDPR compliance)
Governance & Policies
Access Governance
- Quarterly review of all user access:
admin.atlassian.com > User management > Export users - Verify user roles and permissions; remove inactive users
- Limit org admins to 2–3 individuals; audit admin actions monthly
- Require MFA for all admins: `Security > Authentication polic