Breadcrumbs

Permission groups

Permission groups control who can see sensitive employee information. Frank uses Atlassian's native permission groups, so you manage access in a familiar way through the Atlassian admin console.

The sensitive data access group

During installation, Frank creates a permission group for sensitive data access. Members of this group can view fields and information marked as sensitive in employee profiles. Everyone else only sees basic information and their own profile.

Managing group membership

Go to Frank settings and find "Setup Permissions" under the Jira section. Click "Manage permissions" to configure who has access to sensitive employee data.

Alternatively, go directly to Atlassian admin > Groups, find the Frank sensitive data access group, and add or remove users as needed.

Who should have access

Consider who genuinely needs access to sensitive information:

  • HR team members: Typically need full access to manage employee records, compensation, and confidential documentation.

  • People managers: May need access to view their direct reports' information for performance discussions and team management.

  • Finance: May need access to compensation data for payroll and budgeting.

  • Executives: May need organization-wide visibility for strategic planning.

Add people deliberately rather than broadly. You can always expand access later, but restricting it after people are used to seeing certain information is harder.

Scope of access

Group members can see all sensitive fields across all employees in the system. If you need more granular control — for example, if managers should only see their own team's sensitive data — you'll need to configure additional restrictions through Jira project permissions.

Regular review

Review your permission group membership periodically:

  • Remove access when someone's role changes and they no longer need it

  • Add new HR staff and managers as they join

  • Audit who has access during compliance reviews

The principle of least privilege applies: grant access only to those who genuinely require it for their work.