Some permissions — like deleting issues — are irreversible. Granting them without a framework is a risk. Here's how to govern them.
On a large instance, sensitive permissions end up distributed widely "for convenience". But a permission like permanent deletion doesn't forgive, and the lack of traceability makes it impossible to know who did what.
Restricting a permission that's already distributed creates political friction. And defining "who should have it" requires clarifying responsibilities nobody has ever formalized.
Define an explicit accountability framework, document the assignment rules, and validate it all with the relevant data owners — so the decision rests on governance, not habit.
Nimbax designed a governance framework of this kind for a critical permission on an enterprise instance, making responsibilities explicit and compliance stronger.
An irreversible permission deserves explicit governance. "It's simpler if everyone has it" is precisely the mistake to avoid.
An Atlassian expert gets back to you directly.