Permissions audit: allow project admin to review effective permissions for a particular user


      Atlassian status as of Oct 2022

      Hi everyone,

      I'm happy to announce that in Bitbucket Data Center 8.5 we have completely redesigned repository/project permission page. Repository admins can see not only users with direct permissions, but also users who have access because of permissions assigned on project/global level. For example, if user has read permission for a repository, but also has write permissions for the project, then repository admin will be able to see both permissions in the list. This feature will help repository admins to identify effective permissions of specific users much easier. 

      Anton Genkin
      Product Manager - Bitbucket Data Center


      I have a project with some sensitive repositories and a non-sensitive respository. I need to provide read access to the non-sensitive repository to a user, but he needs to NOT have access to the sensitive repositories.

      I got this working, but only after accidentally opening the project up to any logged-in user, and I did not realize this until I was able to request a test user to be created so I could log in as the test user and see what repositories were accessible.

      The permissions management would be a LOT easier to verify if you could just see what a particular user sees.

