---
title: "Xray and Permissions"
canonical: "https://docs.getxray.app/space/XRAYCLOUD/1203503118/Xray%20and%20Permissions"
format: markdown
---
> Macro (rw-ui-expands-macro)
> 
> > Macro (rw-expand)
> 
> > Macro (toc)

# Introduction

Xray serves as the central point to manage your manual, automated, or exploratory QA efforts. It becomes easier to gather stakeholders in one place for improved collaboration. At the same time, it also means that, without proper controls, users from different teams may have access to assets not intended for them, which creates significant risks, especially in regulated industries.

Therefore, establishing relevant role and entity-based permissions becomes a key part of your Xray setup. 

For this topic, we separate Xray entities into two groups:

- Work items (e.g. Test).
- “Special cases” (e.g., [Test Run](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565109), [Test Repository](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565166)).

Then, we look at Xray-specific permissions and controls vs Jira-level ones, which leads us to the following matrix (Figure 1):

![Figure 1 - Permission control matrix](media://68e6185d-d52a-47f6-b900-af4f6265dc10)


We will break this review into two major parts: by Xray entity group, then discuss considerations in each square (Figure 1).

> ℹ️ This article focuses on the end-user actions as part of their QA workflow and advanced configuration options for company-managed spaces in Xray Cloud. It also assumes no other third-party plugins for permissions. For the initial setup, basic configuration, and the associated permission requirements, please refer to <u>[Quick Setup](https://docs.getxray.app/space/XRAYCLOUD/44565860/Quick+Setup)</u> and <u>[Settings](https://docs.getxray.app/space/XRAYCLOUD/44565796/Settings)</u>.

# Actions and Permissions

## Xray Work Items

> ℹ️ “Jira level” below refers specifically to* Jira Admin settings -> Work Items -> Work Item Attributes -> Permission Schemes*

|  |  |  |  |
| --- | --- | --- | --- |
| **Action** | **Eligible Xray Work Items** | **Permissions Needed to Perform** | **Notes** |
| View | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- *Browse Spaces* | Includes being able to use filters and add/remove columns in the tables inside Xray entities (e.g., Tests list in a Test Execution). |
| Prevent visibility/access | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - <u>[Jira level](https://support.atlassian.com/jira-software-cloud/docs/view-and-change-a-work-items-security-level/)</u>
- Administer Spaces / Jira Admin | - Once you have set up some security levels, be sure to grant the *Set work item security* permission to relevant users.
- Once enabled, the icon is next to the *Watch* feature on the top right.
- An example of the use case: “Can we restrict visibility based on User Groups to ensure testers only see their assigned Test Cases and specific test data?”
- “Scenario: 5 specific people should see Test Cases #1, 3, 5, while others see #2, 4, 6.”
- Sub-Test Execution would inherit the security level of the associated parent. |
| Create (from the standard Jira dialog) | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- Create Work Items | - To create Tests from other Jira or Xray work items, you need “Edit Work Items” permission.
- To correctly create Tests from Coverable items, specifically, you also need “Link Work Items” permission. Without it, the test item will be created but not automatically connected to the Coverable item.
- For bulk creation (e.g., [Test Case Importer](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565062)), you also need “Make bulk changes” in Jira Admin → System-> Security → Global Permissions. |
| Prevent creation (or another workflow status change) | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- Workflow Rule validation with a specific permission can restrict actions by Work type, which applies to Xray Work items (<u>[primary reference](https://support.atlassian.com/jira/kb/how-to-restrict-the-creation-of-an-issue-based-on-issuetype/)</u>, [secondary reference](https://community.atlassian.com/forums/Jira-questions/Permission-on-Issue-Type/qaq-p/1217233)). | ![image-20260311-140933.png](media://841eedbf-1ab4-4bf2-988e-4cd65e97834d)<br>Also affects Xray Test Case Importer |
| Delete | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- “Delete Work Items” | N/A |
| Clone | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- “Clone Work Items” | N/A |
| Edit non-Xray fields (i.e., Jira system or custom fields) | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- Depending on the specific edit, “Manage Issue Layouts” + “Edit Work Items” + more granular permissions like “Link Work Items”, “Add Comments”, “Create Attachments”, etc. | For bulk edits, you also need “Make bulk changes” in Jira Admin → System → Security → Global Permissions |
| Edit Xray-specific “fields” (see the list below the table) | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114)
- Also coverable items | - Jira level
- “Edit Work Items” | N/A |
| Prevent Xray execution | - Test
- Test Execution | Xray Global or Space settings -> Miscellaneous -> “Disallow executions of Tests with workflow statuses” and “Disallow executions with workflow statuses”  
(the status selection depends on the Jira Workflow Schemes) | N/A |
| Make the entity read-only | - [Test](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565156)
- [Precondition](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565159)
- [Test Set](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565163)
- [Test Plan](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565153)
- [Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565117)
- [Sub-Test Execution](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565114) | - Jira level
- “Edit Workflows” + “Transition Work Items” permissions<br>The core aspect of this action is the “jira.issue.editable” Jira attribute, which you can set to “false” via Workflow status changes | - Can clone a non-editable item, which will reset the Workflow status.
- Can still move the non-editable item to a different folder in the Xray [Test Repository](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565166).
- Coverage status on read-only Requirements can still be affected by status changes in the related Test Runs.
- Overall progress / consolidated status on read-only Test Plans can still be affected by changes in existing Test Executions already linked to that Test Plan. |

For the *Edit Xray-specific “fields”* action, common Xray-specific fields or parts of the Work item are:

- *Precondition Details* section on Preconditions.
- *Test Details* section on Test Work items (including Test Type, Datasets, Test Case Versioning).
- *Test Coverage* section on Coverable Work items.
- *Test Environments* field on Test Execution/Sub-Test Execution Work items.
- *Test Plans* field on Test Execution/Sub-Test Execution Work items.
- *Tests* list section on Test Execution/Sub-Test Execution Work items (meaning, change the list of associated Tests, not their content).
- *Tests* list section on Test Set and Test Plan work items (meaning, change the list of associated Tests, not their content).

For example, you cannot add Tests to Test Execution without “Edit Work Items” permission.

> ℹ️ If a Test Execution or another item with Tests has a Test work item that a user doesn’t have access to (e.g., because of the *Prevent visibility/access* action), they will see the following error screen (Figure 2). 
> ℹ️ 
> ℹ️ Given the nature of the reason, the proper “fix” would be the permission or Work item security adjustments, so the option under the *here* button (Figure 2 - 1) is unlikely to be very helpful.

Figure 2 - Error in a Test Execution

![Figure 2 - Error in a Test Execution](media://2ad79d89-16f8-4a5c-b468-d513065a4785)

## Xray-specific Entities 

### Test Run

You can view the details of the already-initiated Test Run with just “Browse Spaces” permission by clicking the Settings icon (Figure 3 - 1). The details will be in the read-only state.

![Figure 3 - State of an existing Test Run](media://3482f910-3209-47f6-ab54-4f00b7c6129f)


You are allowed to initiate a Test Run or modify most of its details if you have the following permissions: 

- "Browse Spaces" (to open the Test Execution, assuming it’s not locked via Work Item Security Level).
- “Resolve Work Items” (to actually interact with the *Play* button in the Tests table).

The same applies to inline execution (from the Status column of the Tests table), as long as it is enabled via the dedicated checkbox in the Xray settings (Figure 4).

![Figure 4 - Xray settings](media://d963eeee-8347-4de9-8cb1-f31e85926bcf)


Both the Test and the Test Execution must **not** be in the Workflow status that is set to disallow executions in Xray settings.

The Test Run modifications that require just the two permissions above include:

- Changing Test Run assignee.
- Modifying the overall status of a Test Run.
- Adjusting data on a Test Run (Test Run custom fields, “Actual Result” field, evidence, comments, step level status).
- Resetting or merging the Test Run definition when the underlying Test is changed (even if you do not have permissions to edit the Test).

#### Operations

- To create a Defect from the Test Run, you need “Create Work Items” and (unless you disable automatic linking in Xray settings) “Link Work Items” permissions.
- To edit the Dataset at the Test Run level (from the Tests table of the Test Execution), you need “Edit Work Items” permission.

Keep in mind these extra options in [Xray Miscellaneous settings](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44566331) (Figure 5):

![Figure 5 - Xray settings](media://681d03b5-de81-4152-80c7-e892b8a79947)

> ✅ Test Run Archiving in Global Xray settings does not require “Archive Work Items” permission.

### Testing Board (and its Components)

To access the main [Testing Board](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/1193377803) menu, you just need “Browse Spaces” permission.

- [Test Repository](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565166) - you can create, rename, expand, or delete folders with the “Browse Spaces” permission. You can also move Tests between folders. However, to create tests or preconditions (manually or via AI), you need the “Create Work Items” permission.
- [Test Plans Board](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565285) - you can use “Edit Work Items” permission for the target Test Plan Work items to create or modify folders.
- Reports (directly through the Testing Board vertical menu or through [Reporting Center](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/338526916)):
  - “Browse Spaces” for accessing and running reports.
  - “Administer Spaces” (or “Jira Admin”) for [Document Generator](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44565169) setup/template management.
- Steps Library ([BDD](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44577261) or [Manual](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/723648516)) - by default, use “Browse Spaces” to access, create, edit, or delete steps. You can further limit the permission scope via Xray settings at the Space level.

> ℹ️ Xray Cloud doesn't allow the control of repository-specific permissions (unlike[ Xray ](https://docs.getxray.app/display/XRAY/Permissions#Permissions-XrayTestRepositoryPermissions)<u>[DC](https://docs.getxray.app/display/XRAY/Permissions#Permissions-XrayTestRepositoryPermissions)</u>), so creating a separate Space could make more sense for "full control" (+ voting on[ ](https://jira.getxray.app/browse/XRAYCLOUD-6574)<u>[https://jira.getxray.app/browse/XRAYCLOUD-6574](https://jira.getxray.app/browse/XRAYCLOUD-6574)</u> or[ ](https://jira.getxray.app/browse/XRAYCLOUD-5775)<u>[https://jira.getxray.app/browse/XRAYCLOUD-5775](https://jira.getxray.app/browse/XRAYCLOUD-5775)</u>)

### Remote Jobs Trigger

Configuration has to be done by a user with “Administer Spaces” permission, but any user with just “Browse Spaces” permission (who can view Test Execution/Test Plan work items) could trigger the build, even without seeing Tests/being able to add or edit Tests.

# Use Cases for Jira Automation

> ⚠️ These tips and use cases could be applied to the Work Item actions, not to the Xray-Specific entities.

Since many of the actions on the table above are native to Jira, you can build Jira Automation rules around them to reduce manual effort. We provide some tips below:

- On the due date, prevent any further Xray execution - you can leverage the *Scheduled* type of *When* statement with the JQL that includes something like “issueType = “Test Execution” AND resolution is EMPTY AND duedate <= 2d”. The *Then* statement could change the Workflow status, which, in turn, prevents Test Execution based on Xray settings (*Prevent Xray execution* - table action item).
- Lock the item visibility - the guidance we typically share is this <u>[Atlassian tutorial](https://support.atlassian.com/jira/kb/restrict-access-to-certain-jira-issues-based-on-the-value-of-a-custom-field/)</u> (with a few more considerations [here](https://community.atlassian.com/forums/Jira-questions/How-to-hide-specific-issues-from-specific-user-groups/qaq-p/2719465).
- Locate who created a Work Item, then delete it immediately after creation for users who should not be using a specific Work Item Type. You could also send the user an email confirming that they are not allowed to create that Work Item Type.

> ℹ️ More <u>[tips](https://docs.getxray.app/space/XRAYCLOUD/44565672/Generic+automation+of+Testing+processes#Copy-fields-from-requirement/Story-to-Test-whenever-creating-a-Test-or-linking-it-to-a-story)</u> for Xray and Jira Automation (not limited to the Permissions topic).

# Team-managed Spaces

A good rule of thumb - be Member or Administrator in the Team-managed Space to “fully” interact with Xray (similar to “Create Work Items” + “Edit Work Items”). 

While the implementation details are different, the concepts are similar to the company-managed nuances we described above because:

- Roles in team-managed Spaces rely on many of the same granular permissions (e.g., “Edit any Work Item”) you would configure for Permission Schemes in company-managed Spaces.
- You can create custom roles with a specific combination of granular permissions.
- Changing the Space access level (Open, Limited, Private) also works through the Roles. Therefore, it relies on the granular permission levels (just “packaged” into the default roles of Viewer, Member, Admin).

For a more detailed breakdown, see the table in <u>[this article from Atlassian](https://support.atlassian.com/jira-software-cloud/docs/next-gen-permissions/)</u> (while the list is not 1-to-1 compared to the company-managed spaces, most permission levers relevant for Xray are available with the same/similar names). 

Keep in mind that there is a concept of “a set of permissions” (e.g., “Work on space work items”), so you may not need to assign each granular permission individually for custom roles.

Another relevant aspect that is a bit different is Workflows, you can check out <u>[this article](https://support.atlassian.com/jira-software-cloud/docs/set-up-a-workflow-in-a-team-managed-software-project/)</u> for the basics, as well as a couple of permission-specific examples.

# References

- [Understand workflows](https://support.atlassian.com/jira-cloud-administration/docs/work-with-issue-workflows/)
- [Work item permissions in a space](https://support.atlassian.com/jira-cloud-administration/docs/work-item-permissions/)
- [ What are work item security schemes?](https://support.atlassian.com/jira-cloud-administration/docs/what-are-work-item-security-schemes/)
- [ Space access and configuration permissions](https://support.atlassian.com/jira-cloud-administration/docs/space-access-and-configuration-permissions/)
- [Permissions limitations in Free Jira sites](https://support.atlassian.com/jira-cloud-administration/docs/permissions-and-issue-level-security-in-free-plans/)
- [ Permissions limitations in Free Jira sites](https://support.atlassian.com/jira-cloud-administration/docs/permissions-and-issue-level-security-in-free-plans/)
- [ How to find a work item security level value when setting work item security via automation](https://support.atlassian.com/jira/kb/how-to-find-an-issue-security-level-value-when-setting-issue-security-via-automation/)
- [ Issues are Editable In Closed State](https://support.atlassian.com/jira/kb/issues-are-editable-in-closed-state/)
- <u>[Xray Quick Setup](https://docs.getxray.app/space/XRAYCLOUD/44565860/Quick+Setup)</u>
- <u>[Xray Settings](https://docs.getxray.app/space/XRAYCLOUD/44565796/Settings)</u>
- [Using Jira workflows for Testing purposes](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44567832)

> Macro (rw-ui-expands-macro)
> 
> > Macro (rw-expand)
> 
> If you have questions or technical issues, please [contact the Support team via the Customer Portal (Jira service management)](https://jira.getxray.app/servicedesk/customer/portal/2/user/login?destination=portal%2F2%2Fcreate%2F28) or [send us a message using the in-app chat](https://getxraydocs.atlassian.net/wiki/spaces/XRAYCLOUD/pages/44577312).