---
title: "App-level permissions"
canonical: "https://support.appfire.com/space/DLP/2211971293/App-level%20permissions"
format: markdown
---
> Macro (aura-html)

App-level (or global) permissions determine access to the app and its respective pages, and the scope of actions permitted users can carry out within the app.

## Navigation and access

Only Jira and App Admins can access global security settings.

1. Click the **App settings** () button.
2. Select **Security** from the dropdown.

![App settings dropdown.](media://9cf868c1-8ef7-4300-a628-24ced464dcb7)

3. You are now on the **Administration** > **Security** page.

![BigPicture security page where Jira and App Admins can assing global roles to Jira users..](media://3a3bae1a-9f08-490d-a4ec-392a35a0444c)

## App Security (page)

### “Permissions for everyone” (toggle)

![Security for everyone toggle on the security page.](media://348fed30-8fc2-425c-a451-52a4ea1a0041)

 This toggle switch changes permissions in BigPicture only. It does not affect user permissions in Jira.

#### Toggle switched ON

When enabled, every logged-in Jira user has the same administrative level of access, which includes:

- App Administration
- Boxes and their content (depending on Jira permissions and security settings).

When the **Permissions for everyone** toggle is on, you cannot assign global roles to individual users or Jira groups because all users have full access to manage the app and boxes. 

Likewise, this toggle disables [box-level security settings](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211743914) (security roles for [box types](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211645733) are not affected).

| **App *****Security***** page** | **Box *****Security***** page** |
| --- | --- |
| ![Permission for every one are enabled.](media://10bb14b6-bbbb-4c87-a8dc-2ea95e98714c) | ![Box security page. The box-level security roles cannot be assigned due to the permissions for everyone option being active.](media://27a10ff0-9ac1-4f6c-8f0f-888e119bb9f1) |

The **Permissions for everyone** option is useful for small teams or when you're testing the app. It helps you quickly see how things work. But in a live environment, you may need more advanced access controls to keep things secure.

> ℹ️ The **Permissions for everyone **option does not override Jira permission settings. If a user is not permitted to access a project in Jira, this option will not allow them to view it in BigPicture, either. 
> ℹ️ 
> ℹ️ If you want your users to view and manage all boxes in BigPicture, ensure you have granted them the relevant permissions in Jira.

#### Toggle switched OFF

When the **Permissions for everyone **option is disabled, Jira/App Admins can manage global role permissions on the **Administration** > **Security **page. The security settings on the **box configuration** >  **Security** page are also enabled.

### Role permissions

There are three global security roles in BigPicture:

- App Admin
- App User
- Resource Admin

#### App Admin 

App Admins have full access to the *App Configuration,* *App Administration*, every box, and gadget. They can create new boxes and view and configure every existing box in the [box hierarchy](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211645621). 

> ℹ️ - Jira Admins automatically get the App Admin role, but they do not show up in the App **Administration** > **Security** tab by default.
> ℹ️ - Only Jira Admins and App Admins can give the App Admin role to others.
> ℹ️ - Once a user is granted the App Admin role, they can set up the app and add other users to the App Admin role, even if they are not Jira Admins.

When a Jira Admin grants someone the App Admin role, that user can manage the app and all boxes. Their name will appear under the App Admin role (**Administration** > **Security**) but not on the **box configuration** > **Security** pages.

| **App *****Security***** page** | **Box *****Security***** page** |
| --- | --- |
| ![App security page.](media://d6eed144-6e6a-41f5-9a2d-bbf04b60b671) | ![Box security page.](media://6b100790-5d60-432b-89c0-f981106b2729) |

#### App User 

The App User is the basic global role that allows Jira users to:

- See BigPicture under **Apps** in Jira
- Open BigPicture

Access to the app alone does not automatically grant access to individual boxes (even if the App User is permitted to view and/or manage a respective Jira project).

[Important] For that reason, to ensure users can benefit from using BigPicture, they must be granted:

- App User role in BigPicture
- project permissions in Jira
- a box-level security role to view/manage respective boxes
- BigPicture gadgets

Below, you can see how these permissions affect one another:

#### Resource Admin

This role grants you access to and management of all resource-related pages within the app’s *Administration* section. The Resource Admin role builds upon the App User role, meaning that users with this role:

- have basic access to the app but cannot access the *App Configuration*
- can access boxes based on individual box security settings (but they do not get access to all boxes like the App Admin)
- are allowed to administer resource-related global configuration on the resource [https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212529895](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212529895) (including all its subpages)
- can access the Administration page but not the Resources tab

> ℹ️ The App Financial Viewer and App Financial Admin are [Financials module-specific roles](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211842572).

## Grant and manage global security roles

> 📝 Global roles can be assigned to individual Jira users and Jira groups.

Jira and App Admins can grant global roles in BigPicture in the following ways:

1. On the *Security* page, expand the section with the security role you want to assign.
2. From the dropdown, under **Users**, select a Jira user or multiple users in one go; if you want to add a Jira group or groups to a specific role, select them from the list under **Groups**.

![Security page in BigPicture with all global roles listed.](media://9a1a8d77-18c1-4c56-aa02-7b0b5d65d98a)

The roles are assigned, and you do not need to confirm it with any additional buttons.

Alternatively:

1. Click the **+New assignment** button.
2. A dialog appears. Select whether you want to assign a user or a group.

![Assign security role dialog.](media://050b0863-fe8b-42c7-9370-638ce27c3481)

3. Next, select the global role from the list.

You can assign only one person or group at a time. To continue adding users and groups to the roles, check the **Add another** box.

4. Click the **Assign** button to finish the process.