---
title: "App-level permissions"
canonical: "https://support.appfire.com/space/SPM/1918535770/App-level%20permissions"
format: markdown
---
> Macro (aura-html)

App-level (or global) permissions determine access to the app and its pages, and the scope of actions users can perform within the app.

> ⚠️ **Temporary access issue for OKR and Priorities**
> ⚠️ 
> ⚠️ Currently, Jira Administrators may not automatically have access to the OKR and Priorities modules in BigPicture. 
> ⚠️ 
> ⚠️ Until this issue is fixed, Jira Administrators must be granted access to these modules directly in BigPicture. To provide access, assign either:
> ⚠️ 
> ⚠️ - App Admin role, or
> ⚠️ - App OKR Admin and App Priorities Admin roles.
> ⚠️ 
> ⚠️ A fix is planned for late August or early September 2026.

## Navigation and access

Only Jira and App Admins can access global security settings.

1. Click the **App settings** button.
2. Select **Administration** > **Security** from the dropdown.

![Screenshot of the Security tab under Administration.](media://b973d91d-bf6c-4d98-be4c-af1adb31ef3c)

You are now on the **Administration** > **Security** page.

![Screenshot of the Security page in the BigPicture Administration.](media://319b8633-4ffc-4931-a0fe-92ecb836ada3)

## App Security (page)

### Every user is the App Admin (toggle)

This toggle switch changes permissions in BigPicture only. It doesn't affect user permissions in Jira.

![Screenshot of the Every user is the App Admin toggle switch.](media://48ea85c5-f82c-419d-b8c7-268cefc41ac3)

#### Toggle switched ON

When enabled, every logged-in Jira user has the same administrative level of access, which includes:

- App Administration
- Boxes and their content (depending on Jira permissions and security settings).

When the **Every user is the App Admin** toggle is on, you can't assign global roles to individual users or Jira groups because all users have full access to manage the app and boxes. 

Likewise, this toggle disables [box-level security settings](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918797447) (security roles for [box types](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918830000) are not affected).

| **App *****Security***** page** | **Box *****Security***** page** |
| --- | --- |
| ![Screenshot of the settings when the Every user is the App Admin toggle is enabled.](media://06c7c2a6-e58e-48e9-ab6e-691d219a2796) | ![Box security page. The box-level security roles cannot be assigned due to the permissions for everyone option being active.](media://3d29e7be-b86f-40ad-bce2-373a35ff9f5d) |

The **Every user is the App Admin** option is useful for small teams or when you're testing the app. It helps you quickly see how things work. But in a live environment, you may need more advanced access controls to keep things secure.

> ℹ️ The **Every user is the App Admin** option doesn't override Jira permission settings. If a user is not permitted to access a project in Jira, this option won't allow them to view it in BigPicture, either. 
> ℹ️ 
> ℹ️ If you want your users to view and manage all boxes in BigPicture, ensure you have granted them the relevant permissions in Jira.

#### Toggle switched OFF

When the **Every user is the App Admin** option is disabled, Jira/App Admins can manage global role permissions on the **Administration** > **Security **page. The security settings on the **box configuration** >  **Security** page are also enabled.

### Role permissions

The following security roles are available in BigPicture:

| **Role name** | **Description** |
| --- | --- |
| App Admin | Owns the entire application configuration and governance. Can access and manage any box. Grants full control over all settings, modules, and boxes, including permissions, structure, and data access. |
| App Financial Admin | Controls financial planning and management. Provides full access to create, edit, and manage financial data in the boxes they have access to.<br>> ℹ️ The App Financial Viewer and App Financial Admin are [Financials module-specific roles](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918765525). |
| App Financial Viewer | Provides read-only access to financial data. Allows visibility into budgets and financial metrics without the ability to modify them in the boxes they have access to.<br>> ℹ️ The App Financial Viewer and App Financial Admin are [Financials module-specific roles](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918765525). |
| App OKR Admin | Manages strategic objectives and key results. Allows creation, editing, and maintenance of OKRs across the organization. |
| App OKR User | Can view and edit Objectives and Key Results based on the permission settings of the OKR module. |
| App Priorities Admin | Manages prioritization frameworks and data. Allows configuration and maintenance of priorities used for planning and decision-making. |
| App Resource Admin | Manages organizational resources. Allows configuration of resources used across planning and execution. |
| App User | Has basic access to the App, which is dependent on the individual permissions given at box levels. |

#### App Admin 

App Admins have full access to the *App Configuration,* *App Administration*, and every box and gadget. They can create new boxes and view and configure every existing box in the [box hierarchy](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918535907). 

> ℹ️ - Jira Admins automatically get the App Admin role, but they do not show up in the App **Administration** > **Security** tab by default.
> ℹ️ - Only Jira Admins and App Admins can give the App Admin role to others.
> ℹ️ - Once a user is granted the App Admin role, they can set up the app and add other users to the App Admin role, even if they aren't Jira Admins.

When a Jira Admin grants someone the App Admin role, that user can manage the app and all boxes. Their name will appear under the App Admin role (**Administration** > **Security**) but not on the **box configuration** > **Security** pages.

| **App *****Security***** page** | **Box *****Security***** page** |
| --- | --- |
| ![App security page.](media://42720647-b84d-4e63-b2de-9aa3d8a54476) | ![Box security page.](media://2dae0667-a824-4cdd-a9f7-43af0c599dd8) |

#### App User 

The App User is the basic global role that allows Jira users to:

- See BigPicture under **Apps** in Jira
- Open BigPicture

Access to the app alone does not automatically grant access to individual boxes (even if the App User is permitted to view and/or manage a respective Jira project).

[Important] For that reason, to ensure users can benefit from using BigPicture, they must be granted:

- App User role in BigPicture
- project permissions in Jira
- a box-level security role to view/manage respective boxes
- BigPicture gadgets

Below, you can see how these permissions affect one another:

#### App Resource Admin

This role grants you access to and management of all resource-related pages within the app’s *Administration* section. The Resource Admin role builds upon the App User role, meaning that users with this role:

- Have basic access to the app but cannot access the *App Configuration.*
- Can access boxes based on individual box security settings (but they do not get access to all boxes like the App Admin).
- Are allowed to administer resource-related global configuration on the resource [Individual's details page](https://appfire.atlassian.net/wiki/spaces/SPM/pages/1918637190) (including all its subpages).
- Can access the Administration page but not the Resources tab.

## Grant and manage global security roles

> 📝 Global roles can be assigned to individual Jira users and Jira groups.

Jira and App Admins can grant global roles in BigPicture in the following ways:

1. On the *Security* page, find the security role you want to assign.
2. Click **Manage assignments** next to the role.
3. From the dropdown, under **Users**, select a Jira user or multiple users in one go; if you want to add a Jira group or groups to a specific role, select them from the list under **Groups**.

The roles are assigned, and you don't need to confirm them with any additional buttons.

Alternatively:

1. Click the **+Assign role** button.
2. A dialog appears. Select whether you want to assign a user or a group.

3. Next, select the global role from the list.

You can assign only one person or group at a time. To add more users and groups to the role, check the **Add another** box.

4. Click the **Save** button to finish the process.