Restrict access with governance groups
Mode: how-to. Restrict who can see Tollgate governance data to a named Jira group.
By default the Portfolio is visible to Jira admins only, and each project’s Tollgate tab falls back to that project’s own members. Setting a governance group changes that. The group gates the Portfolio view, every project’s governance tabs, and the Tollgate AI agent. Only its members and Jira admins keep access.
Set an access group
Section titled “Set an access group”- Open Apps → Tollgate Portfolio.
- In the page header, open the Settings menu and choose Who can see this portfolio.
- Enter the name of an existing Jira group — for example
sapper-pmo-governance. - Select Save group. Access now narrows to that group’s members and Jira admins.
Who can do what once a group is set
Section titled “Who can do what once a group is set”The group gates everything. Project membership alone is no longer enough. A project lead outside the group cannot open Tollgate on their own project.
| Can open Tollgate | Can edit | |
|---|---|---|
| In the governance group, and the project’s lead or a nominated editor | Yes | Yes |
| In the governance group, no role on the project | Yes | No |
| Jira site admin, outside the group | Yes | Only if they are the project’s lead or a nominated editor |
| The project’s lead, outside the group | No | No |
| Everyone else | No | No |
Two rules sit behind that table:
-
Opening Tollgate needs group membership (or Jira site admin).
-
Editing needs, on top of that, the project’s lead or a nominated editor.
Administering Jira does not confer it. The people accountable for the investment edit the governance data.
Remove the restriction
Section titled “Remove the restriction”- Reopen Settings → Who can see this portfolio.
- Select Remove access group, then confirm.
- The Portfolio reverts to Jira admins only, and each project’s tabs fall back to that project’s own members.