Admin Pro for Jira security and data

Admin Pro for Jira is a read-only app built on Atlassian Forge. This page covers what it can access, what it stores and where, and how to report a security issue.

Last reviewed October 2026.

Runs on Atlassian

Admin Pro runs on Atlassian's Forge platform and carries the Runs on Atlassian badge. Skymeadow Software doesn't run any servers, databases or cloud accounts for it, and the app doesn't send data outside Atlassian. Its code runs in Forge's sandboxed runtime, and its calls to Jira use Atlassian-managed authentication.

Read-only

Admin Pro never changes your Jira configuration or work items. It reads configuration with GET requests. Its only POST requests go to Jira's approximate-count search, which counts work items and changes nothing. The Edit and Delete links in the app open Jira's own admin pages, where Jira's normal permissions and confirmations apply.

Your permissions apply

Admin Pro calls Jira as the person who is using it, so it can only show what that person is allowed to see. The main app is a Jira admin page. The View Field IDs and View Field Details actions on a work item appear only to people who can edit that work item.

Scopes it requests

Jira requires admin-level scopes to read screens, schemes and workflows, so the app requests them, but it makes no write calls. These are the scopes in the app's manifest:

  • manage:jira-configuration
  • manage:jira-project
  • read:jira-work
  • read:jira-user
  • storage:app

storage:app lets the app keep the short-lived cache described below in its own Forge storage.

What it stores, and where

  • In Forge app storage (hosted by Atlassian): cached work item counts for fields and cached report results, so large sites load faster. These entries expire after 1 to 6 hours.
  • In your browser: cached work item counts and some row details, kept in the browser's local storage for 24 hours by default.
  • Nowhere else: Skymeadow Software has no copy of your data. The app doesn't store passwords or API tokens; it uses the Jira session of the person using it.

Report a security issue

Raise a request on the Skymeadow support portal, or email support@skymeadow.atlassian.net. Include the steps to reproduce and, if it's relevant, your Jira site URL.

Related