Roles & access
Two roles, both answered by Jira
Change Guards keeps no list of members. It asks Jira two questions at the moment they matter, and caches neither answer.
Project administrator
Anyone holding Administer projects on the Jira project. They configure the app, define freeze windows and are the only people who can override one. Overriding a freeze is the deliberate setting-aside of a control the project agreed to, so it must be attributable to somebody who owns the project.
Agent
Anyone in the Jira project role the administrator bound — directly, or through a group in that role. Agents record changes, request approvals and answer the ones addressed to them.
Every administrator is also an agent. An administrator who could configure the app but not use it would be an odd thing to ship, and it removes the trap where the first person to open the app in a new project cannot get in.
What each role can do
| Action | Project admin | Agent | Everyone else |
|---|---|---|---|
| Record and edit a change | Yes | Yes | No |
| Request an approval | Yes | Yes | No |
| Answer an approval addressed to them | Yes | Yes | No |
| Move a change through its lifecycle | Yes | Yes | No |
| See the CAB workbench, calendar and evidence | Yes | Yes | No |
| Take an evidence export | Yes | Yes | No |
| Bind or clear the agent role | Yes | No | No |
| Create and remove freeze windows | Yes | No | No |
| Override a freeze window | Yes | No | No |
“Everyone else” sees an explanation naming the role they would need to be added to — not an error, and not a blank panel.
Granting access
A project administrator opens Project settings → Change Guards, picks a project role and binds it. Membership stays in Jira’s own People screen, where it already lives.
Licensing is separate, and simpler
Atlassian charges for Change Guards per agent, at the site level, through the Marketplace. The app itself contains no plan, tier, entitlement, trial state or feature flag — there is nothing to withhold from somebody who is licensed and in the role.
That means the two questions are genuinely independent: Atlassian decides whether your site is licensed, and your project administrator decides who inside the project can use it.
Put change governance where the work already happens
Change Guards installs from the Atlassian Marketplace and is charged per agent. No external systems, no data leaving your site, nothing to host.