工作流程
用户配置
- 创建用户账户:
admin.atlassian.com > User management > Invite users
- REST API:
POST /rest/api/3/user 使用
{"emailAddress": "...", "displayName": "...","products": [...]}
- 添加到适当的组:
admin.atlassian.com > User management > Groups > [group] > Add members
- 通过
admin.atlassian.com > Products > [product] > Access 分配产品访问权限(Jira、Confluence)
- 配置每组的默认权限方案
- 发送包含入职信息的欢迎邮件
- 通知:相关团队负责人新成员加入
- 验证:确认用户在
admin.atlassian.com/o/{orgId}/users 显示为活跃状态并且可以登录
用户取消配置
- Jira:
GET /rest/api/3/search?jql=assignee={accountId} 查找开放问题
- Confluence:
GET /wiki/rest/api/user/{accountId}/property 查找拥有的空间/页面
- Jira 项目:
Project settings > People > Change lead
- Confluence 空间:
Space settings > Overview > Edit space details
- 开放问题:通过
Jira > Issues > Bulk change 批量重新分配
- 过滤器和仪表板:通过
User management > [user] > Managed content 转移
- 从所有组中移除:
admin.atlassian.com > User management > [user] > Groups
- 撤销产品访问权限
- 停用账户:
admin.atlassian.com > User management > [user] > Deactivate
- REST API:
DELETE /rest/api/3/user?accountId={accountId}
- 验证:确认
GET /rest/api/3/user?accountId={accountId} 返回 "active": false
- 在审计日志中记录取消配置操作
- 使用:Jira 专家重新分配任何剩余问题
组管理
- 创建组:
admin.atlassian.com > User management > Groups > Create group
- REST API:
POST /rest/api/3/group 使用
{"name": "..."}
- 按以下方式组织:团队(engineering、product、sales)、角色(admins、users、viewers)、项目(project-alpha-team)
- 定义组的用途和成员标准(在 Confluence 中记录)
- 为每组分配默认权限
- 将用户添加到适当的组
- 验证:通过
GET /rest/api/3/group/member?groupName={name} 确认组成员
- 定期审查和清理(每季度)
- 使用:Confluence 专家记录组结构
权限方案设计
Jira 权限方案 (Jira Settings > Issues > Permission Schemes):
- 公共项目:所有用户可以查看,成员可以编辑
- 团队项目:团队成员完全访问,相关者查看
- 受限项目:仅限指定人员
- 管理员项目:仅限管理员
Confluence 权限方案 (Confluence Admin > Space permissions):
- 公共空间:所有用户查看,空间成员编辑
- 团队空间:团队特定访问
- 个人空间:仅限个人用户
- 受限空间:指定人员和组
最佳实践:
- 使用组,而不是个人权限
- 最小权限原则
- 定期权限审核
- 记录权限理由
SSO 配置
- 选择身份提供商(Okta、Azure AD、Google)
- 配置 SAML 设置:
admin.atlassian.com > Security > SAML single sign-on > Add SAML configuration
- 设置实体 ID、ACS URL 和来自 IdP 的 X.509 证书
- 使用管理员账户测试 SSO(测试期间保持密码登录活跃)
- 使用普通用户账户测试
- 为组织启用 SSO
- 强制 SSO:
admin.atlassian.com > Security > Authentication policies > Enforce SSO
- 配置 SCIM 自动配置:
admin.atlassian.com > User provisioning > [IdP] > Enable SCIM
- 验证:确认 SSO 流程成功,审计日志显示
saml.login.success 事件
- 监控 SSO 日志:
admin.atlassian.com > Security > Audit log > filter: SSO
Marketplace 应用管理
- 评估应用需求和安全性:在
marketplace.atlassian.com 检查供应商的安全自我评估
- 审查供应商安全文档(渗透测试报告、SOC 2)
- 在沙箱环境中测试应用
- 购买或请求试用:
admin.atlassian.com > Billing > Manage subscriptions
- 安装应用:
admin.atlassian.com > Products > [product] > Apps > Find new apps
- 根据供应商文档配置应用设置
- 培训用户使用应用
- 验证:确认应用出现在
GET /rest/plugins/1.0/ 中,健康检查通过
- 监控应用性能和使用情况;每年审查是否继续需要
系统性能优化
Jira (Jira Settings > System):
- 归档旧项目:
Project settings > Archive project
- 重新索引:
Jira Settings > System > Indexing > Full re-index
- 清理未使用的工作流和方案:
Jira Settings > Issues > Workflows
- 监控队列/线程计数:
Jira Settings > System > System info
Confluence (Confluence Admin > Configuration):
- 归档不活跃空间:
Space tools > Overview > Archive space
- 移除孤立页面:
Confluence Admin > Orphaned pages
- 监控索引和缓存:
Confluence Admin > Cache management
监控频率:
- 每日健康检查:
admin.atlassian.com > Products > [product] > Health
- 每周性能报告
- 每月容量规划
- 每季度优化审查
集成设置
常见集成:
- Slack:
Jira Settings > Apps > Slack integration — Jira 和 Confluence 通知
- GitHub/Bitbucket:
Jira Settings > Apps > DVCS accounts — 将提交链接到问题
- Microsoft Teams:
admin.atlassian.com > Apps > Microsoft Teams
- Zoom:通过 Marketplace 应用
zoom-for-jira 提供
- Salesforce:通过 Marketplace 应用
salesforce-connector
配置步骤:
- 审查集成要求和所需的 OAuth 范围
- 配置 OAuth 或 API 认证(将令牌存储在安全保险库中,不要明文存储)
- 映射字段和数据流
- 使用示例数据彻底测试集成
- 在 Confluence 运行手册中记录配置
- 培训用户使用集成功能
- 验证:通过
Jira Settings > System > WebHooks > [webhook] > Test 确认 webhook 交付
- 通过应用特定仪表板监控集成健康状况
全局配置
Jira 全局设置 (Jira Settings > Issues)
问题类型:创建和管理组织范围的问题类型;定义问题类型方案;跨项目标准化
工作流:通过 Workflows > Add workflow 创建全局工作流模板;管理工作流方案
自定义字段:在 Custom fields > Add custom field 创建组织范围的自定义字段;管理字段配置和上下文
通知方案:配置默认通知规则;创建自定义通知方案;管理电子邮件模板
Confluence 全局设置 (Confluence Admin)
蓝图和模板:在 Configuration > Global Templates and Blueprints 创建组织范围的模板;管理蓝图可用性
主题和外观:在 Configuration > Themes 配置组织品牌;自定义标志和颜色
宏:在 Configuration > Macro usage 启用/禁用宏;配置宏权限
安全设置 (admin.atlassian.com > Security)
认证:
- 密码策略:
Security > Authentication policies > Edit
- 会话超时:
Security > Session duration
- API 令牌管理:
Security > API token controls
数据驻留:在 admin.atlassian.com > Data residency > Pin products 配置数据位置
审计日志:admin.atlassian.com > Security > Audit log
- 启用全面日志记录;通过
GET /admin/v1/orgs/{orgId}/audit-log 导出
- 根据策略保留(SOC 2/GDPR 合规至少保留 7 年)
治理与策略
访问治理
- 每季度审查所有用户访问:
admin.atlassian.com > User management > Export users
- 验证用户角色和权限;移除不活跃用户
- 将组织管理员限制为 2-3 人;每月审计管理员操作
- 要求所有管理员启用 MFA:
Security > Authentication policies > Require 2FA
命名约定
Jira:项目键 3-4 个大写字母(PROJ、WEB);问题类型标题大小写;自定义字段带前缀(CF: Story Points)
Confluence:空间使用团队/项目前缀(TEAM: Engineering);页面描述性和一致性;标签小写,连字符分隔
变更管理
重大变更:提前 2 周宣布;在沙箱中测试;创建回滚计划;在非高峰时段执行;实施后审查
次要变更:提前 48 小时宣布;在变更日志中记录;监控问题
灾难恢复
备份策略
Jira 和 Confluence:每日自动备份;每周手动验证;保留 30 天;异地存储
- 触发手动备份:
Jira Settings > System > Backup system / Confluence Admin > Backup and Restore
恢复测试:每季度恢复演练;记录程序;测量 RTO 和 RPO
事件响应
严重级别:
- P1(关键):系统宕机 — 15 分钟内响应
- P2(高):主要功能损坏 — 1 小时内响应
- P3(中):次要问题 — 4 小时内响应
- P4(低):增强功能 — 24 小时内响应
响应步骤:
- 确认并记录事件
- 评估影响和严重程度
- 向相关者沟通状态
- 调查根本原因(检查
admin.atlassian.com > Products > [product] > Health 和 Atlassian 状态页面)
- 实施修复
- 验证:通过受影响用户测试和健康检查确认解决
- 事后分析和经验教训
指标与报告
系统健康:活跃用户(每日/每周/每月)、存储利用率、API 速率限制、集成健康状况、响应时间
- 导出方式:
GET /admin/v1/orgs/{orgId}/users 获取用户计数;产品特定分析仪表板
使用分析:最活跃的项目/空间、内容创建趋势、用户参与度、搜索模式
合规指标:用户访问审查完成情况、安全审计发现、登录失败尝试、API 令牌使用情况
决策框架与交接协议
升级到 Atlassian 支持:系统宕机、组织范围性能下降、数据丢失/损坏、许可证/计费问题、复杂迁移
委托给产品专家:
- Jira 专家:项目特定配置
- Confluence 专家:空间特定设置
- Scrum Master:团队工作流需求
- 高级 PM:战略规划输入
涉及安全团队:安全事件、异常访问模式、合规审计准备、新集成安全审查
给 Jira 专家:新的全局工作流、自定义字段、权限方案或自动化功能可用
给 Confluence 专家:新的全局模板、空间权限方案、蓝图或宏已配置
给高级 PM:使用分析、容量规划洞察、成本优化、安全合规状态
给 Scrum Master:团队访问已配置、看板配置选项、自动化规则、集成已启用
来自所有角色:用户访问请求、权限变更、应用安装请求、配置支持、事件报告
Atlassian MCP 集成
主要工具:Jira MCP、Confluence MCP
管理员操作:
- 通过 API 进行用户和组管理
- 批量权限更新
- 配置审核
- 使用报告
- 系统健康监控
- 自动合规检查
集成点:
- 支持所有具有管理员能力的角色
- 为 Jira 专家启用全局配置
- 为 Confluence 专家提供模板管理
- 确保高级 PM 可见组织健康状况
- 为 Scrum Master 启用团队配置
Workflows
User Provisioning
- Create user account:
admin.atlassian.com > User management > Invite users
- REST API:
POST /rest/api/3/user with
{"emailAddress": "...", "displayName": "...","products": [...]}
- Add to appropriate groups:
admin.atlassian.com > User management > Groups > [group] > Add members
- Assign product access (Jira, Confluence) via
admin.atlassian.com > Products > [product] > Access
- Configure default permissions per group scheme
- Send welcome email with onboarding info
- NOTIFY: Relevant team leads of new member
- VERIFY: Confirm user appears active at
admin.atlassian.com/o/{orgId}/users and can log in
User Deprovisioning
- CRITICAL: Audit user's owned content and tickets
- Jira:
GET /rest/api/3/search?jql=assignee={accountId} to find open issues
- Confluence:
GET /wiki/rest/api/user/{accountId}/property to find owned spaces/pages
- Jira projects:
Project settings > People > Change lead
- Confluence spaces:
Space settings > Overview > Edit space details
- Open issues: bulk reassign via
Jira > Issues > Bulk change
- Filters and dashboards: transfer via
User management > [user] > Managed content
- Remove from all groups:
admin.atlassian.com > User management > [user] > Groups
- Revoke product access
- Deactivate account:
admin.atlassian.com > User management > [user] > Deactivate
- REST API:
DELETE /rest/api/3/user?accountId={accountId}
- VERIFY: Confirm
GET /rest/api/3/user?accountId={accountId} returns "active": false
- Document deprovisioning in audit log
- USE: Jira Expert to reassign any remaining issues
Group Management
- Create groups:
admin.atlassian.com > User management > Groups > Create group
- REST API:
POST /rest/api/3/group with
{"name": "..."}
- Structure by: Teams (engineering, product, sales), Roles (admins, users, viewers), Projects (project-alpha-team)
- Define group purpose and membership criteria (document in Confluence)
- Assign default permissions per group
- Add users to appropriate groups
- VERIFY: Confirm group members via
GET /rest/api/3/group/member?groupName={name}
- Regular review and cleanup (quarterly)
- USE: Confluence Expert to document group structure
Permission Scheme Design
Jira Permission Schemes (
Jira Settings > Issues > Permission Schemes):
- Public Project: All users can view, members can edit
- Team Project: Team members full access, stakeholders view
- Restricted Project: Named individuals only
- Admin Project: Admins only
Confluence Permission Schemes (Confluence Admin > Space permissions):
- Public Space: All users view, space members edit
- Team Space: Team-specific access
- Personal Space: Individual user only
- Restricted Space: Named individuals and groups
Best Practices:
- Use groups, not individual permissions
- Principle of least privilege
- Regular permission audits
- Document permission rationale
SSO Configuration
- Choose identity provider (Okta, Azure AD, Google)
- Configure SAML settings:
admin.atlassian.com > Security > SAML single sign-on > Add SAML configuration
- Set Entity ID, ACS URL, and X.509 certificate from IdP
- Test SSO with admin account (keep password login active during test)
- Test with regular user account
- Enable SSO for organization
- Enforce SSO:
admin.atlassian.com > Security > Authentication policies > Enforce SSO
- Configure SCIM for auto-provisioning:
admin.atlassian.com > User provisioning > [IdP] > Enable SCIM
- VERIFY: Confirm SSO flow succeeds and audit logs show
saml.login.success events
- Monitor SSO logs:
admin.atlassian.com > Security > Audit log > filter: SSO
Marketplace App Management
- Evaluate app need and security: check vendor's security self-assessment at
marketplace.atlassian.com
- Review vendor security documentation (penetration test reports, SOC 2)
- Test app in sandbox environment
- Purchase or request trial:
admin.atlassian.com > Billing > Manage subscriptions
- Install app:
admin.atlassian.com > Products > [product] > Apps > Find new apps
- Configure app settings per vendor documentation
- Train users on app usage
- VERIFY: Confirm app appears in
GET /rest/plugins/1.0/ and health check passes
- Monitor app performance and usage; review annually for continued need
System Performance Optimization
Jira (
Jira Settings > System):
- Archive old projects:
Project settings > Archive project
- Reindex:
Jira Settings > System > Indexing > Full re-index
- Clean up unused workflows and schemes:
Jira Settings > Issues > Workflows
- Monitor queue/thread counts:
Jira Settings > System > System info
Confluence (Confluence Admin > Configuration):
- Archive inactive spaces:
Space tools > Overview > Archive space
- Remove orphaned pages:
Confluence Admin > Orphaned pages
- Monitor index and cache:
Confluence Admin > Cache management
Monitoring Cadence:
- Daily health checks:
admin.atlassian.com > Products > [product] > Health
- Weekly performance reports
- Monthly capacity planning
- Quarterly optimization reviews
Integration Setup
Common Integrations:
- Slack:
Jira Settings > Apps > Slack integration — notifications for Jira and Confluence
- GitHub/Bitbucket:
Jira Settings > Apps > DVCS accounts — link commits to issues
- Microsoft Teams:
admin.atlassian.com > Apps > Microsoft Teams
- Zoom: Available via Marketplace app
zoom-for-jira
- Salesforce: Via Marketplace app
salesforce-connector
Configuration Steps:
- Review integration requirements and OAuth scopes needed
- Configure OAuth or API authentication (store tokens in secure vault, not plain text)
- Map fields and data flows
- Test integration thoroughly with sample data
- Document configuration in Confluence runbook
- Train users on integration features
- VERIFY: Confirm webhook delivery via
Jira Settings > System > WebHooks > [webhook] > Test
- Monitor integration health via app-specific dashboards
Global Configuration
Jira Global Settings (Jira Settings > Issues)
Issue Types: Create and manage org-wide issue types; define issue type schemes; standardize across projects
Workflows: Create global workflow templates via
Workflows > Add workflow; manage workflow schemes
Custom Fields: Create org-wide custom fields at
Custom fields > Add custom field; manage field configurations and context
Notification Schemes: Configure default notification rules; create custom notification schemes; manage email templates
Confluence Global Settings (Confluence Admin)
Blueprints & Templates: Create org-wide templates at
Configuration > Global Templates and Blueprints; manage blueprint availability
Themes & Appearance: Configure org branding at
Configuration > Themes; customize logos and colors
Macros: Enable/disable macros at
Configuration > Macro usage; configure macro permissions
Security Settings (admin.atlassian.com > Security)
Authentication:
- Password policies:
Security > Authentication policies > Edit
- Session timeout:
Security > Session duration
- API token management:
Security > API token controls
Data Residency: Configure data location at admin.atlassian.com > Data residency > Pin products
Audit Logs: admin.atlassian.com > Security > Audit log
- Enable comprehensive logging; export via
GET /admin/v1/orgs/{orgId}/audit-log
- Retain per policy (minimum 7 years for SOC 2/GDPR compliance)
Governance & Policies
Access Governance
- Quarterly review of all user access:
admin.atlassian.com > User management > Export users
- Verify user roles and permissions; remove inactive users
- Limit org admins to 2–3 individuals; audit admin actions monthly
- Require MFA for all admins:
Security > Authentication policies > Require 2FA
Naming Conventions
Jira: Project keys 3–4 uppercase letters (PROJ, WEB); issue types Title Case; custom fields prefixed (CF: Story Points)
Confluence: Spaces use Team/Project prefix (TEAM: Engineering); pages descriptive and consistent; labels lowercase, hyphen-separated
Change Management
Major Changes: Announce 2 weeks in advance; test in sandbox; create rollback plan; execute during off-peak; post-implementation review
Minor Changes: Announce 48 hours in advance; document in change log; monitor for issues
Disaster Recovery
Backup Strategy
Jira & Confluence: Daily automated backups; weekly manual verification; 30-day retention; offsite storage
- Trigger manual backup:
Jira Settings > System > Backup system / Confluence Admin > Backup and Restore
Recovery Testing: Quarterly recovery drills; document procedures; measure RTO and RPO
Incident Response
Severity Levels:
- P1 (Critical): System down — respond in 15 min
- P2 (High): Major feature broken — respond in 1 hour
- P3 (Medium): Minor issue — respond in 4 hours
- P4 (Low): Enhancement — respond in 24 hours
Response Steps:
- Acknowledge and log incident
- Assess impact and severity
- Communicate status to stakeholders
- Investigate root cause (check
admin.atlassian.com > Products > [product] > Health and Atlassian Status Page)
- Implement fix
- VERIFY: Confirm resolution via affected user test and health check
- Post-mortem and lessons learned
Metrics & Reporting
System Health: Active users (daily/weekly/monthly), storage utilization, API rate limits, integration health, response times
- Export via:
GET /admin/v1/orgs/{orgId}/users for user counts; product-specific analytics dashboards
Usage Analytics: Most active projects/spaces, content creation trends, user engagement, search patterns
Compliance Metrics: User access review completion, security audit findings, failed login attempts, API token usage
Decision Framework & Handoff Protocols
Escalate to Atlassian Support: System outage, performance degradation org-wide, data loss/corruption, license/billing issues, complex migrations
Delegate to Product Experts:
- Jira Expert: Project-specific configuration
- Confluence Expert: Space-specific settings
- Scrum Master: Team workflow needs
- Senior PM: Strategic planning input
Involve Security Team: Security incidents, unusual access patterns, compliance audit preparation, new integration security review
TO Jira Expert: New global workflows, custom fields, permission schemes, or automation capabilities available
TO Confluence Expert: New global templates, space permission schemes, blueprints, or macros configured
TO Senior PM: Usage analytics, capacity planning insights, cost optimization, security compliance status
TO Scrum Master: Team access provisioned, board configuration options, automation rules, integrations enabled
FROM All Roles: User access requests, permission changes, app installation requests, configuration support, incident reports
Atlassian MCP Integration
Primary Tools: Jira MCP, Confluence MCP
Admin Operations:
- User and group management via API
- Bulk permission updates
- Configuration audits
- Usage reporting
- System health monitoring
- Automated compliance checks
Integration Points:
- Support all roles with admin capabilities
- Enable Jira Expert with global configurations
- Provide Confluence Expert with template management
- Ensure Senior PM has visibility into org health
- Enable Scrum Master with team provisioning