Skip to main content
This page lists every permission each Raley app requests from your Atlassian site, app by app. The lists are copied verbatim from each app’s Atlassian Marketplace listing (Privacy & Security tab) on August 19, 2026. Permission lists belong to a specific app version, so the listing is always the authoritative source: each section below links to the live tab so you can verify today’s list in one click.

How to read this page

  • A permission is what a Jira admin sees and grants when installing the app. It is a declared ceiling, not a log of activity: the list shows the most access the app can request.
  • Our listings show permissions in 2 formats. Some apps declare classic site-wide scopes such as Read, Write, and Admin, which Atlassian defines in its scopes documentation. Others declare granular permission statements that describe one capability each. The format follows from how the app integrates with Atlassian; the platform’s concepts page explains the difference.
  • This page covers access permissions only. For where data is hosted, encrypted, and processed, see the data security and privacy statement.

Raley Email Notifications for Jira & JSM

Email Notifications declares 18 granular permissions. Verify the live list on the Marketplace Privacy & Security tab. Read access
  • View user information in Jira that the user has access to, including usernames, email addresses, and avatars.
  • View user groups.
  • View email addresses of all users regardless of the user’s profile visibility settings.
  • Read Jira project and issue data, search for issues, and objects associated with issues like attachments and worklogs.
  • View project properties.
  • Read customer request data, including approvals, attachments, comments, request participants, and status/transitions. Read service desk and request types, including searching for request types and reading request type fields, properties and groups.
  • Read Assets objects, their attributes values and details.
  • Read Assets object types and their attributes.
  • Get list of all Assets object type attributes for a schema or an object type.
  • Get list of or details of individual schemas in Assets.
Write access
  • Create and edit issues in Jira, post comments as the user, create worklogs, and delete issues.
  • Create and update project properties.
  • Create and edit customer requests, including add comments and attachments, approve, share (add request participants), subscribe, and transition.
Administration
  • Take Jira administration actions (e.g. create projects and custom fields, view workflows, manage issue link types).
  • Create, manage and delete customers and organizations. Add and remove customers and organizations from service desks.
App runtime
  • Access and interact with your data from outside of Atlassian.
  • Access and interact with your data as the logged-in user from outside of Atlassian.
  • Read and write to app storage service.

What Email Notifications uses this access for

Per the permissions justification published on the listing:

Raley Intake Forms for Jira & JSM

Intake Forms declares the 6 classic site-wide scopes. Verify the live list on the Marketplace Privacy & Security tab. In practice, Intake Forms reads issue and project metadata needed to create issues, creates issues (with attachments) from form submissions, and creates customers in JSM. The scope-by-scope breakdown lives in the data security and privacy statement.

Raley Procurement - Intake & Approval Orchestration for JSM

Procurement declares 4 site-wide scopes. Verify the live list on the Marketplace Privacy & Security tab.

Raley Bookman - Asset Reservation for JSM

Bookman declares 13 granular permissions. Verify the live list on the Marketplace Privacy & Security tab. Read access
  • Read Assets objects, their attributes values and details.
  • Read Assets object types and their attributes.
  • Get list of all Assets object type attributes for a schema or an object type.
  • Get list of or details of individual schemas in Assets.
  • View user information in Jira that the user has access to, including usernames, email addresses, and avatars.
  • Read Jira project and issue data, search for issues, and objects associated with issues like attachments and worklogs.
  • Read customer request data, including approvals, attachments, comments, request participants, and status/transitions. Read service desk and request types, including searching for request types and reading request type fields, properties and groups.
Write access
  • Create and edit issues in Jira, post comments as the user, create worklogs, and delete issues.
  • Create and edit customer requests, including add comments and attachments, approve, share (add request participants), subscribe, and transition.
Administration
  • Take Jira administration actions (e.g. create projects and custom fields, view workflows, manage issue link types).
App runtime
  • Access and interact with your data from outside of Atlassian.
  • Access and interact with your data as the logged-in user from outside of Atlassian.
  • Read and write to app storage service.
The permission list mirrors the app’s job: Bookman reads your Assets schemas and objects to show what can be reserved, reads and writes JSM requests and Jira issues to handle reservations, and keeps its own data in the Atlassian app storage service.

Raley Favourites for Jira

Favourites declares 3 permissions, the smallest footprint of the 5 apps. Verify the live list on the Marketplace Privacy & Security tab. Per the listing justification, no data leaves the Atlassian platform: the app stores only issue IDs, and only in Atlassian storage.

When permission lists change

Permission lists belong to app versions, and the Marketplace listing always shows the list for the latest version. This page is reviewed against the listings on the date in the footer; if the two ever disagree, the listing wins.

What this page does not answer


Last updated: August 19, 2026