Browse documentation
Docs/Admin Toolkit/User tools

User tools

Copy someone's access to a new joiner, analyse your user base, and offboard a leaver properly.

Mirror User

What it does. Copies one person's groups and project roles to another person.

Use it when you get the request every administrator gets: “give the new person the same access as Marina”. Answering that by hand means checking every project role in every project.

Admin Toolkit → Mirror UserIllustration

Mirror User

Copy project roles and groups from one user to another.

Source User
Marina Rocha
Target User
Pedro Alves (new joiner)
Scan
Add (merge)
7
Groups
14
Role Assignments
9
Projects with Roles
142
Projects Scanned
Group membership could not be changed
Jira rejected 2 group change(s). Group membership can only be changed by a site admin. Project roles were still mirrored.
Verification
Project roles in sync2 groups missing on target
ModeWhat it doesWhen to use it
Add (merge)Adds the source person's groups and roles on top of whatever the target already has.Almost always. This is the safe choice.
Replace (overwrite)Removes the target from all current groups and roles first, then applies the source's.Only when you want an exact copy and you know what the target currently has. This is destructive.

After applying, the tool runs a Verification: it compares the two people and reports what matches, what is missing on the target and what exists only on the target. Read it. It is how you know the copy actually worked.

Jira may refuse the group changes, and that is normal
Group membership can only be changed by a site administrator. When Jira refuses, the tool tells you how many changes were blocked and confirms that project roles were still copied. Either re-run it signed in as a site admin, or send the group list to whoever has that right.

User Analysis

What it does. Analyses the CSV exports you can already download from admin.atlassian.com: the Managed Accounts export and the Users export. It validates the columns, tells you if one is missing, then produces a report.

Admin Toolkit → User AnalysisIllustration

User Analysis

Import Atlassian Admin CSV exports to analyse users, licences and generate recommendations.

Managed Accounts CSV
Drop file or click to browse
Valid · 1,402 managed users
Export Users CSV
Drop file or click to browse
Valid · 1,388 export rows
Inactivity Threshold (days)
90
Minimum: 30 days.
Analyze
1,402
Total Users
184
Unique Groups
6
Org Admins
37
Users with No Group
Report — 14 sections
1. Executive Summary
8. Org Admins
2. Activity Analysis
9. External Users
3. Product Segmentation
10. Group Analysis
4. License Waste
11. Service Accounts
5. Never-Accessed Users
12. Onboarding Timeline
6. Security Compliance
13. License Overview
7. Site Activity
14. Recommendations
Export PDF
  1. 1Download both CSVs from admin.atlassian.com: the Managed Accounts export and the Users export. The tool has the four-step instructions on screen, including which options to tick in the export dialog.
  2. 2Drop each file into its box. The tool validates the columns and names any that are missing.
  3. 3Set an Inactivity Threshold in days — minimum 30 — to decide what counts as dormant.
  4. 4Click Analyze.

What comes back is not a summary. It is a report you read top to bottom, and it is the part of the toolkit people underestimate.

The headline row
Product users, managed accounts, sites in the org, groups, org admins and Atlassian Guard billable seats — with a second line under each giving the number that qualifies it, such as how many of those accounts are disabled.
Three alerts, each of which opens a list
Ghost seat holders — active people holding billable seats who have never used any of them. Paid seats idle — the percentage unused past your threshold. Stale group members — suspended or deactivated users still sitting in groups, who regain access the instant somebody re-enables them. Click any of the three and the holder list loads at the bottom of the page.
License Optimization — paid seats only
The centre of the report: one row per product per site, with seats, active holders, a usage band breakdown, and a Reclaimable count. Filter by site and by product. A separate table lists what is included with your plans and therefore is not a seat you are paying for — Rovo, platform apps, features of a JSM tier — each with the reason.
Who holds paid seats
The people behind the numbers, with an onboarding note when a year's intake shows up as a wave of accounts that never signed in.
Directory activity
Last activity across the whole organisation directory, and how many accounts have never been active on any Atlassian product — usually provisioned-but-unused identities from a directory sync.
Security posture
From the managed-accounts export: how many accounts are under enforced SSO, how many sign in with an Atlassian password, how many of those passwords are weak, and how many email addresses are unverified.
Org admins, sites footprint and groups
Who holds organisation administration — with a badge counting the never-seen service accounts among them — how many sites the org contains including sandboxes and personal ones, and the group picture.
Recommended actions
Six, each with the number of users, seats, accounts or sites it would affect: reclaim never-used paid seats, trim idle access on the biggest products, clean groups of suspended users, review org-admin service accounts, close the non-SSO gap, and audit the site long tail.

Every drill-down list has Download CSV, and when the table shows only the first N rows it says so and confirms the CSV covers them all.

Ghost seat holders, service accounts, org admins — in that order
Ghost seat holders is your cheapest win: a seat bought and never once used. Service accounts is what stops you breaking an integration while chasing that win. Org admins is the one that starts an uncomfortable but necessary conversation.
Everything here happens in your browser
The two CSVs are parsed and analysed in the page. Nothing is uploaded, nothing is stored by the app, and no resolver is called — which is also why this one tool keeps working when the app has no licence.
This tool or License Waste Manager?
User Analysis reads CSV files and needs no credentials. Good for a one-off review, or when you cannot get an organisation API key. License Waste Manager connects to the organisation API, sees live activity data, and can act on what it finds on a schedule.

User Offboarding

What it does. Finds everything a departing person owns — projects they lead, components, dashboards, filters, permission grants, automation rules, boards, assigned issues — and transfers what can be transferred to a replacement.

Why. Deactivating the account is the easy part. What breaks is everything that pointed at them.

Admin Toolkit → User OffboardingIllustration

User Offboarding

Find and transfer all ownership and role assignments from a departing user to a replacement.

User to Offboard
Carla Nunes
Select replacement user
Marina Rocha
Select categories to scan
Project & Component Leads
Dashboards
Filters
Permission Schemes
Project Roles
Assigned Issues
Scan
Scan complete
CategoryFoundAction
Project Leads4Transfer
Component Leads11Transfer
Dashboards6Transfer
Filters23Transfer
Permission Grants3Info only — manual transfer required
Automation Rules2Info only — manual transfer required
Assigned Issues184
Reassign to replacement
What a scan cannot see
Objects the app cannot enumerate — some automation rules, third-party app data and personal boards — are reported for manual handling rather than silently skipped.
Apply Transfer
  1. 1Pick the user to offboard.
  2. 2Select the categories to scan. There are nine — project leads, component leads, dashboards, filters, permission grants, project roles, notifications, security levels and boards — plus their assigned issues. Select All takes the lot.
  3. 3Click Scan. Results are grouped by category with a count for each.
  4. 4Choose the replacement user.
  5. 5Per section, choose Transfer to the replacement user or Remove without a replacement. They are not the same decision, and for a permission grant or a notification recipient the second is often the right one.
  6. 6For issues, choose whether to reassign them to the replacement user. This is slow for large numbers, up to a maximum of 10,000.
  7. 7Click Apply Transfer. The tool reports what succeeded and what was skipped, per category.
It tells you what it cannot do, and what it could not see
Some things cannot be transferred automatically: certain automation rules, permission grants that name the person directly, third-party app data. Those are listed as info only — manual transfer required, under a heading that says exactly that. Separately, a What a scan cannot see panel names the blind spots — among them private filters belonging to other people, which Jira's API does not expose to anybody. A tool that silently skipped either would be worse than useless during an offboarding.
Run the scan before the account is deactivated
Once an account is gone, several of these relationships are much harder to enumerate. Make the scan part of your leaver checklist, on the day.

Something missing or wrong on this page? Tell us in the support portal or email contact@synapseoasis.com.