One Attio connection per Jira project

Two people usually want opposite things here. A team lead wants to try the card on one queue without asking anybody's permission, and a site administrator wants to know which projects are sending customer data to which CRM workspace. The per-project design is what lets both happen.

A key belongs to the Jira project it was pasted into, and to nothing else. Different projects on the same site can be connected to different Attio workspaces, and none of them can see another's key.

#What per project means

  • The project settings page is the only place in the app that accepts a key. The setup step says so: "This key belongs to this Jira project alone. Other projects on this site connect their own workspace, and a site admin can see that a connection exists but never the key itself."

  • There is no site-level key and no site-level connection to inherit, so a project that has not connected shows the card nowhere regardless of what its neighbours have done.

  • The key is filed against the project rather than against its project key, so renaming a project does not orphan the credential or make a connected project look unconnected.

  • The key is never sent back to the browser, on any screen, for anybody.

#What a site administrator sees

A read-only site-level page called "Attio for Jira" lists every project on the site that is connected, under the heading "Attio connections". The page describes its own limits: "Every project on this site that is connected to an Attio workspace. Attio keys belong to the project that pasted them, so they are never entered or shown here: this page is for seeing the estate, not for administering credentials you do not hold."

Column

What it holds

Project

The Jira project. A project Jira no longer returns a name for reads "Unknown project".

Attio workspace

The workspace the key belongs to, recorded when it was stored. A connection made before the app recorded it reads "Not recorded".

Object

The record type as it was named when the project chose it, or "Not chosen".

Attributes shown

How many attributes that project's card shows.

Connected by

The person's name where Jira will resolve it, "Unknown user" where it will not, and "Not recorded" for a connection made before the app started recording it. A raw account identifier is never displayed.

Connected

When the key was stored.

Shown on

The placements the project chose, named as Issue panel, Activity tab or Issue sidebar. A connected project that has chosen none reads "Nowhere", which is an ordinary state rather than a fault.

A way into that project's settings

An "Open settings" link. Where the app cannot build a working link it shows the path in words, "Project settings, Apps, Attio", rather than offering one that would fail.

#What the page cannot do

It cannot enter, reveal, rotate or clear a key, and there is nothing on it that could display a credential. A site administrator sees which projects are sending customer data to which CRM workspace, and nothing more. Both the page and every request behind it are limited to Jira administrators, checked on the server rather than by hiding the page.

#Limits of the list

  • Up to 2,000 connected projects are held. Past that the card keeps working normally in every project and only the list stops growing.

  • Names are resolved for up to 400 distinct connecting administrators in one page load. Rows beyond that read "Unknown user", and a resolved name is remembered for a day, so somebody who changes their display name can appear under the old one for up to twenty-four hours.

  • A project is listed as soon as a key is stored for it, even if setup is unfinished, and drops off when the key is removed.

  • The list can be up to about half a minute behind a change made a moment earlier.

#When a project goes away

Deleting a Jira project does not remove its Attio connection, so the row survives with the project name missing. That is deliberate: it is how a leftover connection can be seen and cleaned up rather than sitting invisibly on the site.

Clearing a connection properly is done in the project itself, with Reset to defaults on the Connection tab, which "Removes the API key, the record type, the matching attribute, every field on the card, the linked record settings, the audience and the placements, and clears everything this app has cached about your Attio records. The card comes off every issue in this project and setup starts again from the beginning. Nothing in Attio itself is changed or deleted." A key that is no longer wanted still has to be revoked in Attio separately.


#A few things worth knowing

  • A row on the site list is not proof that agents are seeing a card. A project appears there as soon as it holds a key, whether or not anybody finished the other five steps.

  • A deleted Jira project keeps its row, without a project name. That is the only trace left of a connection whose project has gone, so it is worth clearing rather than ignoring.

  • Resetting a project removes what this app stored in Jira and nothing else. The Attio key itself stays live in Attio until somebody revokes it there.



One key, one project, and a list that admits what it does not know.