Azure DevOps - 限制特定工作项类型(WIT)的写入权限:仅允许PO和SM编辑用户故事
Great question! Restricting backlog edit access to only Product Owners (POs) and Scrum Masters (SMs) is a smart way to keep your product backlog focused, aligned with team goals, and free from unapproved changes. Let’s walk through how to set this up for the two most popular Scrum tools—Jira and Azure DevOps—since you didn’t specify which platform your team uses.
Step 1: Create Dedicated User Groups
First, group your POs and SMs together for streamlined permission management:
- Go to Jira Settings > User Management > Groups
- Create two groups: e.g.,
Team-POsandTeam-SMs - Add all relevant POs and SMs to their respective groups
Step 2: Access Your Project’s Permission Scheme
- Navigate to your Scrum project, then go to Project Settings > Permissions
- If you’re using a shared permission scheme, ensure it only applies to projects needing this restriction (or create a new scheme for this project to avoid affecting other teams)
Step 3: Lock Down the "Edit Issue" Permission
This is the core step to restrict edits:
- Locate the Edit Issue permission in the list
- Remove any existing groups/roles that have this access (like
DevelopersorAll Users) - Add only your
Team-POsandTeam-SMsgroups to this permission - Pro tip: If you want to let other team members suggest changes without editing directly, keep the Create Issue permission open—they can submit new user stories or comments, and the PO/SM can review and merge updates as needed.
Optional: Restrict to User Story Issue Type Only
If you want this restriction to apply only to user stories (and let developers edit other issue types like bugs), use Issue Security Schemes:
- Create a security level accessible only to POs/SMs
- Apply this security level to all user stories in your backlog, either manually or via an automation rule.
Step 1: Create Security Groups
- Go to Project Settings > Permissions > Security Groups
- Create two groups:
Product OwnersandScrum Masters - Add the appropriate team members to each group
Step 2: Set Backlog Item Permissions
- Stay in Project Settings > Permissions, scroll to the Backlogs section (or search for "Backlog Items")
- Select the backlog level you want to restrict (e.g., "Product Backlog Items")
- In the right-side permissions panel, find the Edit permission
- Remove access from broad groups (like "Contributors") and grant it only to your
Product OwnersandScrum Mastersgroups
Whichever tool you use, test the setup with a non-PO/SM account—try editing an existing user story to confirm they get a permission error. This ensures your configuration works as intended before rolling it out to the whole team.
内容的提问来源于stack exchange,提问作者user2717436

