Licensing & Permissions
Overview
Use this guide to find information about P1 application access, licenses, roles, and permissions.
This guide covers applications and services across IL2, IL4, and IL5 environments, including Jira, Confluence, GitLab, SonarQube, Argo CD, and Iron Bank.
Select the option below that best matches what you need to do.
Choose your issue
| Issue | What You Need to Do |
|---|---|
| Request Application Access | Request access to one or more P1 applications or environments. |
| Request an Application License | Request a paid license, elevated role, or specialized license for an existing application user. |
| Modify or Remove a License | Change, downgrade, or remove an existing application license or access level. |
Before you request access
Before submitting an application-access or licensing request, make sure you meet the following requirements.
The user must have logged in to P1
The user must log in to P1 at least once before submitting an access request.
If the user has never logged in to the portal, their name may not appear in the user-selection fields on request forms.
Confirm that you are authorized to submit the request
Request submission permissions depend on the type of access being requested.
| Request Type | Authorized Submitter |
|---|---|
| Standard application access | Authorized Onboarding Supervisor |
| Multi-application access | Authorized Onboarding Supervisor |
| Service Desk Agent access | Authorized Onboarding Supervisor |
| Argo CD access | Authorized Onboarding Supervisor or Team Lead |
| SonarQube access | Authorized Onboarding Supervisor or Team Lead |
| Iron Bank access | Authorized Onboarding Supervisor |
WARNING
Important: If you are not an authorized submitter, contact your organization's Onboarding Supervisor or Team Lead for assistance.
Request application access
Requesting application access provisions the standard access or license associated with the requested application when the request is approved.
Use the Request Application Access article for instructions and approved request forms.
Applications may include:
- Jira
- Confluence
- GitLab
- IL2 Staging
- IL4 Staging
- IL5 Staging
- SonarQube
- Argo CD
- Iron Bank
Access availability depends on the user's organization, authorization, environment, and approved licensing.
Application access by environment
P1 applications may be available in different IL environments.
| Environment | Applications |
|---|---|
| IL2 | Jira, Confluence, GitLab, IL2 Staging |
| IL4 | Jira, Confluence, GitLab, IL4 Staging |
| IL5 | Jira, Confluence, GitLab, IL5 Staging |
Not every user or organization is authorized for every environment or application.
Request an application license
Some applications and roles require paid licenses.
Use Request an Application License when you need:
- A paid application license.
- An elevated application role.
- A specialized license.
- Jira Service Desk Agent access.
- Additional licensing for an existing application user.
To request an application license, contact the BAM team.
For Jira Service Desk Agent requests, provide the organization's PBO or CTT number when required. If the number is unavailable, provide the applicable major command or organization, such as AMC, AETC, or ACC.
Mattermost licensing
P1LM manages Mattermost licensing.
If you cannot access the P1LM, submit a request through the approved assistance process:
Authorized Onboarding Supervisors may also use the approved supervisor documentation and Customer Experience resources for assistance.
Onboarding supervisors can schedule office hours for help navigating P1LM, managing users, and tracking license allocation.
Understand roles and permissions
Application roles determine what a user can view, create, modify, or manage.
WARNING
Do not request more access than the user needs to perform their role. Some roles provide administrative or elevated permissions.
Jira roles
| Role | Key Capabilities | Best Suited For |
|---|---|---|
| Reporter | Can view projects and log/create new issues; cannot edit work logs, be assigned tickets, or transition states. | Stakeholders, testers, or users submitting and tracking bugs. |
| Developer / Member | Can create, edit, assign, and log work against issues; move tickets through workflow transitions and manage board sprints. | Active software engineers, analysts, and project contributors. |
| Project Administrator | Full control over project-level settings: manages project roles, component/version leads, workflow associations, and custom permissions. | Project Leads, Scrum Masters, and Technical Team Leads. |
| Jira Service Desk Agent | Requires Paid License. Can view customer portals, manage service queues, transition tickets, respond internally/externally, and execute SLA workflows. | Support desk staff and customer-facing service team members. |
Confluence Data Center: Core Space Roles
| Role | Key Capabilities | Best Suited For |
|---|---|---|
| Viewer / Reader | Can view space pages, view attachments, and leave page comments. Cannot create or edit content. | General team members needing read-only documentation access. |
| Developer / Contributor | Can create, edit, update, attach files, and manage page content within the space. | Team members actively writing specifications, guides, and notes. |
| Space Administrator | Manages space settings, configures sidebar links/themes, manages page restrictions, and assigns user/group permissions. | Space owners, Team Leads, and Documentation Managers. |
| Anonymous / Unlicensed User | Restricted view-only access configured specifically for public or cross-portal documentation spaces. | External stakeholders or portal customers accessing public knowledge bases. |
Role and permission changes
Changes to existing Jira Project or Confluence Space roles may require prior authorization.
Before requesting a role or permission change, obtain approval from the applicable:
- Jira Project Administrator or Project Lead.
- Confluence Space Administrator or Space Lead.
Requests requiring prior authorization may be placed on hold until we verify the required approval.
Modify or remove a license
Request to modify or remove a license when an existing user:- No longer needs a license.
- Needs a lower access level.
- Needs a different license or role.
- Is changing roles.
- Is leaving a project or organization.
- No longer requires access to an application.
Removing a license or application access does not necessarily remove the user's P1 account.
For complete user offboarding, see our Offboarding Guide.
Common licensing errors
Sorry, you have not been granted access to that application group
This message generally indicates that the account does not have a valid license or access assignment for the requested application.
Before submitting another request:
- Confirm that you are using the correct P1 account.
- Confirm that you are accessing the correct application and environment.
- Confirm that the appropriate application access or license has been requested.
- If applicable, ask your Onboarding Supervisor to verify the user's license or access.
- If the issue continues, contact the Help Desk.
For Mattermost, authorized Onboarding Supervisors should verify and manage licensing through the P1LM when applicable.
For other applications, use the approved license or application-access request process.
Processing times
Approved application and licensing requests may be processed automatically.
When an automated process is used, access may become available within approximately 10 minutes after approval. Processing times may vary by application and request type.
If the expected access does not appear after the applicable processing period, contact the Help Desk.
Contact the Help Desk
If you are unable to request or receive the appropriate application access or license, contact the Help Desk.
When requesting assistance, provide:
- User's name.
- P1 username, if known.
- Email address associated with the P1 account.
- Application or service.
- Environment, if applicable.
- Requested role or license.
- Request or ticket number, if available.
- Exact error message.
- Screenshot, when available.