# Work Item Selector for Jira Cloud

Allow users to select work items based on Jira Query Language (JQL).

A single- or multi-select field that offers only the work items a JQL query returns, and the JQL can take dynamic values from the user editing the field and from the work item the field sits on. It supports advanced search, automation, workflow validation and native work item linking, all of it with a native Atlassian look and feel.

- **Host:** Jira Cloud
- **Version:** v3.0.0
- **Documentation:** https://oktul.com/docs/plugins/work-item-selector/install/

## Native work item linking needs a link type, and it offers every work item the user can see.

Jira’s own work item link is instance-wide. An editor searching from a service desk ticket is offered every work item they can read, across every project on the site. On an enterprise instance that is tens of thousands of them, so the field they were given to record one relationship becomes a search problem.

The only option so far was to use that link and hope it worked. What was missing is a field whose search scope is a property of the field rather than of the instance.

## Four things it does that the built-in linking does not.

Each one is set where it belongs in Jira, on the field context or on the workflow, so two fields on the same screen can behave differently without anyone negotiating a global setting.

### Set the search scope in JQL

A Jira administrator sets the JQL on each field context, and that JQL can take dynamic values from the user editing the field and from the work item the field sits on.

### Show the columns that make the choice obvious

One to seven columns on the selected work item cards: work type, key, summary, priority, status, assignee and custom fields. Enough for an editor to tell two similar work items apart without opening either.

### Readable and writable from the rest of Jira

Automation actions set the field, and the application adds JQL functions so the field can be filtered, boarded and reported on across projects like any other Jira data.

### Require the field before a transition

A workflow validator holds a transition until the selection satisfies the rules you set: a selection exists, the selected work items are in allowed statuses, they belong to allowed projects, and the selection creates no circular dependency back to the work item. The administrator writes the message a blocked person sees.

## Every step is in the product you already administer.

1. **Install from the Marketplace** One install, and the setup screens are the Atlassian ones you already use. There is no server to deploy and nothing to host, because the application runs on Forge inside your Atlassian Cloud site.
2. **Create the field** A Jira administrator creates the field from one of two types, Work Item Selector (Single Select) or Work Item Selector (Multi Select).
3. **Set the scope on the field context** Which JQL the field searches, which columns appear on the selected work items, and whether the field respects each user’s permissions. All of it in Jira’s own settings.
4. **Add the field to a screen** Settings, then Work items, then the screen schemes the work types use, exactly as with any other Jira custom field.

## Host platform and compatibility.

- **Host product:** Jira Cloud
- **Runtime:** Atlassian Forge
- **Automation:** Supported
- **Data residency:** Your instance’s

## Nothing leaves your Atlassian instance.

The application runs inside your Atlassian Cloud instance, and the values it stores stay there. No third party can read them, and neither can we.

- **Egress:** None. No external permissions declared
- **Storage:** Atlassian storage, inside your instance
- **Oktul infrastructure:** None in the data path
- **Sub-processors:** None
- **Analytics or telemetry:** None collected

**Scope / What it is for**

- `read:jira-work` — Run the JQL scope query and read the fields each work item card draws.
- `write:jira-work` — Save a selection, maintain the relationship index, and keep a native work item link in step.
- `read:jira-user` — Draw the assignee and other user columns as avatars.
- `manage:jira-configuration` — Read the field context configuration and the site's field catalogue. The broad one, and the privacy policy says why it is not yet the granular replacement.
- `storage:app` — Store each field context's own configuration.
- `read:cmdb-object:jira` — Resolve an Assets object to its label so it can be shown as a column. Every call is optional and fails silently, so a site without Assets is unaffected.
- `read:servicedesk-request` — Establish which requests are a person's own on the Jira Service Management portal, as the customer, because a portal customer holds no Jira application access.

**Runs on Atlassian.** Atlassian grants this badge per application, to apps that store data only inside Atlassian and declare no external permissions.

[What the programme requires](https://developer.atlassian.com/platform/marketplace/runs-on-atlassian/)

**CSA STAR Level 1.** This application is listed in the Cloud Security Alliance STAR Registry at Level 1, which is a self-assessment. We completed the CAIQ Lite questionnaire, all 138 questions, and published it for anyone to read.

[Read the assessment on the STAR Registry](https://cloudsecurityalliance.org/star/registry/oktul-llc/services/work-item-selector-for-jira-cloud-issue-picker)

## What runs before this application ships.

- **Automated tests:** 843. Run on every release, including injection and security suites.
- **Test suites:** 36. Behaviour, configuration, permissions and input handling.
- **Work items per field:** 100. The ceiling is Atlassian Forge’s, not ours.

## The limitations, next to the features they bound.

If any of these matter to your configuration, they are better found here than after you install.

### How many work items can one field hold?

Up to 100. The limit comes from the Atlassian Forge runtime rather than from a choice of ours. If your use case needs more than 100 in a single field, this application will not do it.

### Does it run on Data Center or Server?

No. It is a Forge application and Forge is Cloud only. There is no Data Center build and none is on the roadmap.

### Why does the picker dropdown show plain text rather than icons?

Because Atlassian’s UI Kit Select accepts only a string for an option label, so a work type icon, a status pill or an avatar cannot be drawn inside the menu. The columns are joined with a middle dot instead. The richer treatment appears on the selected work item cards, where the component does allow it. It is the cost of building on Atlassian’s own components rather than a custom interface, which is what keeps the field looking like the rest of Jira.

### Is the JQL scope a permission boundary?

Not on its own. The JQL controls which work items the field offers, not what a user is allowed to see. An administrator can set the field context to respect each user’s permissions, and where it is not set that way, every user sees every work item the JQL returns whatever their own permissions are.

## What administrators ask before installing.

### Who needs to install it?

An organisation administrator, from the Atlassian Marketplace listing. Because the application declares no external permissions there is no consent screen for external data access. A Forge application can take up to a minute to become available across a site after installation.

### What happens to our data if we uninstall?

Uninstalling removes the field type, and the values stored against it are removed with it, exactly as with any other Jira custom field. That is Jira’s behaviour rather than ours and we cannot restore them afterwards, which is why the documentation tells you to export first if you need them.

### Does it replace Jira’s own work item links?

No. It is a custom field alongside them, so existing links keep working and nothing has to be migrated. Use the built-in link where instance-wide search is what you want, and this field where the scope needs to be a property of the field.

### Will this application be supported when Atlassian changes the platform?

Yes, that is what the support covers. Problems go through our Help Center, where a request gets a reference and a service-level agreement measuring the response, and the same channel takes feature requests and demo bookings.

---

## Published by

- Oktul OÜ (Oktul LLC)
- Oktul OÜ · Reg. nr 17589681 · Tallinn, Harjumaa, Estonia
- Email: hello@oktul.com
- Web: https://oktul.com/
- Atlassian Marketplace: https://marketplace.atlassian.com/vendors/534484195
- Estonian: https://oktul.com/et/
