LicenseGuard for Jira

JiraForgeComing soon

Stop paying for Jira seats nobody is using

Current Version
v4.0.0
Updated Jun 17, 2026
Notify me when it ships
Launching soon

Get notified when LicenseGuard for Jira ships

One email when it's live on the Atlassian Marketplace. No follow-ups, no newsletter — just the launch ping.

What it does

Stop paying for Jira seats nobody is using

Every growing Jira instance accumulates ghost accounts — people who left, switched roles, or stopped using Jira months ago. Each quietly burns through your Atlassian licence budget. LicenseGuard finds them automatically: a scan identifies inactive accounts against thresholds you set, calculates what they cost you each year, and flags the risky ones (admins, users with open work) so you don't reclaim a seat by mistake. When you're ready, it takes you straight to Atlassian's admin console to deactivate the accounts you've reviewed, and records every safelist change and removal hand-off in an activity log. And it's completely free.

Inside the app

  • Automated weekly or monthly scans that detect inactive and ghost accounts
  • Cost calculator showing what you're spending on unused licences each year
  • One-click hand-off to Atlassian's admin console to deactivate the accounts you've reviewed
  • Activity log of safelist changes and removal hand-offs, with timestamps and the admin who made them
  • Dashboard with inactive-account trends and savings over time
  • Configurable thresholds and a safelist for service accounts and protected users
  • Free — every feature included, with no external servers and no data leaving your Atlassian tenancy

How it compares

We're not the first to think about this

Most teams reach for a manual audit or a homegrown JQL script. Here's how License Guard stacks up against the alternatives we've seen most often.

CapabilityManual auditJQL / scriptingLicense Guard
Time to scan a 200-user instance
2–4 hours
~1 hour to write
Under 30 seconds
Bulk deactivation in one click
No
You build it
Yes
ROI / cost-saving calculator
Spreadsheet
You build it
Built in
Tamper-proof audit log
No
You build it
Yes
Sandboxed (no external egress)
N/A
Depends
Forge-native
GDPR personal-data hooks
No
You build them
Yes
Setup time
Every audit
Days
Under 5 min
Cost
Hidden — admin time
Hidden — dev + maintenance
From $0.50/user/mo

Time estimates based on the patterns we've seen most often across mid-sized Jira instances. Your mileage will vary.

ROI calculator

How much could you save?

Adjust the sliders to estimate your annual savings from reclaiming inactive Jira seats. The math is conservative — most teams find more inactive accounts than they expect.

Potential annual savings

$1,260

Estimate only. Actual savings depend on your seat-cleanup policy and the deactivation paths your admins choose.

Common questions

Things admins ask before installing

How does License Guard identify “ghost” users?
It reads each user's last-login timestamp from Jira's audit-log API and classifies them by configurable thresholds — Active (under 90 days by default), Dormant (90–180 days), Ghost (over 180 days). You set the cut-offs that match your policy.
What if it deactivates an active user by accident?
Three guardrails. First, the bulk-deactivate flow shows you every user in the selection with their last-login date before you confirm. Second, every action is written to a tamper-proof audit log keyed to the admin who triggered it. Third, deactivated users can be reactivated with one click from Atlassian's standard user-management screen — the user re-appears with the same permissions they had before.
What permissions does it need? Where is the data going?
The manifest declares read:jira-user, read:audit-log:jira, manage:jira-configuration, and storage:app — the minimum needed to list users, fetch login history, deactivate, and store config. License Guard runs entirely in Atlassian's Forge sandbox: zero external egress. No data leaves your Atlassian Cloud tenant.
Is it GDPR-compliant?
Yes. License Guard implements Atlassian's onPersonalDataRequest and onPersonalDataDelete privacy hooks. The audit log only retains accountId references and action metadata — no email addresses, names, or other PII beyond what Atlassian itself stores. When a user is deleted from your instance, License Guard's local state for them is cleared automatically.
How does pricing work?
Free tier: scan, classify, and view savings estimates as much as you want. Paid tier: bulk deactivation, scheduled scans, audit-log retention, exclusion rules, CSV export. Billed per-user/month through the Atlassian Marketplace, starting from $0.50/user/mo. Annual plans available at a discount.
Does it work for Jira Service Management?
Yes. JSM uses the same user model as Jira Software/Core, so License Guard sees agent and customer accounts the same way. Agent licenses (the ones that actually cost money) are detected and reported separately from customer accounts.
What about service accounts and bots — will it flag those?
Configure exclusion rules. You can exclude by username pattern (e.g. *_bot), by group membership (e.g. "Service Accounts"), or by individual accountId. Excluded accounts are skipped from every scan and never appear in deactivation suggestions.
Can I run it on a schedule?
Daily, weekly, or monthly scheduled scans are available on the paid tier. Each scan generates a savings report you can email to a distribution list, post to a Slack channel via a webhook, or just view in the dashboard.

Question we didn't answer? [email protected] we reply within 24 hours.

We built License Guard after noticing we'd been paying for two years' worth of inactive Jira seats — accounts of contractors who'd left, founders who'd sold, ghost addresses still on the licence count. The audit was too tedious to do manually, and the JQL scripts we tried missed half the patterns. The first time we ran the proto-version on our own instance, it found 23 seats we hadn't touched in over a year.

Every Jira admin we've shown it to has the same reaction: "why isn't this just built into Jira?" It probably should be. Until then, we're shipping it as a Forge app — the same architecture and discipline we use for the other apps in our suite.

L
Luis Lerones
Founder, EvolRed · Building from London & Madrid

Need a custom plugin for your team?

We build private Atlassian plugins tailored to your workflows.