RECOMMENDATION
For each permission you restrict, consider what risk or problem you’re trying to address. Does JIRA already mitigate the risk (by logging user actions, for example?) Is there a specific compliance requirement to satisfy? Can the issue be solved with user education instead?