Bitbucket logo

Bitbucket

Access
Code Repository

Mycroft records pull request approvals and branch restrictions from Bitbucket as change management evidence.

Every merge to a restricted branch carries the approver and timestamp an auditor asks for. Mycroft stores those records and includes workspace and repository permissions in access reviews.

How Mycroft connects to Bitbucket

How it connects
A workspace administrator authorizes Mycroft through Bitbucket OAuth.
What Mycroft can access
Granted scopes are account, repository, pullrequest, project and issue, which include repository read access. Mycroft runs a read-only pull model and does not write back.

Which controls Bitbucket evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Bitbucket to satisfy it. Collection runs on a schedule and every result is timestamped.

Bitbucket compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Bitbucket
SOC 2CC8.1Changes are authorized, reviewed and approved before release.Pull request records with approvers, merge checks satisfied, build status and merge timestamp for each change to a restricted branch.
SOC 2CC6.1Logical access controls restrict access to information assets.Workspace member and group inventory with repository-level permissions, and admin holders identified.
SOC 2CC6.3Least privilege is enforced and access is removed on departure.Workspace membership reconciled against the current workforce roster, surfacing accounts belonging to former staff or expired contractors.
ISO 27001A.8.4Access to source code is restricted.Per-repository permission matrix across users and groups, with repository visibility settings.
ISO 27001A.8.32Changes are controlled through change management procedures.Branch restriction configuration (required approvals, required successful builds, restrictions on direct pushes and rewriting history) evidenced continuously.
ISO 27001A.5.17Authentication information is managed securely.Two-factor authentication enforcement status on the workspace, with members lacking it identified.
ISO 27001A.8.31Development, test and production environments are separated.Deployment environment configuration with environment-level approval and restriction settings.

What Mycroft collects automatically

Gathered from Bitbucket on a schedule, dated and stored against the controls above.

  • Pull request history with approvers, merge checks and merge timestamps
  • Branch restriction rules on production branches, including who may bypass them
  • Workspace member and group inventory with repository permissions
  • Repository visibility settings across the workspace
  • Two-factor authentication enforcement on the workspace
  • Deployment environment configuration and approval settings
  • App password and access token inventory at workspace level

Manual work this removes

The tasks that disappear from someone's quarter once Bitbucket is connected.

  • Building a repository-by-repository permission list for the quarterly review
  • Screenshotting branch restrictions for the change management walkthrough
  • Exporting pull request approvals for the auditor's sample
  • Checking two-factor authentication enrolment member by member

Bitbucket and Mycroft: frequently asked questions

The integration targets Bitbucket Cloud. Bitbucket Data Center is handled through a scoped API connection instead, which needs network access to the instance.
They cover different halves of the same control. Jira evidences that a change was requested, prioritized and authorized; Bitbucket evidences that it was reviewed, approved and merged. Mycroft links the two through the issue key in the branch or pull request, so a sampled change presents as one record with both halves attached.
The granted scopes are account, repository, pullrequest, project and issue, so repository read access is included. Mycroft runs a read-only pull model and does not store your code or write back.
Yes. Branch restriction configuration includes any exemption list, and Mycroft records who holds a bypass. An exemption that exists but was never documented as an exception is exactly the kind of finding an access review is meant to surface.

We turn the compliance nightmare into a dream

Talk to us