
Bitbucket
Access
Code Repository
Mycroft records pull request approvals and branch restrictions from Bitbucket as change management evidence.
Every merge to a restricted branch carries the approver and timestamp an auditor asks for. Mycroft stores those records and includes workspace and repository permissions in access reviews.
How Mycroft connects to Bitbucket
- How it connects
- A workspace administrator authorizes Mycroft through Bitbucket OAuth.
- What Mycroft can access
- Granted scopes are account, repository, pullrequest, project and issue, which include repository read access. Mycroft runs a read-only pull model and does not write back.
Which controls Bitbucket evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Bitbucket to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Bitbucket |
|---|---|---|---|
| SOC 2 | CC8.1 | Changes are authorized, reviewed and approved before release. | Pull request records with approvers, merge checks satisfied, build status and merge timestamp for each change to a restricted branch. |
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Workspace member and group inventory with repository-level permissions, and admin holders identified. |
| SOC 2 | CC6.3 | Least privilege is enforced and access is removed on departure. | Workspace membership reconciled against the current workforce roster, surfacing accounts belonging to former staff or expired contractors. |
| ISO 27001 | A.8.4 | Access to source code is restricted. | Per-repository permission matrix across users and groups, with repository visibility settings. |
| ISO 27001 | A.8.32 | Changes are controlled through change management procedures. | Branch restriction configuration (required approvals, required successful builds, restrictions on direct pushes and rewriting history) evidenced continuously. |
| ISO 27001 | A.5.17 | Authentication information is managed securely. | Two-factor authentication enforcement status on the workspace, with members lacking it identified. |
| ISO 27001 | A.8.31 | Development, test and production environments are separated. | Deployment environment configuration with environment-level approval and restriction settings. |
What Mycroft collects automatically
Gathered from Bitbucket on a schedule, dated and stored against the controls above.
- Pull request history with approvers, merge checks and merge timestamps
- Branch restriction rules on production branches, including who may bypass them
- Workspace member and group inventory with repository permissions
- Repository visibility settings across the workspace
- Two-factor authentication enforcement on the workspace
- Deployment environment configuration and approval settings
- App password and access token inventory at workspace level
Manual work this removes
The tasks that disappear from someone's quarter once Bitbucket is connected.
- Building a repository-by-repository permission list for the quarterly review
- Screenshotting branch restrictions for the change management walkthrough
- Exporting pull request approvals for the auditor's sample
- Checking two-factor authentication enrolment member by member
Bitbucket and Mycroft: frequently asked questions
Is Bitbucket Server or Data Center supported?
How does Bitbucket pair with Jira for change management?
Does Mycroft read our repositories?
Can Mycroft see who bypassed a branch restriction?
We turn the compliance nightmare into a dream
Talk to us


