Jira logo

Jira

Access
Task Management

Mycroft uses Jira issue records, including approvals, transitions and resolution times, as evidence for change, incident and remediation controls.

The ticket already records what was requested, who approved it, who did the work and when it closed. Mycroft stores those records against the controls they satisfy, and can raise remediation issues in a project you nominate.

How Mycroft connects to Jira

How it connects
You authorize Mycroft through Atlassian OAuth 2.0 against your Jira site. The grant includes offline_access so the connection refreshes itself.
What Mycroft can access
Granted scopes are read:jira-user, read:organization.user:jira-service-management, read:issue:jira and write:issue:jira. The write scope is requested at connection time so Mycroft can raise remediation issues in Jira.

Which controls Jira evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Jira to satisfy it. Collection runs on a schedule and every result is timestamped.

Jira compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Jira
SOC 2CC8.1Changes are requested, authorized and approved before implementation.Issue records for changes with requester, approver, approval timestamp and workflow transition history, linked to the merge that implemented them.
SOC 2CC7.3Security events are evaluated to determine whether they are incidents.Incident issue records with severity classification, triage decision and the time from report to classification.
SOC 2CC7.4Identified incidents are responded to and resolved.Incident resolution history with assignee, actions taken, resolution timestamp and post-incident review linkage.
SOC 2CC3.2Identified risks are analysed and addressed.Remediation issues raised from control failures and vulnerability findings, with owner, due date and closure record.
SOC 2CC6.1Logical access controls restrict access to information assets.Project role and permission scheme membership showing who can view, edit and administer each project.
ISO 27001A.8.32Changes are subject to change management procedures.Workflow configuration proving an approval state exists and must be passed, together with the transition history for each change.
ISO 27001A.5.25Security events are assessed and classified.Incident issue type configuration with severity fields, and the classification recorded on each incident.
ISO 27001A.5.26Incidents are responded to according to documented procedures.Response timelines per incident measured from creation to resolution against your documented response targets.

What Mycroft collects automatically

Gathered from Jira on a schedule, dated and stored against the controls above.

  • Change issues with requester, approver, approval timestamp and workflow transitions
  • Incident issues with severity, assignee, triage time and resolution timestamp
  • Remediation issues raised from control failures, with owner, due date and closure
  • Workflow scheme configuration proving approval states are mandatory
  • Project role and permission scheme membership for access reviews
  • Links between issues and the pull requests or deployments that implemented them

Manual work this removes

The tasks that disappear from someone's quarter once Jira is connected.

  • Exporting issue histories for change and incident samples
  • Maintaining a compliance tracker separate from the team's tickets
  • Calculating time to resolution for the incident response control
  • Documenting the approval workflow for each audit
  • Assembling project permission lists for the quarterly review

Jira and Mycroft: frequently asked questions

Yes. The Atlassian OAuth grant includes write:issue:jira alongside the read scopes, requested at connection time so Mycroft can raise remediation issues in Jira. The remaining scopes are read:jira-user, read:organization.user:jira-service-management and read:issue:jira.
An auditor testing remediation or change management wants four things: what was identified, who owned it, what was done, and when it closed. The issue record carries all four with timestamps. Mycroft stores it against the control it satisfies, so the auditor's sample is answered from stored evidence instead of a live export.
Yes, provided incidents are logged there consistently. Severity classification, assignment history and resolution timestamps evidence SOC 2 CC7.3 and CC7.4 and ISO 27001 A.5.25 and A.5.26. The measured time from report to resolution is what demonstrates your response targets were met rather than merely documented.
Yes. Teams running incident and change workflows through Jira Service Management get richer evidence, because approval and SLA fields are first-class there. Mycroft reads the approval records and SLA measurements alongside the standard issue history.

We turn the compliance nightmare into a dream

Talk to us