
Jira
Access
Task Management
Mycroft uses Jira issue records, including approvals, transitions and resolution times, as evidence for change, incident and remediation controls.
The ticket already records what was requested, who approved it, who did the work and when it closed. Mycroft stores those records against the controls they satisfy, and can raise remediation issues in a project you nominate.
How Mycroft connects to Jira
- How it connects
- You authorize Mycroft through Atlassian OAuth 2.0 against your Jira site. The grant includes offline_access so the connection refreshes itself.
- What Mycroft can access
- Granted scopes are read:jira-user, read:organization.user:jira-service-management, read:issue:jira and write:issue:jira. The write scope is requested at connection time so Mycroft can raise remediation issues in Jira.
Which controls Jira evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Jira to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Jira |
|---|---|---|---|
| SOC 2 | CC8.1 | Changes are requested, authorized and approved before implementation. | Issue records for changes with requester, approver, approval timestamp and workflow transition history, linked to the merge that implemented them. |
| SOC 2 | CC7.3 | Security events are evaluated to determine whether they are incidents. | Incident issue records with severity classification, triage decision and the time from report to classification. |
| SOC 2 | CC7.4 | Identified incidents are responded to and resolved. | Incident resolution history with assignee, actions taken, resolution timestamp and post-incident review linkage. |
| SOC 2 | CC3.2 | Identified risks are analysed and addressed. | Remediation issues raised from control failures and vulnerability findings, with owner, due date and closure record. |
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Project role and permission scheme membership showing who can view, edit and administer each project. |
| ISO 27001 | A.8.32 | Changes are subject to change management procedures. | Workflow configuration proving an approval state exists and must be passed, together with the transition history for each change. |
| ISO 27001 | A.5.25 | Security events are assessed and classified. | Incident issue type configuration with severity fields, and the classification recorded on each incident. |
| ISO 27001 | A.5.26 | Incidents are responded to according to documented procedures. | Response timelines per incident measured from creation to resolution against your documented response targets. |
What Mycroft collects automatically
Gathered from Jira on a schedule, dated and stored against the controls above.
- Change issues with requester, approver, approval timestamp and workflow transitions
- Incident issues with severity, assignee, triage time and resolution timestamp
- Remediation issues raised from control failures, with owner, due date and closure
- Workflow scheme configuration proving approval states are mandatory
- Project role and permission scheme membership for access reviews
- Links between issues and the pull requests or deployments that implemented them
Manual work this removes
The tasks that disappear from someone's quarter once Jira is connected.
- Exporting issue histories for change and incident samples
- Maintaining a compliance tracker separate from the team's tickets
- Calculating time to resolution for the incident response control
- Documenting the approval workflow for each audit
- Assembling project permission lists for the quarterly review
Jira and Mycroft: frequently asked questions
Does Mycroft need write access to Jira?
How does a Jira ticket become audit evidence?
Can Mycroft evidence incident response from Jira?
Does this work with Jira Service Management?
We turn the compliance nightmare into a dream
Talk to us


