Linear logo

Linear

Access
Task Management

Mycroft raises findings as Linear issues and uses their state history to measure time to remediate.

Remediation work gets done where the team already operates. Every state transition is timestamped, so the interval from creation to done is measured rather than self-reported, and workspace membership is included in access reviews.

How Mycroft connects to Linear

How it connects
You authorize Mycroft through Linear OAuth.
What Mycroft can access
Granted scopes are read and issues:create, so Mycroft can read your workspace and raise new issues but cannot edit or delete existing ones.

Which controls Linear evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Linear to satisfy it. Collection runs on a schedule and every result is timestamped.

Linear compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Linear
SOC 2CC3.2Risks are identified, analysed and addressed.Remediation issues raised from control failures and findings, with assignee, priority, due date and completion timestamp.
SOC 2CC8.1Changes are authorized and tracked through to implementation.Issue state history showing the transition from triage through review to done, linked to the pull request that shipped the change.
SOC 2CC6.1Logical access controls restrict access to information assets.Workspace and team membership with roles, including guest access, surfaced in the periodic access review.
SOC 2CC7.4Incidents are responded to and tracked to resolution.Incident-labelled issues with priority, assignee and time from creation to completion.
ISO 27001A.8.32Changes follow a documented change management procedure.Workflow state configuration per team with the state transition history recorded for each change.
ISO 27001A.5.18Access rights are provisioned, reviewed and revoked.Workspace member and guest inventory reconciled against the current workforce roster.

What Mycroft collects automatically

Gathered from Linear on a schedule, dated and stored against the controls above.

  • Issue records with assignee, priority, labels, project and completion timestamp
  • Full state transition history per issue, with actor and time in each state
  • Remediation issues raised from Mycroft findings, tracked to done
  • Workspace and team membership including guests, with roles
  • Cycle and project completion data for measuring remediation throughput
  • Links between issues and the pull requests that resolved them

Manual work this removes

The tasks that disappear from someone's quarter once Linear is connected.

  • Copying compliance findings into Linear by hand
  • Exporting issue histories for remediation samples
  • Maintaining a separate list of workspace access for the quarterly review
  • Measuring time to remediate manually across a quarter of issues

Linear and Mycroft: frequently asked questions

Yes, optionally. Control failures, vulnerability findings and access review exceptions can be raised as issues in a team you nominate, with the finding detail and due date populated. Mycroft then follows the issue's own state to closure. If you'd rather keep the connection read-only, leave creation disabled and Mycroft simply observes existing issues.
Through state history. Every transition is timestamped, so the interval from creation to done is measured rather than self-reported. That interval, compared against the SLA in your vulnerability management policy, is what evidences SOC 2 CC3.2 and ISO 27001 A.8.8 remediation timeliness.
The Linear OAuth grant carries the read scope, which covers the workspace, plus issues:create so Mycroft can raise remediation issues. It cannot edit or delete existing issues.

We turn the compliance nightmare into a dream

Talk to us