JiraComingAgentLens for Jira
AI agent guardrails, approvals and audit for Jira
AgentLens for Jira is a Jira Cloud app that lets Claude, ChatGPT, Cursor and Rovo agents work in Jira safely. It is built for Jira admins who are asked to connect AI agents and first have to answer three questions: what can the agent see, what can it change, and who checks?
Agents get their own governed Jira tools over MCP. Every call runs as the user, under your rules: allow, require approval or deny. Risky changes wait for a person, sensitive values are masked before the model sees them, and every agent call is logged.
Coming soon to the Atlassian Marketplace. AgentLens is not listed yet, so it cannot be installed today. Email support@mortiseapps.com and we will tell you when it is available.
Key facts
The short version for admins and security reviewers.
- Type
- Jira Cloud app (Atlassian Forge, Runs on Atlassian)
- What it does
- Governed Jira tools for AI agents over MCP, with policy rules, approvals, field and value masking, prompt-injection screening, an audit log and a Monitor
- Works with
- Jira Software, Jira Work Management and Jira Service Management on Jira Cloud; AI clients that support remote MCP servers with OAuth 2.1
- Availability
- Coming soon to the Atlassian Marketplace; not yet listed
- Planned price
- Free up to 10 users, then USD 1.25 per user per month for 11-100 users, lower per user above 100, billed by Atlassian
- Data handling
- No external servers and no egress; tool calls run as the signed-in user; settings, audit log and approvals in Forge SQL and Forge storage on Atlassian's infrastructure; no AI model called by the app
- Support
- support@mortiseapps.com, reply within one business day
The problem with AI agents in Jira
Teams are being asked to connect AI agents to Jira. Admins have to answer three questions first.
What can the agent see?
An agent reads what its user can read. Fields such as salary or customer email, and secrets pasted into comments, reach the model unless something hides or masks them first.
What can the agent change?
Atlassian's own MCP controls are switches for the whole organization. They do not cover agents that use API tokens and they do not mask individual fields.
Who checks?
Atlassian's controls cannot hold a change for a person to approve. An agent's transition or edit lands straight in the issue.
Hidden instructions in tickets
Customer tickets can carry text aimed at the agent, such as "ignore previous instructions" or requests to send secrets or call URLs. Untrusted text needs screening before an agent acts on it.
What AgentLens adds to Jira
One governed door for every AI agent, and a record of everything it did.
Governed Jira tools for AI agents (MCP)
Search with JQL, read issues and comments, list transitions, create issues, update fields, comment, transition and assign. Agents connect to the AgentLens MCP address with the user's own Atlassian sign-in, so Jira permissions and issue security always apply.
Policy rules and a simulator
Allow, require approval or deny by operation (read, create, update, comment, transition, assign), project, group or person. The first matching rule wins; by default reads are allowed and writes need approval. The simulator shows which rule decides a call.
Stop all agents and read-only mode
One switch stops every agent call; another makes agents read-only. Read-only can also be set per project.
Approvals with a diff
Held changes show what would change: old and new values, target status, comment text. Approvers approve or reject with a note. An approver must hold the same Jira permission, nobody approves their own request unless you allow it for single-admin teams, and requests expire (default 24 hours).
Dashboard and charts
Pick 7, 30 or 90 days: agent calls per day by decision, the decision and approval split with average time to decide, tools used, projects touched, people, what was masked and the busiest hours.
Exports for reviews and audits
Download the dashboard report, the audit log, approvals, alerts and issue changes as CSV or JSON. Export and import every setting as JSON for change control or a second site.
Every agent change is visible
Changes made through AgentLens are stamped "Changed by an AI agent through AgentLens" in the issue history, and comments carry an agentlens property.
Field and value masking
Hide or redact chosen fields. Detectors mask email addresses (partly), phone numbers, card numbers (Luhn-checked), IBANs, API keys and tokens, passwords in text and private keys, plus your own patterns. Masked counts are logged, never the values.
Prompt-injection screening
Text from service-desk projects, portal customers or projects you choose is scanned for hidden instructions. Choose to warn the agent, strip the suspicious sentences or withhold the text. Every detection is logged.
Audit log
One record per agent call: person, tool, issues, decision and rule, masked arguments, masking counts, injection flags, duration. Filter and export CSV. Keep 30, 90, 180 or 365 days.
Monitor and setup guide
The Monitor watches every issue change on the site, whoever made it, tags the accounts your bots use and alerts on bulk changes. The setup guide walks through turning on the tools, connecting each AI client, choosing approvers and closing the side doors so agents cannot go around AgentLens.
How to put AI agents in Jira under your rules with AgentLens
About ten minutes for a Jira admin. The full steps are in the getting-started guide.
Install and turn on the tools
Once AgentLens is on the Atlassian Marketplace, a Jira admin installs it, then enables its tools once in Atlassian Administration under Connected apps. Atlassian ships this switch off.
Connect AI clients
The Setup tab shows the AgentLens MCP address. Add it as a remote MCP server in Claude, Claude Code, Cursor, VS Code or another MCP client. Each person signs in with their Atlassian account and approves the connection once.
Choose approvers and close the side doors
Pick approver groups, then in Atlassian Administration block Atlassian MCP write access and API-token MCP access, so agents use the governed tools instead of going around them.
The tools agents get
Every call runs as the person who connected the agent, so Jira project permissions and issue security apply. By default reads are allowed and writes need approval.
| Tool | What it does | Type |
|---|---|---|
list-projects | Projects the person can see and agents may use | read |
search-issues | JQL search, up to 50 per page | read |
get-issue | One issue with description, people, dates, labels, custom fields | read |
get-comments | Latest comments, newest first | read |
get-transitions | Workflow moves available now | read |
check-request | Status of a change waiting for approval | read |
add-comment | Comment on an issue | write |
update-issue | Summary, description, priority, labels, due date, custom fields | write |
transition-issue | Move an issue by transition name, id or target status | write |
assign-issue | Assign to "me", a name, an account id or "unassigned" | write |
create-issue | Create an issue in a project | write |
Pricing
Planned pricing, billed by Atlassian once the Marketplace listing is live. Final rates appear on the listing.
Small teams
Sites with up to 10 Jira users.
11-100 users
About $63 a month for 50 users and $125 for 100, lower per user above 100. 30-day free trial.
Questions
Pricing, security reviews or availability: support@mortiseapps.com. We reply within one business day.
Frequently asked questions
Straight answers, including what the app cannot do.
What is AgentLens for Jira?
AgentLens is a Jira Cloud app that gives AI agents (Claude, ChatGPT, Cursor, Rovo and any client that speaks MCP) their own set of Jira tools and puts every call through your rules: reads you allow, changes you mark as risky wait for a person to approve, sensitive values are masked before the model sees them, and every call is logged.
Can I install it today?
Not yet. AgentLens is coming soon to the Atlassian Marketplace. Email support@mortiseapps.com to hear when it is available.
Does AgentLens replace Atlassian Guard?
No. Guard governs your whole organization (SSO, data security policies, classification). AgentLens governs what AI agents do in Jira through its tools: per-project rules, approvals, field masking, injection screening and a detailed log. They work together.
Can AgentLens block Atlassian's own MCP server or Rovo?
No app can sit in front of them. AgentLens gives agents a governed alternative; you then switch off Atlassian MCP write access and API-token access so agents use AgentLens. The Monitor still shows every issue change, whoever made it.
Which AI clients work?
Any client that supports remote MCP servers with OAuth 2.1. The connection was tested with the official MCP SDK client on 5 October 2026; Claude, Cursor, ChatGPT connectors and Rovo Studio agents use the same standard flow and are being confirmed one by one before launch. Each person connects once.
Why does my agent say "pending approval"?
Your policy requires approval for that change. An approver decides on the AgentLens approvals page; the agent can check progress with the check-request tool.
Who appears as the author of approved changes?
"AgentLens for Jira", because the app applies them after approval. The comment text and the issue history name the request; the audit log names the requester and the approver.
Does AgentLens send data to an AI provider?
No. It runs on Atlassian with no external servers and calls no AI model. Your AI client receives only what the tools return after masking.
How much will it cost?
The planned pricing is free for sites with up to 10 users, then USD 1.25 per user per month for 11-100 users and lower per user above 100, billed by Atlassian with a 30-day free trial. Final rates appear on the Marketplace listing.
Known limitations, stated plainly
What AgentLens does not do in this version. The same list is on the limitations page.
- AgentLens governs agents that connect through it. Agents using Atlassian's own MCP server or REST API tokens are visible in the Monitor but not blocked; the setup guide shows how to close those routes in Atlassian Administration.
- The MCP tools come from Atlassian's Forge "rovo:mcp" capability, which Atlassian marks as Preview, with external AI clients in early access; Atlassian may change it.
- A site admin must click "Enable tools" for the app once (Atlassian Administration, Connected apps), and each person approves the connection once in their AI client and once for AgentLens.
- The app cannot tell which AI client made a call (Atlassian does not pass it), so rules work per person, group and project, not per client.
- Approved changes are applied by the app on the requester's behalf, so the author shown in Jira is "AgentLens for Jira", with the requester and approver named in comments and in the audit log.
- Attachments are not read or written in this version; Confluence is not covered yet.
On the roadmap: Confluence tools, AI-model screening for injection (Atlassian's own models, no egress), Slack and Teams approvals, per-tool switches, a monthly compliance PDF and SIEM export.
Let AI agents into Jira on your terms
Runs on Atlassian. Calls run as the user. Every agent action logged.