Jira logoJiraComingAgentLens for Jira

AI agent guardrails, approvals and audit for Jira

AgentLens for Jira is a Jira Cloud app that lets Claude, ChatGPT, Cursor and Rovo agents work in Jira safely. It is built for Jira admins who are asked to connect AI agents and first have to answer three questions: what can the agent see, what can it change, and who checks?

Agents get their own governed Jira tools over MCP. Every call runs as the user, under your rules: allow, require approval or deny. Risky changes wait for a person, sensitive values are masked before the model sees them, and every agent call is logged.

Coming soon to the Atlassian Marketplace. AgentLens is not listed yet, so it cannot be installed today. Email support@mortiseapps.com and we will tell you when it is available.

✓ Runs on Atlassian, no data leaves your site✓ Calls run as the signed-in user✓ Approvals with a before/after diff✓ Calls no AI model itselfMarketplace listing coming soon

Key facts

The short version for admins and security reviewers.

Type
Jira Cloud app (Atlassian Forge, Runs on Atlassian)
What it does
Governed Jira tools for AI agents over MCP, with policy rules, approvals, field and value masking, prompt-injection screening, an audit log and a Monitor
Works with
Jira Software, Jira Work Management and Jira Service Management on Jira Cloud; AI clients that support remote MCP servers with OAuth 2.1
Availability
Coming soon to the Atlassian Marketplace; not yet listed
Planned price
Free up to 10 users, then USD 1.25 per user per month for 11-100 users, lower per user above 100, billed by Atlassian
Data handling
No external servers and no egress; tool calls run as the signed-in user; settings, audit log and approvals in Forge SQL and Forge storage on Atlassian's infrastructure; no AI model called by the app
Support
support@mortiseapps.com, reply within one business day

The problem with AI agents in Jira

Teams are being asked to connect AI agents to Jira. Admins have to answer three questions first.

What can the agent see?

An agent reads what its user can read. Fields such as salary or customer email, and secrets pasted into comments, reach the model unless something hides or masks them first.

What can the agent change?

Atlassian's own MCP controls are switches for the whole organization. They do not cover agents that use API tokens and they do not mask individual fields.

Who checks?

Atlassian's controls cannot hold a change for a person to approve. An agent's transition or edit lands straight in the issue.

Hidden instructions in tickets

Customer tickets can carry text aimed at the agent, such as "ignore previous instructions" or requests to send secrets or call URLs. Untrusted text needs screening before an agent acts on it.

What AgentLens adds to Jira

One governed door for every AI agent, and a record of everything it did.

Governed Jira tools for AI agents (MCP)

Search with JQL, read issues and comments, list transitions, create issues, update fields, comment, transition and assign. Agents connect to the AgentLens MCP address with the user's own Atlassian sign-in, so Jira permissions and issue security always apply.

Policy rules and a simulator

Allow, require approval or deny by operation (read, create, update, comment, transition, assign), project, group or person. The first matching rule wins; by default reads are allowed and writes need approval. The simulator shows which rule decides a call.

Stop all agents and read-only mode

One switch stops every agent call; another makes agents read-only. Read-only can also be set per project.

Approvals with a diff

Held changes show what would change: old and new values, target status, comment text. Approvers approve or reject with a note. An approver must hold the same Jira permission, nobody approves their own request unless you allow it for single-admin teams, and requests expire (default 24 hours).

Dashboard and charts

Pick 7, 30 or 90 days: agent calls per day by decision, the decision and approval split with average time to decide, tools used, projects touched, people, what was masked and the busiest hours.

Exports for reviews and audits

Download the dashboard report, the audit log, approvals, alerts and issue changes as CSV or JSON. Export and import every setting as JSON for change control or a second site.

Every agent change is visible

Changes made through AgentLens are stamped "Changed by an AI agent through AgentLens" in the issue history, and comments carry an agentlens property.

Field and value masking

Hide or redact chosen fields. Detectors mask email addresses (partly), phone numbers, card numbers (Luhn-checked), IBANs, API keys and tokens, passwords in text and private keys, plus your own patterns. Masked counts are logged, never the values.

Prompt-injection screening

Text from service-desk projects, portal customers or projects you choose is scanned for hidden instructions. Choose to warn the agent, strip the suspicious sentences or withhold the text. Every detection is logged.

Audit log

One record per agent call: person, tool, issues, decision and rule, masked arguments, masking counts, injection flags, duration. Filter and export CSV. Keep 30, 90, 180 or 365 days.

Monitor and setup guide

The Monitor watches every issue change on the site, whoever made it, tags the accounts your bots use and alerts on bulk changes. The setup guide walks through turning on the tools, connecting each AI client, choosing approvers and closing the side doors so agents cannot go around AgentLens.

How to put AI agents in Jira under your rules with AgentLens

About ten minutes for a Jira admin. The full steps are in the getting-started guide.

  1. Install and turn on the tools

    Once AgentLens is on the Atlassian Marketplace, a Jira admin installs it, then enables its tools once in Atlassian Administration under Connected apps. Atlassian ships this switch off.

  2. Connect AI clients

    The Setup tab shows the AgentLens MCP address. Add it as a remote MCP server in Claude, Claude Code, Cursor, VS Code or another MCP client. Each person signs in with their Atlassian account and approves the connection once.

  3. Choose approvers and close the side doors

    Pick approver groups, then in Atlassian Administration block Atlassian MCP write access and API-token MCP access, so agents use the governed tools instead of going around them.

The tools agents get

Every call runs as the person who connected the agent, so Jira project permissions and issue security apply. By default reads are allowed and writes need approval.

ToolWhat it doesType
list-projectsProjects the person can see and agents may useread
search-issuesJQL search, up to 50 per pageread
get-issueOne issue with description, people, dates, labels, custom fieldsread
get-commentsLatest comments, newest firstread
get-transitionsWorkflow moves available nowread
check-requestStatus of a change waiting for approvalread
add-commentComment on an issuewrite
update-issueSummary, description, priority, labels, due date, custom fieldswrite
transition-issueMove an issue by transition name, id or target statuswrite
assign-issueAssign to "me", a name, an account id or "unassigned"write
create-issueCreate an issue in a projectwrite

Pricing

Planned pricing, billed by Atlassian once the Marketplace listing is live. Final rates appear on the listing.

Small teams

Free

Sites with up to 10 Jira users.

11-100 users

$1.25 / user / month

About $63 a month for 50 users and $125 for 100, lower per user above 100. 30-day free trial.

Questions

Pricing, security reviews or availability: support@mortiseapps.com. We reply within one business day.

Frequently asked questions

Straight answers, including what the app cannot do.

What is AgentLens for Jira?

AgentLens is a Jira Cloud app that gives AI agents (Claude, ChatGPT, Cursor, Rovo and any client that speaks MCP) their own set of Jira tools and puts every call through your rules: reads you allow, changes you mark as risky wait for a person to approve, sensitive values are masked before the model sees them, and every call is logged.

Can I install it today?

Not yet. AgentLens is coming soon to the Atlassian Marketplace. Email support@mortiseapps.com to hear when it is available.

Does AgentLens replace Atlassian Guard?

No. Guard governs your whole organization (SSO, data security policies, classification). AgentLens governs what AI agents do in Jira through its tools: per-project rules, approvals, field masking, injection screening and a detailed log. They work together.

Can AgentLens block Atlassian's own MCP server or Rovo?

No app can sit in front of them. AgentLens gives agents a governed alternative; you then switch off Atlassian MCP write access and API-token access so agents use AgentLens. The Monitor still shows every issue change, whoever made it.

Which AI clients work?

Any client that supports remote MCP servers with OAuth 2.1. The connection was tested with the official MCP SDK client on 5 October 2026; Claude, Cursor, ChatGPT connectors and Rovo Studio agents use the same standard flow and are being confirmed one by one before launch. Each person connects once.

Why does my agent say "pending approval"?

Your policy requires approval for that change. An approver decides on the AgentLens approvals page; the agent can check progress with the check-request tool.

Who appears as the author of approved changes?

"AgentLens for Jira", because the app applies them after approval. The comment text and the issue history name the request; the audit log names the requester and the approver.

Does AgentLens send data to an AI provider?

No. It runs on Atlassian with no external servers and calls no AI model. Your AI client receives only what the tools return after masking.

How much will it cost?

The planned pricing is free for sites with up to 10 users, then USD 1.25 per user per month for 11-100 users and lower per user above 100, billed by Atlassian with a 30-day free trial. Final rates appear on the Marketplace listing.

Known limitations, stated plainly

What AgentLens does not do in this version. The same list is on the limitations page.

  • AgentLens governs agents that connect through it. Agents using Atlassian's own MCP server or REST API tokens are visible in the Monitor but not blocked; the setup guide shows how to close those routes in Atlassian Administration.
  • The MCP tools come from Atlassian's Forge "rovo:mcp" capability, which Atlassian marks as Preview, with external AI clients in early access; Atlassian may change it.
  • A site admin must click "Enable tools" for the app once (Atlassian Administration, Connected apps), and each person approves the connection once in their AI client and once for AgentLens.
  • The app cannot tell which AI client made a call (Atlassian does not pass it), so rules work per person, group and project, not per client.
  • Approved changes are applied by the app on the requester's behalf, so the author shown in Jira is "AgentLens for Jira", with the requester and approver named in comments and in the audit log.
  • Attachments are not read or written in this version; Confluence is not covered yet.

On the roadmap: Confluence tools, AI-model screening for injection (Atlassian's own models, no egress), Slack and Teams approvals, per-tool switches, a monthly compliance PDF and SIEM export.

Let AI agents into Jira on your terms

Runs on Atlassian. Calls run as the user. Every agent action logged.