Security and privacy
Last updated 2026-10-05
- Runs on Atlassian. No external servers and no egress. Compute, Forge SQL and Forge storage run on Atlassian's infrastructure for your site.
- Acts as the user. Tool calls read and write Jira as the signed-in person, so project permissions and issue security levels apply. Approved changes are applied by the app after two checks: the requester held the Jira permission when the request was made, and the approver holds it when approving.
- What is stored: settings; one audit record per agent call (account id, tool, issue keys, decision, rule, arguments after masking, masking counts, injection flags, duration, error text); approval requests (the requested change, requester and approver ids and names, note); Monitor events (account id, event type, issue key, names of changed fields, not their values). Retention 30-365 days, purged daily.
- What is never stored: Atlassian tokens or passwords, the platform's per-call context token, unmasked values that a detector caught in tool arguments.
- AI models: AgentLens does not call any AI model. Your AI client (Claude, ChatGPT, Cursor, Rovo) receives only what the tools return after masking.
- Scopes: read:jira-work, write:jira-work, read:jira-user, storage:app. Jira admin pages check the Administer Jira permission on every request; the approvals page checks approver-group membership.
- What AgentLens does not cover: agents that use Atlassian's own MCP server or REST API tokens directly. They show up in the Monitor but are not blocked; close those routes in Atlassian Administration (see getting started, step 7).
- Report a vulnerability: support@mortiseapps.com.
Was this page helpful? Email support@mortiseapps.com.