Complete user guide
Last updated 2026-10-05
AgentLens gives AI agents (Claude, ChatGPT, Cursor, Rovo and any client that speaks MCP) their own set of Jira tools and puts every call through your rules. Agents can read what you allow, changes you mark as risky wait for a person to approve, sensitive values are masked before the model sees them, and every call is logged.
AgentLens is coming soon to the Atlassian Marketplace and is not listed yet. Setup steps are in getting started.
1. The tools agents get
| Tool | What it does | Type |
|---|---|---|
| list-projects | Projects the person can see and agents may use | read |
| search-issues | JQL search, up to 50 per page | read |
| get-issue | One issue with description, people, dates, labels, custom fields | read |
| get-comments | Latest comments, newest first | read |
| get-transitions | Workflow moves available now | read |
| check-request | Status of a change waiting for approval | read |
| add-comment | Comment on an issue | write |
| update-issue | Summary, description, priority, labels, due date, custom fields | write |
| transition-issue | Move an issue by transition name, id or target status | write |
| assign-issue | Assign to "me", a name, an account id or "unassigned" | write |
| create-issue | Create an issue in a project | write |
Every call runs as the person who connected the agent, so Jira project permissions and issue security apply.
2. Policies
- Defaults: reads are allowed and writes need approval. Change them on the Policies tab.
- Rules decide allow, approve or deny for an operation (read, create, update, comment, transition, assign, or "write" for all changes), limited to projects, groups or people. The first matching rule wins.
- Read-only projects and the Read-only switch block all agent changes; Stop all agents blocks everything.
- The simulator shows which rule decides a call for a person, project and operation.
- "Approve" on a read is treated as deny (reads cannot wait in a queue).
3. Approvals
When a rule says approve, the change is not made. The agent receives "pending approval, request #N" and a preview, and the request appears on Apps → AgentLens approvals (and the Approvals tab for admins) with the old and new values. Approve and apply, or reject with a note.
- The approver must hold the Jira permission the change needs.
- Nobody approves their own request unless Settings → "Allow people to approve their own requests" is on (for teams with one admin; still logged).
- Requests expire after 24 hours by default.
- Approved changes are applied by AgentLens on the requester's behalf and stamped "AI agent via AgentLens (approved request #N)" in the issue history. Comments name the requester and the approver.
The agent can check progress with check-request.
4. Masking and untrusted content
- Hidden fields: pick fields on the Masking & content tab; choose "Show as masked" (the agent knows the field exists) or "Remove".
- Value detectors: emails (partly masked by default), phone numbers, card numbers (Luhn-checked), IBANs, API keys and tokens, passwords written in text, private keys, and your own regular expressions. "Never mask" keeps exact values such as your public support address.
- Untrusted sources: service-desk projects, comments by portal customers and projects you choose are scanned for hidden instructions ("ignore previous instructions", requests to send secrets or call URLs, hidden markup, invisible characters, long encoded blocks). Choose to warn the agent, strip the suspicious sentences or withhold the text.
- The agent's result says what was masked and which injection patterns were found; the audit log records counts.
5. Overview, audit log, Monitor and exports
- Audit log: every agent call with person, tool, issues, decision and rule, masked arguments, masking counts, injection flags and duration. Filter by decision, project and date; export CSV or JSON (up to 1,000 records per export). Policy and switch changes by admins are logged too. Retention: Settings (30, 90, 180 or 365 days).
- Monitor: every issue change on the site, by anyone, including Atlassian's own MCP server, API tokens and automation. Tag the accounts your bots use; get an alert when one account changes many issues in a few minutes.
- Overview: pick 7, 30 or 90 days. Cards for calls, people, change requests, approvals, blocks, masking and injection flags, and charts for calls per day by decision, the decision and approval split (with average time to decide), tools used, projects, people, what was masked and the busiest hours (UTC).
- Exports: the dashboard report, audit log, approvals, alerts and issue changes as CSV or JSON. If the browser blocks the download, the same data appears in a copy box.
- Settings backup: Settings → Export settings (JSON) saves every rule and setting; Import settings validates and replaces them.
6. Limits
See known limitations and security and privacy.
7. Roadmap
Confluence tools, AI-model screening for injection (Atlassian's own models, no egress), Slack and Teams approvals, per-tool switches, a scheduled compliance report and SIEM export.
Was this page helpful? Email support@mortiseapps.com.