Close Reviewfor Jira

Security and access

A saved review is useful only if its contents remain protected and its limitations are clear.

Two narrow app permissions

Close Review requests read:jira-work to read the Jira data used in a check and storage:app to retain app settings and review evidence. It does not request a Jira write scope. The browser calls Forge functions; no external app backend or external AI service is configured.

Access is checked again

The backend requires Jira administrator access and checks current access before showing protected issue/worklog contents. It does not accept a browser-supplied tenant as authority. Forge storage is installation-scoped.

An inaccessible entry is not treated as a zero-hour adjustment. An unconfirmed disappearance stays unresolved. These choices protect both private content and the integrity of the comparison.

What the evidence means

Checks use two verification passes and report their coverage. Jira is read over an interval, so a capture is not a transactional snapshot. Content fingerprints help detect changes; they are not independent signatures or third-party certification. Close Review is not a statutory accounting ledger or a guarantee of regulatory compliance.

Exports and local copies

Readable HTML reports have no scripts or external assets. CSV output protects against formula-like cell content. After an export, your organization controls the file’s storage, sharing and deletion. Limit review notes to the information needed for the decision.

Report a security concern

Contact oguztan48@proton.me. Include the affected feature, a description and the approximate time. Do not send credentials or other customers’ data. We can agree a safe evidence-transfer method if more information is needed.

Security, privacy and access issues are escalated for individual review. We do not claim a certification, penetration-test result, response-time guarantee or security program badge that has not been earned.

Read the data disclosure or get product support.