Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Who can actually see that JSM request? Finding unintended customer sharing

Claervo
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 7, 2026

Hi everyone, Engin here from Claervo. We build small Forge apps for Jira and Jira Service Management administrators, and I want to share the problem behind our first app and how it works, because the problem is more common than most teams realise.

 

The problem

 

In Jira Service Management a request can quietly gain a much wider audience than the person who raised it. Two fields do most of the damage:

 

Organizations. When a request is shared with a customer organization, every member of that organization can open it. An HR, legal or security request shared with "Acme Corp (all staff)" is visible to all staff.

 

Request participants. Agents add participants to keep people in the loop. Over time, external addresses and large groups accumulate, and nobody reviews them.

 

Neither field shows up in the usual permission reviews, and Jira gives administrators no report that lists which requests are exposed to whom.

 

What we built

 

Claervo Privacy Guard for JSM is an admin app that scans service projects for organization and participant sharing and ranks what it finds:

 

1. Exposure scan across selected service projects, with a deterministic risk score per request (sensitive organization share, external participant, multiple organizations, unusually large audience).

2. Policies scoped by project and request type: allowed participant domains, audience size limits, prohibited organization sharing.

3. Monitor-only mode first. You see what a policy would change before it changes anything.

4. Remediation that re-reads the request from Jira right before acting, then clears a prohibited organization or removes only the violating participants.

5. A sanitized audit trail and CSV/JSON exports for evidence.

6. A private customer account field so a request can be linked to a customer without granting organization-wide access.

 

What it never does

 

The app runs entirely on Atlassian Forge. There is no remote backend, no analytics endpoint and no AI processing, so customer data never leaves your Atlassian site. It does not read request descriptions, comments or attachments. It is eligible for Runs on Atlassian.

 

How to try it

 

It is on the Atlassian Marketplace as Claervo Privacy Guard for JSM, free for up to 10 users and with a 30-day trial above that. A first monitor-only scan takes a few minutes on a typical site.

 

Marketplace listing: https://marketplace.atlassian.com/apps/2917950185

 

I would genuinely like to hear how your teams review organization sharing today, and which exposure patterns you have run into. Happy to answer questions here.

 

pg-1-overview.pngpg-2-policies.pngpg-3-settings.png

0 comments

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events