Community moderators have prevented the ability to post new answers.
Hello @Chris Adams , direct answer first: no, there is no allowlist. Safe customer notifications is a site-wide compliance setting (Settings, then Apps, then Compliance settings under Jira Service Management) and it masks summary, description, comment and attachment content in every customer notification the site sends; it has no recipient, domain or project dimension (About safe customer notifications). So the question becomes how to get full-detail emails to your internal people without turning it off, and that is possible, because of a distinction the setting relies on.
It only masks customer notifications, not internal ones. JSM sends two different email streams: customer notifications (the templates under Space settings, Notifications, Customer notifications, which is what the compliance setting masks) and internal notifications, which come from the space's Jira notification scheme and are never touched by it (what notifications customers and team receive). Your agents are getting stripped emails because they are receiving the customer stream, which happens whenever an agent sits in the Reporter, Request participant or Approver field, or is in an organisation the request is shared with.
The exemption is by role, not by address. Atlassian's troubleshooting KB states it plainly: a person added as watcher or assignee receives internal notifications instead of customer notifications (fix customer notification issues). So the design is:
Two boundaries to know: the masked variables in customer templates render as bullets and cannot be edited around; and emails sent by automation rules are not customer notifications, so they are not masked, which is a route for a deliberate internal digest, and also the reason Atlassian's HIPAA guidance tells you to review any rule that emails work item content when the setting is on.
"Stop putting internal staff in customer-role fields (participant, approver) when the goal is to keep them informed; use watchers, the assignee, or a role in the notification scheme (for example a "Service desk team" role receiving Work item commented) instead."
We aren't doing that. We have tried untagging apps, ensuring both safe client and hipaa are unticked and it's still happening.
It's happening for regular Jira spaces as well as JSM.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Chris Adams , that changes the diagnosis, and I would rather narrow it than guess. If safe customer notifications is off and the same stripping happens in regular Jira spaces, which have no customer notification stream at all, then the compliance setting is not the cause, and nothing else in Atlassian's documentation masks notification content by design. @Nikola Perisic personal Notification settings control whether a person receives an email, not what is in it, so they will not explain missing content either. Two questions that will isolate it:
Reply with which of the two it is and I will take it from there.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Chris Adams
This is something that users need to set for their personal notifications.
They get there: Cog -> Notification settings
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.