We are currently evaluating the use of Atlassian Assist integrated with Microsoft Teams, and a few questions came up regarding security and traceability of chat interactions.
I searched through the official Atlassian documentation but couldn’t find a clear or satisfactory answer for the scenarios below.
For tickets containing sensitive information and restricted visibility (for example, Cybersecurity incidents using Issue Security), are those permissions still respected when interacting through Teams chat?
In the event of a data breach investigation, is it possible to identify which user performed actions or interactions through the chat integration? Is there also a place where chat requests/interactions can be audited or reviewed?
If anyone has already dealt with this scenario or has documentation/evidence regarding how Atlassian Assist handles these cases, I’d appreciate the help.
Hello @Andre Felipe Rodrigues Lopes
Let's break this down into two main areas: Jira permissions and how things are visible in Microsoft Teams.
So, while Jira actions like adding comments and changing status get recorded in the ticket history, Teams chat messages aren't tracked centrally in the Atlassian audit logs. Crucially, Jira Issue Security cannot protect data once it's pushed into a Teams channel; Microsoft 365/Purview compliance and channel membership settings take over at that point.
For sensitive cybersecurity incidents, I highly recommend testing with an unauthorized user first to see what they can preview, and getting official written confirmation from Atlassian regarding Assist's exact data logging before rolling it out broadly.
Best,
Arkadiusz🤠😎
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.