Forums

Articles
Create
cancel
Showing results forΒ 
Search instead forΒ 
Did you mean:Β 

ROVO posted a comment to JSM as Public instead of Internal

Mark B Wager
Contributor
July 17, 2026

🚨 Warning: Rovo Will Post PUBLIC Comments on JSM Tickets Even When You Ask for Internal

Product: Rovo AI Assistant
Context: Jira Service Management (Cloud)

The Problem

If you ask Rovo to post an internal/agent-only comment on a JSM ticket, it will post it as a PUBLIC comment instead β€” without warning you.

The customer and all request participants will receive the email notification immediately. There is no undo.

What Happened to Me

I was investigating an automation delay on a JSM ticket and asked Rovo to post a post-mortem explanation as an internal comment. Rovo:

  1. Did not check whether its comment-posting tool supports internal/restricted visibility before executing
  2. Did not stop and warn me that it couldn't honor the "internal" requirement β€” it just posted it publicly anyway
  3. Did not ask for confirmation before executing a write action on a live customer-facing ticket
  4. Casually suggested I "manually toggle it to internal" β€” but the email notifications had already gone out to the customer and all request participants

A post-mortem comment containing internal operational details was sent to the customer. That damage can't be undone.

What Rovo Should Have Done

"Hey, I need to let you know β€” the tool I have for adding comments doesn't support JSM internal/agent-only notes. I can't guarantee this stays private. Here's the full comment text so you can post it yourself as an internal note directly in the ticket."

Recommendations for JSM Admins

  • Do NOT ask Rovo to post comments on JSM tickets if visibility matters β€” it currently has no ability to distinguish between public and internal comments
  • Treat all Rovo write actions on tickets with caution β€” it may execute without confirming, even when it can't fulfill your exact instructions
  • Provide feedback to Atlassian β€” use the πŸ‘Ž button on Rovo responses and/or file a support ticket requesting:

    • Internal comment visibility support in Rovo's comment-posting tool
    • Mandatory user confirmation before write actions on live tickets
    • Rovo should refuse to execute rather than silently downgrade from internal to public

Environment

  • Jira Service Management (Cloud)
  • Rovo AI Assistant
  • July 2026

 

2 answers

1 accepted

1 vote
Answer accepted
Arkadiusz Wroblewski
Community Champion
July 17, 2026

Hello @Mark B Wager and @Ajay _view26_ 

This is a known bug (ROVO-297)β€”the Rovo comment action currently posts publicly even when told to make an internal note.

The best way to handle this is actually to split up generating the text and then posting it.

You'll want to use that Rovo agent action to create the text first, and then right after that, pop in a regular Jira Comment on issue action. Just make sure you set that one up specifically as internal using what the agent comes back with (that's the `{{agentResponse}}` part!).

 Best,

Arek 🀠 

 

1 vote
Ajay _view26_
Community Champion
July 17, 2026

Hi @Mark B Wager 

The underlying issue is that the Jira REST API's "Add comment" endpoint does support the visibility property (for restricting to a service desk role like sd.public.comment vs sd.internal), but Rovo's comment-posting action currently doesn't expose or honour that parameter.

It defaults to public visibility, and there's no guardrail prompting you to confirm before it executes a write operation on a customer-facing ticket. 

I think its best to raise a support ticket to report the issue. Hopefully Atlassian picks this up quickly as  it's a data exposure risk.

Mark B Wager
Contributor
July 20, 2026

Great info! Thanks!

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events