We got an email this morning that someone from outside our organization was added to our Jira/Confluence account.
None of our admins added him. When I called him he said that he joined by clicking a link from his company's self-hosted Confluence (without an invite from us).
This is very strange. We need to figure out just how he got in. I'm catching a lot of heat for this.
I tried looking at the security audit log but apparently, you need to purchase the "Access" license to see your security log