Summary
When a Jira admin creates a new webhook that can send all Jira issue events to an external endpoint, this action does not appear in any audit trail I can find - neither in the Jira Cloud audit log nor in the organization-level (Atlassian) audit log.
Expected result
An audit entry recording webhook creation (including creator, time, target URL redacted or partially masked, scope/events enabled).
Actual result
No audit entry found in either Jira’s audit log or the Atlassian organization audit log.
Why this matters
Webhooks can exfiltrate issue data to external systems. For compliance, security reviews, and incident response, we need a definitive audit trail for webhook lifecycle events (create/update/enable/disable/delete), ideally with:
Actor and timestamp
Webhook name/ID
Event scope (e.g., issue events)
Status changes (enabled/disabled)
Target URL (masked if necessary)