At my company, Jira is set up quite restrictive, with quite strict workflows.
One of these workflows is the automatic transitioning of issues from "Code review" to "QA" status when PRs are merged in Bitbucket.
This bypasses the option to transition issues in the Bitbucket "merge PR" popup. It should be noted that for some reason, my Jira account is not allowed to transition issues from "Code review" to "QA" manually. Annoying, but fair enough.
However, something is automatically transition these issues, and in the issue history this shows as *my user transitioning the issues*.
I have big ACL concerns about this. I have no visibility whatsoever on these automations, and the automation acts, as far as I can see, *with the privileges of my user*. I can't see the audit logs of the automation, but I assume the audit log will show the issue being transitioned by my user.
In a hypothetical scenario, a privileged actor with malicious intent could create a "nuke the project" automation, and set it up so it triggers when I e.g. merge a PR. In the audit logs, this will show up as "<my user> nuked the project".
A tool with proper ACL should not allow such a scenario to happen.