We've run into a problem that I'm sure a lot of teams have seen. Users sometimes add personal information, IDs, or other sensitive data to Jira tickets without realizing they shouldn't.
What I've noticed is that most PII detection tools only catch the issue after the ticket has already been created. By then, the data has already been stored, indexed, included in notifications, or viewed by other users. At that point, you're cleaning up the problem instead of preventing it.
I'm interested in approaches that stop sensitive data from being submitted in the first place.
A few questions for the community:
- Has anyone implemented real-time validation or blocking before a ticket is submitted?
- Have you found any effective approaches using forms, workflows, client-side validation, or other techniques to reduce accidental data exposure?
- How are you moving from detecting sensitive data after the fact to preventing it from entering Jira in the first place?
I'd love to hear what's worked for your team, whether it's a technical solution, a process change, or something else entirely.