Hi App Central — I'm Engin, founder of Claervo (Marketplace partner). I've spent the last few months looking at how customer requests in JSM quietly gain a wider audience, and I wanted to share what I found — and, at the end, the app I built for it.
The problem: a request's audience grows without telling anyone
- Add an Organization to a request and every member of that organization can see it in the portal. Fine with 3 members; an HR request accidentally shared with a 200-member customer organization is a privacy incident.
- Request participants can be outside the customer's domain (a contractor, a personal address, the wrong person).
- Jira raises no alert for either, and JQL is a weak audit tool here because organization membership changes on the organization, not on the request.
How to check your own site (no app needed)
- Search
Organizations is not EMPTY per project and flag requests tied to large organizations. - Search
Request participants is not EMPTY and eyeball the email domains. - Write down a rule for sensitive request types (HR, legal, security): no organization sharing, ever — and check it weekly.
This works on small sites; it doesn't scale past ~10k requests.
What we built
To automate this I built Claervo Privacy Guard for JSM: it scans your service projects, lists every finding with an explainable risk score, lets you scope policies by project/request type (monitor-only first), revalidates before any remediation, and keeps a sanitized audit trail. It runs on Forge with the Runs on Atlassian badge — no remote backend, no data egress, and it never reads request descriptions or comments.
Marketplace:
https://marketplace.atlassian.com/apps/2917950185
What I'd love to hear from you
- What do you use today to audit organization sharing — automation, JQL, nothing?
- Which scenario worries you most: large organizations, external participants, or the wrong request type?
Critiques and counter-examples very welcome.