Security and permissions

Report Steward reads authorized Jira Service Management data and prepares customer files within Atlassian Forge. Last updated 13 September 2026.

Where the app runs

The backend runs on Atlassian Forge, using Forge compute and key-value storage. Your browser displays previews and receives downloads. No external destination for report data is configured in the app.

No advertising, analytics or AI service receives customer report data from the app. Diagnostic logs may include run stages, counts, timings and error codes. They are not intended to contain report content.

Why Jira permissions are needed

PermissionPurpose
read:jira-workRead visible project and request metadata used in the report.
read:servicedesk:jira-service-managementDiscover service projects available to the reporting user.
read:servicedesk.organization:jira-service-managementRead customer organizations and request membership.
read:request.sla:jira-service-managementRead selected native SLA metrics and completed cycles.
storage:appSave report setup, schedules, temporary report data and generated files.

Scheduled and background reads use the report owner’s identity through Forge offline user impersonation. They remain subject to that user’s Jira permissions. The app does not request write access to Jira issues.

Access and customer separation

Access to saved setups, report runs and files is restricted to their owner account within the app installation. A schedule uses its saved owner identity; opening the app as a different user does not give access to that owner’s reports.

Before showing report data or providing a download, the app rechecks your current Jira access and the organization assignments of the scanned requests. Individual customer files exclude other organizations and the internal pack manifest. The full ZIP is intended for the report owner’s records.

Downloads require a short-lived authorization for the specific file. The app checks ownership, expiry and file integrity during transfer. Deleting a report prevents new downloads while its stored report data is removed in the background.

Data minimization and retention

The report reads identifiers, dates, current resolution information, organization assignments and selected native SLA cycles. It does not read issue descriptions, comments, attachments, reporter or assignee fields for these reports.

Generated report data and files are retained for a limited period. Saved setup revisions, committed logos and the owner record have different retention rules. Read the complete retention table, including what the deletion controls do.

Platform controls and scope

Atlassian provides the underlying Forge hosting and storage controls. Its hosted storage lifecycle applies after uninstall and to platform recovery. This page does not promise a particular region for every processing activity or support service.

These measures describe the app’s implementation; they are not a claim of an independent security certification. Downloaded files are under the customer’s control and should be shared only with intended recipients.

Report a concern

Contact support@misheno.com with “Security” in the subject. Include steps to reproduce and the affected function, without credentials or unnecessary customer data. Support response times apply.