Connector · Jira and Confluence

Jira and Confluence for your AI assistant, with every change approved.

PrivacyFence connects an AI assistant to Jira Cloud and Confluence Cloud through one Atlassian sign-in. The assistant can search issues and pages straight away, reads their full content only after you have looked at it, and creates or updates nothing until you approve. It cannot delete anything: PrivacyFence does not even ask Atlassian for a delete permission.

What the assistant can do

Two connectors, one sign-in.

Every tool has a gate fixed in code. The Tools reference lists each Jira and Confluence tool.

Jira

Without a card
Projects, issue search with JQL, and an issue's available transitions.
Reviewed before release
An issue's full details, including its description and comments.
Needs your approval
Creating and updating issues, commenting, and moving an issue to a new status.

Confluence

Without a card
Spaces, page lists, search, and a page's attachment names.
Reviewed before release
A page's content, and its attachments.
Needs your approval
Creating and updating pages.

Personal data

Tickets and pages are checked before you see them.

Before a reviewed read is shown to you, PrivacyFence scans it locally for likely personal data in English, German and Hungarian: IBANs, card numbers, ID and tax numbers, salary information and similar. It scans a Jira issue's description and comments, a Confluence page's body, and the text it can extract from an attachment (up to 20,000 characters; files over 5 MB and images are not scanned).

A match sends the read to a card even if an always-allow rule covers it, highlights what was found, and asks for a second confirmation. The audit log records the category, never the matched text.

The privacy filter, separately, decides what may leave PrivacyFence at all. Out of the box it blocks Confluence search excerpts and attachments until you allow them in Settings → Privacy Filter → Confluence.

How the PII check works · The privacy filter

Routine requests

Trust a project or a space.

An always-allow rule lets matching requests run without a card, and each one is still audited. A rule can trust, for example:

A Jira project

Reading or changing issues in the projects you name, by project key.

Your own issues

Issues you reported, or issues assigned to you.

A Confluence space

Reading or editing pages in the spaces you name.

Your own pages

Pages you wrote.

Likely personal data in a read still goes to a card. Every scope is in the scope catalogue.

Set it up

One Atlassian app, then each person approves it.

  1. An administrator creates one Atlassian OAuth 2.0 (3LO) app in the developer console and packages its client ID and secret into an organization config bundle. Desktop installs and an organization server each need their own app, because an Atlassian app has a single callback URL.
  2. Each person installs the bundle, connects from PrivacyFence's Settings page, and approves the app in the browser. One sign-in covers both Jira and Confluence.
  3. The tools appear to the assistant. The sign-in stays with PrivacyFence and is never given to the AI client.

Atlassian Cloud sites (*.atlassian.net) only; Jira and Confluence Data Center or Server are not supported.

Set it up Connecting a service

Next

See how a request is approved.

Follow a read and a write through PrivacyFence, card by card.