Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-2164

Org Audit logs doesn't include Atlassian Support agent added as Org Admin events

      Issue Summary

      When a support ticket is created with Atlassian and data access consent is granted, the Atlassian Engineer is able to get a temporary and controlled access to the instance added to the support ticket.

      However, the access granted to the Atlassian Support is not added as an Org Audit log event, so the Org admins not involved in the ticket do not have any visibility of the access consent given.

      Steps to Reproduce

      1. Raise a Support ticket with Atlassian > Add a tenant for the support and approve data access.
      2. The Atlassian Engineer/assignee gets access to the instance as Org/site admin.
      3. No event is tracked in Audit logs about the access/permission granted to the Atlassian contact.

      Expected Results

      Add an event of the Atlassian engineer receiving such permissions and access.

      Actual Results

      No events are recorded/available.

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

            [ACCESS-2164] Org Audit logs doesn't include Atlassian Support agent added as Org Admin events

            Sean.Byrne added a comment -

            Thank you for raising ACCESS-2164 regarding the missing audit logs when an Atlassian Support agent is granted temporary Org Admin access. This issue introduces significant security and compliance risks for organizations using Atlassian Cloud.

            Key Concerns

            • No Visibility for Org Admins – Other Org Admins not involved in the support ticket remain unaware when an Atlassian engineer gains access.
            • Audit & Compliance Risks – Most security frameworks (SOC 2, ISO 27001) require tracking privileged access. The absence of logs creates a compliance gap.
            • No Available Workaround – Currently, customers must manually track support tickets to check if Atlassian has been granted access.

            Questions

            🔹 ACCESS-2155 was closed – Does this mean Atlassian has no plans to implement audit logs for these events? If so, can you clarify why?
            🔹 Timeline for Fix – Is there an estimated timeframe for when Atlassian will provide a fix for this issue?
            🔹 Interim Workaround – Until a proper fix is in place, does Atlassian recommend any alternative method for tracking support agent access?

            This is a high-priority issue, and we strongly urge Atlassian to provide a clear commitment and timeline for resolution.

             

            Sean.Byrne added a comment - Thank you for raising ACCESS-2164 regarding the missing audit logs when an Atlassian Support agent is granted temporary Org Admin access. This issue introduces significant security and compliance risks for organizations using Atlassian Cloud . Key Concerns No Visibility for Org Admins – Other Org Admins not involved in the support ticket remain unaware when an Atlassian engineer gains access. Audit & Compliance Risks – Most security frameworks (SOC 2, ISO 27001) require tracking privileged access. The absence of logs creates a compliance gap. No Available Workaround – Currently, customers must manually track support tickets to check if Atlassian has been granted access. Questions 🔹 ACCESS-2155 was closed – Does this mean Atlassian has no plans to implement audit logs for these events? If so, can you clarify why? 🔹 Timeline for Fix – Is there an estimated timeframe for when Atlassian will provide a fix for this issue? 🔹 Interim Workaround – Until a proper fix is in place, does Atlassian recommend any alternative method for tracking support agent access? This is a high-priority issue, and we strongly urge Atlassian to provide a clear commitment and timeline for resolution .  

              Unassigned Unassigned
              5bbd7c890e1e Italo Oliveira Araujo
              Affected customers:
              1 This affects my team
              Watchers:
              5 Start watching this issue

                Created:
                Updated: