At a glance
| Input | Action | Output | Limit |
|---|---|---|---|
| Current Forge manifest | Review modules, scopes, and egress | Deployed permission model | Recheck after every manifest change |
| Evidence data model | Review SQL, Object Store, and legacy KVS use | Storage and retention understanding | Regional behavior follows current Atlassian services |
| GitHub connector | Review repository binding, paths, credentials, and egress | Approved external access model | Current visible workflow is report-only terminology checking |
| Uploaded evidence | Review type, size, hash, parser, and retention controls | File-ingestion risk model | Successful parsing is not content approval |
| Administrative roles | Review term-manager and license gates | Access-control evidence | Organizational authority remains external |
How it works
- Review the current production manifest.
- Map each data type to its storage path and retention state.
- Review GitHub egress and repository restrictions.
- Validate administrator roles and inactive-license behavior.
- Review file upload limits and failure states.
- Record accepted risks and required controls outside the app.
Example
A procurement reviewer confirms that Confluence access is read-only, enterprise evidence uses Forge storage, and GitHub API egress is declared. The reviewer also records that the app is not eligible for a no-egress designation in this configuration and does not provide WORM storage.
What this does not mean
This page is a review checklist, not a security certification. Customers must assess the current deployed version, Atlassian platform terms, their configuration, and their own risk requirements.
Related questions
Next step
Review the current manifest and data flow before approving production use.
View on Atlassian Marketplace